Senior Engineer, Security & Compliance (US)
Code and Theory· Austin, United States·
The Machine is the agentic operating system for marketing, built by Code & Theory. It plugs into the tools marketing teams use and turns disconnected workflows into a single intelligent system, connecting brand strategy, creative production, and media performance. The Machine helps power agencies across Stagwell's network and world-leading brands.
We're looking for a Senior Security Engineer to be the hands-on technical backbone of our security and compliance program across our SaaS products and client delivery work. This role would own the implementation — building the controls, tooling, automation, and processes that make our security program real. You'll work directly with engineering teams, embed into delivery workflows, and be the person who actually builds and runs the systems that keep our products and client data secure.
Our engineers are AI native and engage in and advance the state of the art in the practice of software development flow with AI.
WHAT YOU'LL DO
- Build and maintain code security controls across our cloud infrastructure and technology products
- Instrument and operate security monitoring and alerting across cloud environments (GCP, AWS, and/or Azure), with hands-on responsibility for code security, threat detection, log aggregation, and response
- Partner with engineering teams to embed security into CI/CD pipelines
- Document, review, and implement privacy controls in product and client environments, including data classification, retention, access controls, and audit logging aligned to specific security and compliance requirements
- Lead technical implementation of SOC 2 Type II, ISO 27001, and ISO 42001 compliance programs
- Execute the client engagement security model — provisioning and deprovisioning access, configuring environment segregation, and meeting client-specific delivery security requirements
- Conduct hands-on vendor security assessments, reviewing third-party architectures, configurations, and data handling practices
- Develop, maintain and test incident response playbooks; lead technical response and forensic analysis during security events
- Build and maintain security controls for AI agent workflows and AI-assisted development pipelines
- Contribute to the compliance policy response library, serving as a key technical author and reviewer
WHAT YOU'LL NEED
- 5+ years of hands-on security engineering experience in a software product development team
- Deep practical knowledge of cloud security in at least one major platform (GCP, AWS, or Azure)
- Experience building security automation across CI/CD pipelines — integrating vulnerability scanners, SAST/DAST tools, and policy enforcement into engineering workflows
- Working knowledge of privacy regulations (HIPAA, GDPR, CCPA/CPRA) and experience implementing technical controls that operationalize compliance requirements
- Proficiency with security monitoring and security incident event management
- Strong communication skills — you can explain a complex finding clearly to an engineer, a PM, or a client, and clearly document your analysis
- Comfort working across a distributed, fast-moving organization with multiple concurrent workstreams
- Fluent with AI-enabled development tools and agent-driven workflows — comfortable selecting models/tools, building prompts and evaluation frameworks, and using AI to accelerate engineering and operational work, while exercising sound judgment on the security, scalability, and reliability of AI-assisted output
- Hands-on experience reviewing and hardening AI agent workflows — understanding risks like prompt injection, data leakage, and model misuse in production systems
NICE TO HAVE
- Hands-on experience with SOC 2 Type II and ISO 27001 control implementation
- Experience in agency, consultancy, or enterprise SaaS environments where you've had to meet varying client security requirements
- Familiarity with ISO 42001 and AI governance frameworks
- Experience securing multi-tenant SaaS architectures at the infrastructure and application layer
- Relevant certifications: CISSP, CCSP, AWS/GCP/Azure Security Specialty, CIPP, or similar
- Experience with infrastructure-as-code security tooling (e.g., Checkov, tfsec, OPA/Rego)
ABOUT US
Born in 2001, Code and Theory is a digital-first creative agency that sits at the center of creativity and technology. We pride ourselves on not only solving consumer and business problems, but also helping to establish new capabilities for our clients. With a global client roster of Fortune 100s and start-ups alike, we crave the hardest problems to solve. We have teams distributed across North America, South America, Europe, and Asia. The Code and Theory global network of agencies is growing and includes Kettle, Instrument, Left Field Labs, Create Group, Current, and TrueLogic.
Striving never to be pigeonholed, we work across every major category: from tech to CPG, financial services to travel & hospitality, government and education to media and publishing. We value the collaboration with our client partners, including but not limited to Adidas, Amazon, Con Edison, Diageo, EY, J.P. Morgan Chase, Lenovo, Marriott, Mars, Microsoft, Thomson Reuters, and TikTok.
The Code and Theory network is comprised of nearly 2,000 people with 50% engineers and 50% creative talent. We’re always on the lookout for smart, driven, and forward-thinking people to join our team.
The base compensation range for this role is $110,000 – $160,000 and spans multiple levels. We're open to hiring at the level that best matches the right candidate's experience. Actual compensation is influenced by a wide array of factors including but not limited to skill set, level of experience, budget, and location.