The Security & Compliance Engineer owns the security, compliance, and integration of our tool ecosystem: CRM, community/LMS, data, and collaboration platforms. This is a hands-on technical role: you write scripts, work with APIs, and reason about system and security architecture to harden, connect, and automate the platforms we already run (HubSpot, Hivebrite, Notion, Looker Studio/Tableau, Slack, and others). You won't be building new consumer-facing or product software from scratch. The engineering is applied to keeping our existing technology ecosystem secure, compliant, integrated, and reliable as we grow.
Key Responsibilities
Security & Compliance Engineering: Design and implement secure configurations, access controls and SSO, secrets management, and data protection controls across our tool stack. Ensure compliance with data protection requirements (e.g. GDPR), own audit readiness, and lead vendor/security reviews for new tools.
AI Governance & Compliance: Oversee the secure and compliant use of AI tools (e.g. Claude, Gemini) across the organization, ensuring use cases align with the EU AI Act and internal data protection standards, classifying and documenting AI workflows, and advising teams on safe, approved use of AI in their day-to-day work.
Tool & Systems Integration: Build and maintain API-based integrations and automations between HubSpot, Notion, Hivebrite (or similar LMS/Community platforms), Looker Studio/Tableau, Slack, and other operational platforms, using scripting and automation tools (e.g. Python, Zapier/Make, native APIs).
Monitoring & Incident Response: Set up monitoring, logging, and alerting across systems; lead investigation and resolution of security and technical incidents, and drive down recurring risk.
Process Optimization & Automation: Identify manual, recurring workflows and replace them with automated, auditable solutions.
Cross-Team Collaboration & Documentation: Work closely with marketing, business development, and leadership to translate operational needs into secure technical solutions, and keep architecture, security, and compliance documentation up to date.
