Senior Security Engineer

๐Ÿข UserGems ๐Ÿ’Ž ยท all UserGems ๐Ÿ’Ž jobs
๐Ÿ“ Worldwide
๐Ÿ’ฐ EUR 80,000 - 100,000 / annual
๐Ÿ“… Posted 2026-08-03 ยท via Himalayas
๐Ÿท Security-Engineering,GRC-Security,Cloud-Security-Engineering,Compliance-Engineering,AI-Security,Senior-Information-Security-Engineer,Senior-Cybersecurity-Engineer,Senior-Principal-Security-Engineer,Senior-Security-Engineering-Manager,Senior-Security-Operations-Engineer,Senior-Application-Security-Engineer,Lead-Security-Engineer,Security-Engineer
Apply on original site โ†—

UserGems is an AI platform that helps sales and marketing teams double their pipeline impact with the same team.

Our AI agent (Gem-E) captures buying signals and your CRM data to identify who to target, when, and why, drafting highly personalized and impactful outreach that results in higher conversion.

UserGems has generated $4 Billion in pipeline and over $950 Million in revenue for hundreds of start-ups and public companies. Companies like Mimecast, UserTesting, SAP LeanIX see more than 15X ROI in closed won revenue from UserGems.

Operate UserGems' security and compliance program day-to-day, partnered with the Sr. Director on direction and strategy.

UserGems is an AI platform helping sales and marketing teams double pipeline impact. Our AI agent Gem-E turns signals from CRMs, buying intent, and public data into precise outreach - generating $4B in pipeline and $950M in revenue for customers like CrowdStrike, UserTesting, and SAP LeanIX (15X+ ROI).

UserGems is a ~70-person company with around 25 engineers across Europe and 45 team members in sales and marketing based in the U.S. Several of our customers are top-tier security companies themselves (e.g. CrowdStrike), so our own security posture directly influences how fast revenue can move.
The Role

You will be UserGems' single dedicated security person , taking over the operational majority of the security work the Sr. Director currently owns. This is a compliance-led role with hands-on operational components - heavy on SOC 2 / ISO ownership, customer security reviews, day-to-day program operations, and Drata-driven remediation in AWS. Compliance is the primary focus and over time you'll own the full technical scope described below as well. The Sr. Director approves direction; you propose, shape, and execute the program. Cadence is a bi-weekly 1:1 with the Sr. Director plus a weekly work discussion, same as every UserGems employee.

UserGems' security program is in great shape - no fires to put out. SOC 2 Type II is in place for years already, all compliance monitoring is centralized in Drata , scanner findings auto-flow into Linear and are auto-triaged by an in-house automation, and CrowdStrike Complete (managed MDR) handles runtime protection. There's no on-call rotation at UserGems - incident response is a whole-team effort, and the Sr. Director continues to cover during your time off.

The Sr. Director currently runs the whole program in roughly 25% of one person's time, so a dedicated owner has real headroom. Expect your time to split roughly 2โ€“3 days per week on baseline operations and the remainder on new initiatives . The biggest near-term programs are ISO 27001 and likely ISO 42001 (AI management) - both held back today because no one has the dedicated capacity to drive them. That's the gap you fill.
You'll thrive here if you:

- Lean strongly into compliance/GRC operations - with enough hands-on AWS comfort to action Drata-flagged remediations independently.

- Want to own operations end-to-end and influence direction - you propose, the Sr. Director approves, you ship.

- Like a startup environment where priorities are clear, ownership is real, and you ship and move on.

What You'll Do

-
Own SOC 2 - keep Drata green and audits clean.

-
Lead ISO 27001 implementation , then ISO 42001.

-
Run the customer security questionnaire process (SafeBase + Trust Center) - fast turnaround directly unblocks revenue.

-
Drata-driven AWS remediation. Action simple Drata findings directly in AWS yourself - IAM tweaks, S3 settings, secrets hygiene, audit-trail follow-ups. Larger or higher-risk changes go to engineering.

-
Vulnerability management. Oversee and extend the existing scanner-findings automation in Linear; hit SLAs.

-
Light secure code review. Spot-check high-risk features and new repositories (especially AI/LLM systems) before they go to production; escalate deeper AppSec questions to engineering and external pen testers.

-
Threat detection &

โ† All remote jobs