Security & Compliance Manager
Legal
Prague, Czechia
ALICE Technologies has created the world's first construction optioneering platform for complex projects. Founded in 2015 based on research from Stanford University, ALICE leverages artificial intelligence to help large general contractors reduce risk and plan, bid, and build more efficiently.
ALICE Technologies works with construction leaders in the infrastructure and commercial construction segments, such as Parsons, Takenaka, Austin Bridges and Roads, and Skanska.
About the Role
As our Senior Security & Compliance Engineer, you'll own our security and compliance program end to end and set the technical direction for how we protect our platform, our customers, and their data. You'll be the person who drives our compliance frameworks to certification, hardens our cloud infrastructure, leads incident response, and represents ALICE's security posture to enterprise customers.
Requirements
- 5+ years in security, with demonstrated ownership of a governance, risk, and compliance (GRC) program or equivalent security engineering experience
- Proven track record tackling at least one recognized framework (SOC 2, ISO 27001, or similar) through certification end to end — from gap assessment and control design to audit and continuous compliance
- Deep working knowledge of privacy and data residency requirements (GDPR, DPAs, cross-border data handling) and the ability to translate them into technical and contractual controls
- Owns customer-facing security work at the enterprise level: security questionnaires, RFP responses, trust-center content, and engagement with customer security teams
- Strong cloud security fundamentals on AWS (IAM, network segmentation, encryption, secrets management) alongside solid HTTP and Linux foundations
- Hands-on experience leading incident detection and response, and post-incident review
- Excellent communication and collaboration skills, with the ability to influence engineering and leadership and mentor others on security best practices
- BS/MS in computer science, information security, or related field, or equivalent experience
Nice to have
- Experience defining detection strategy with log aggregation and analysis (SIEM)
- Experience with compliance-automation or evidence-collection tooling (e.g. Vanta, Drata, Secureframe)
- Cloud and code security engineering experience — infrastructure-as-code security, SAST/DAST, secure SDLC
- Threat modeling and security architecture review experience
- Relevant certifications (CISSP, CCSP, or similar)
Why Work at ALICE?
- We’re a small, early stage team that is growing with plenty of opportunity for your professional and personal growth - and we’re here to support you in that growth
- We’re building a truly innovative and category-defining artificial intelligence product in one of the world’s largest and most important industries
- Significant portion of our time is spent on research to find the best ways to solve problems for our users
- Flexible vacation policy and open to remote workers
- We believe in sharing our success in the form of equity, which is part of the compensation for all employees