Framework Engineer
Boost your chances before you apply.
Oneleet
Beaverton, OR, US
Summary
The Framework Engineer will research and map new compliance frameworks to the company's control library. They will also build automations and documentation to streamline the compliance process for customers.
Job Description
About Oneleet
Oneleet is one of the fastest-growing security and compliance platforms in history. We are on a mission to change the compliance and security industry by making cybersecurity and compliance effective, easy, and painless. We provide a platform that helps companies build, manage, and monitor their cybersecurity programs and achieve compliance standards such as SOC 2 and ISO 27001 efficiently, without cutting corners.
Having just raised a $33 million Series A, we are rapidly growing in customers and employees. Our team has decades of experience in security and compliance. Join our team of opinionated rebels and help us build a category-defining company reshaping the broken and fragmented compliance and cybersecurity industry.
Who we’re looking for:
We value passionate self-starters with a growth mindset and a bias for action and personal accountability. If you love solving hard problems, thrive in ambiguity, and want to make a real impact, you’ll fit right in.
We’re especially drawn to:
-
Rebels with a cause — frustrated with the status quo and eager to disrupt it.
-
Opinionated (but not obstinate) builders — decisive yet collaborative, who help us move fast.
-
Clear communicators — who own their ideas and follow through.
Our mission is simple: make effective cybersecurity painless. We believe cybersecurity should empower, not burden. This belief unites our team and drives every decision we make.
If you’re ready to challenge the status quo and help shape the future of cybersecurity, we’d love to meet you.
The Role
This role is the core of how we grow our compliance platform and keep ahead of changes in the compliance space. Your responsibilities will be focused on adding support for new frameworks, deepening our control library and keeping our current frameworks up to date with changes.
Key Responsibilities:
-
Research new frameworks, and break them down into requirements that map to our current control library
-
Evaluate our current control library for inefficiencies or superfluous requirements and keep it clean and focused
-
Build automations or documentation for our customers, so they can meet their requirements with the minimum amount of bullshit required.
-
Make improvements to the compliance product to make compliance easier for our customers.
You Might Be a Good Fit If You Have:
-
Frustration with the current compliance space and how much security theatre there is within the companies you have worked with.
-
Experience building security programs from scratch to meet with compliance requirements.
-
A self-starter mindset — you take initiative, adapt quickly, thrive in ambiguity, and enjoys building processes from scratch.
-
Strong working knowledge of major compliance frameworks (ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS).
-
Comfort editing structured configuration files (JSON) and writing basic scripts to automate rule updates and validation checks—this role requires strong logical/technical fluency.
Bonus Points For:
-
Engineering or coding experience.
-
Experience scaling an early stage startup from Seed to Series A or beyond.
Why Oneleet?
At Oneleet, you’ll join a tight-knit team of rebels redefining the cybersecurity industry. We move fast, own our work, and challenge outdated models to make security effortless and effective for companies.
Here’s what makes us special:
-
We value impact over titles, autonomy over micromanagement, and clarity over jargon.
-
You’ll tackle meaningful, hard problems with real-world consequences.
-
You’ll work with smart, kind, and ambitious teammates who lift each other up.
Perks & Benefits
-
Comprehensive health & wellness benefits
-
20 days PTO per year, plus 8 floating holiday
-
Remote work culture
-
Team off-sites in stunning places (Amsterdam, Italy, etc).
-
Competitive compensation & equity
We hire globally and compensate competitively within each market using geographic pay bands. The range for this role reflects a US national baseline. Offers for candidates in higher cost-of-labor markets (e.g., San Francisco, New York, Zurich) may fall at or above the top of the posted range, while offers in other markets are benchmarked to local standards and are lower. Within any range, individual compensation is determined by work location, skills and experience demonstrated through the interview process, and relevant education or training. This posting reflects base salary only and does not include equity or benefits.
Remote-First & Global Hiring
We’re a remote-first company and hire globally in regions where we can legally engage talent directly or via our employer-of-record (EOR) partner. If you’re based outside the U.S., we’ll explore the most compliant hiring arrangement for your location. We make hiring decisions based on merit, skills, and potential regardless of location.
U.S. Hiring & E-Verify
For U.S.-based candidates, Oneleet participates in E-Verify to confirm employment eligibility, in accordance with federal regulations. We are an equal opportunity employer. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by applicable law.
How we use AI in this Hiring Process
This company uses automated technology, including AI-assisted tools, to assist in reviewing applications, assessing candidate qualifications, and detecting fraudulent submissions. These tools analyze application data and identity signals to support, but not replace, human hiring decisions. All final hiring decisions are made by a human reviewer. Candidates who require accommodation or who wish to request information about how these tools are used, including requesting the bias audit results, may contact [email protected]. This process is conducted in compliance with applicable federal, state, and local laws.
Notice for New York City Residents:
You have a right to take at least 10 business days to decide whether to proceed with submitting your information through this process. By continuing, you confirm your understanding of this notice. If you choose to proceed before the 10-business-day period expires, you are making a knowing and voluntary decision to do so.
Oneleet is the cybersecurity platform for building real security controls, achieving compliance (SOC 2, ISO 27001, GDPR, HIPAA), and maintaining a strong security posture as you grow.
Everything You Need in One Platform- Manage your entire security program from a single view.
At Oneleet, we believe compliance should follow security—not the other way around. We start by building a pragmatic, effective security program tailored to your company. We provide the tools and expertise you need:
• Compliance Platform. Streamline evidence collection and management for SOC 2, HIPAA, ISO 27001, GDPR, and more. Reduce audit preparation time.
• Code Security Scanner. Embed security early. Identify and resolve vulnerabilities in your codebase.
• Attack Surface Discovery. See your business like an attacker. Identify and monitor external-facing assets and risks.
• Penetration Testing. Expert-led testing by OSCE/OSWE certified pros to find critical vulnerabilities missed by automated scans.
• Access Reviews. Ensure least privilege. Stay on top user permissions across critical systems to reduce risk.
• vCISO + Security Programs. Get on-demand, enterprise-grade security expertise and tailored programs without the full-time CISO cost or ramp-up time.
• Trust Center. Showcase your security posture and compliance achievements to build customer confidence and speed up sales cycles.
• Third-Party Audits. We streamline the auditing process for SOC 2, ISO 27001, HIPAA, and more with trusted third-party auditors.
• Oneleet Agent. Enforce security policies and monitor your company’s devices.
• Employee Portal. One place for security resources, training, and support to boost employee awareness.
Pass vendor reviews faster, and unlock deals.
Stop security from being a blocker.
Founded
2022
Company size
51-200 employees
Industry
Computer and Network Security
Org type
Privately Held
Headquarters
Wilmington, DE
Oneleet is the cybersecurity platform for building real security controls, achieving compliance (SOC 2, ISO 27001, GDPR, HIPAA), and maintaining a strong security posture as you grow.
Everything You Need in One Platform- Manage your entire security program from a single view.
At Oneleet, we believe compliance should follow security—not the other way around. We start by building a pragmatic, effective security program tailored to your company. We provide the tools and expertise you need:
• Compliance Platform. Streamline evidence collection and management for SOC 2, HIPAA, ISO 27001, GDPR, and more. Reduce audit preparation time.
• Code Security Scanner. Embed security early. Identify and resolve vulnerabilities in your codebase.
• Attack Surface Discovery. See your business like an attacker. Identify and monitor external-facing assets and risks.
• Penetration Testing. Expert-led testing by OSCE/OSWE certified pros to find critical vulnerabilities missed by automated scans.
• Access Reviews. Ensure least privilege. Stay on top user permissions across critical systems to reduce risk.
• vCISO + Security Programs. Get on-demand, enterprise-grade security expertise and tailored programs without the full-time CISO cost or ramp-up time.
• Trust Center. Showcase your security posture and compliance achievements to build customer confidence and speed up sales cycles.
• Third-Party Audits. We streamline the auditing process for SOC 2, ISO 27001, HIPAA, and more with trusted third-party auditors.
• Oneleet Agent. Enforce security policies and monitor your company’s devices.
• Employee Portal. One place for security resources, training, and support to boost employee awareness.
Pass vendor reviews faster, and unlock deals.
Stop security from being a blocker.
Founded
2022
Company size
51-200 employees
Industry
Computer and Network Security
Org type
Privately Held
Headquarters
Wilmington, DE