This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are on a mission to ensure everyone has access to medical expertise, no matter where they are. Corti is building the infrastructure to close that gap. Our AI platform expands access to medical expertise, reducing errors, restoring time to clinicians, and making care more affordable, accessible, and human again. As a Security Engineer at Corti, you are a security governance-focused engineer. Your primary responsibility is to make sure that security standards, controls, and framework requirements are clearly defined, technically grounded, and consistently implemented across our platform and operations.
Job Responsibility:
Own and maintain Corti's security governance model across ISO 27001, SOC 2 and other relevant frameworks
Translate frameworks and customer requirements into concise policies, playbooks, checklists and acceptance criteria
Plan, manage and follow up on internal and external security audits and assessments
Drive the use of compliance automation tools and internal scripts
Maintain a live security risk register
Partner with Platform and other engineers to ensure that policies and control objectives are reflected in CI or CD pipelines, Infrastructure as Code and cloud configuration baselines
Act as a trusted advisor on secure ways of working and provide answers to customers and stakeholders on Corti’s security
Requirements:
Experience in DevOps, platform engineering, security engineering, or a similar field
Comfortable reading and writing scripts or small tools, for example in Python, Go, or TypeScript
Understand the fundamentals of cloud security, identity, and networks
Have worked with or around security frameworks such as ISO 27001, SOC 2, or GDPR
Communicate clearly with both engineers and governance stakeholders
Enjoy structured work such as defining standards, maintaining inventories, and keeping documentation in sync with reality
Take a pragmatic approach to security
Nice to have:
Know how to implement and enforce secure release workflows
Have hands-on experience with Kubernetes and cloud security practices (especially Azure)
Experience with Drata or similar compliance automation tools
Familiarity with MDM and endpoint hardening across Linux, MacOS, and Windows
Understanding of audit tooling and compliance KPIs (MTTR, version skew, access policies)