Security Engineer, Compliance

Remote

Company Overview

ZBD powers real economies in virtual worlds by enabling game studios, creators, and platforms to embed seamless payments and virtual currencies into their experiences. Whether players are purchasing in-game currency, creators are monetizing their communities, or developers are building new types of digital commerce, ZBD provides the infrastructure to make it happen.

ZBD is a fully remote company. We hire, retain, and develop the best talent from around the world, wherever s/he/they may choose to live. As a result, every member of the ZBD team must demonstrate an ability to work independently and thrive in a remote environment.

Job Overview

ZBD is seeking a Security Compliance Engineer to design, implement, and maintain our organization’s security compliance framework and risk management programs. This role bridges technical security implementation with regulatory compliance and risk assessment. You should be comfortable working in a growth-stage startup, with comfort navigating ambiguity and fast-paced environments. Come build, secure, automate, and monitor with the ZBD team!

Key Responsibilities

  • Design, implement, and maintain security solutions to address vulnerabilities and risks within ZBD systems
  • Work closely with the software engineers and developers to establish and keep a strong security compliance posture
  • Develop and enforce technical security standards, patterns, and best practices to establish and maintain a consistent and robust security posture across ZBD systems
  • Proactively identify and address security & policy gaps in existing systems and architectures, recommending and implementing enhancements to strengthen ZBD’s overall security posture
  • Contribute to the development and maintenance of security documentation, including policies, procedures, and technical guides
  • Bring and keep ZBD systems, processes, and procedures into compliance with relevant compliance frameworks (SOC 2, DORA, GDPR, PCI DSS, etc.)
  • Develop and maintain cloud recovery and backup solutions to ensure availability and business continuity
  • Participate in an On-Call rotation
  • Document processes & procedures

Skills, Knowledge, and Expertise

  • 3+ years of experience in security governance, cloud and application security assessments, risk management, and/or third party risk
  • Thorough understanding of cybersecurity principles, cloud security, and identity and access management
  • Firm grasp on cloud computing principles
  • Demonstrated experience with Infrastructure as Code using Terraform/OpenTofu
  • Working knowledge of Linux
  • Experience with metrics gathering, alerting, reporting
  • Experience with CI/CD pipelines
  • Ability to design, implement, and improve cybersecurity solutions
  • Ability to balance cybersecurity initiatives with business initiatives
  • Ability to identify and analyze potential methods of attack

Nice to Haves

  • Setup Gitlab CI/CD pipelines
  • Experience with AWS Organizations and Multi Accounts
  • Has participated in efforts to keep compliance with SOC 2 controls
  • Experience in developing or working with SIEM or log management solutions
  • Knowledge of, and experience working with Bitcoin and Lightning Network software

About ZBD

We power real economies in virtual worlds. With ZBD, gaming becomes a meaningful economic activity and game devs get a new playground for weaving money into the worlds they create.