About this role
IBM Quantum is an industry-first initiative to build universal quantum computers for business, engineering, and science. This effort includes advancing the entire quantum computing technology stack and exploring applications to make quantum broadly usable and accessible. With a worldwide network of Fortune 500 companies, academic institutions, researchers, educators, and enthusiasts, we are committed to driving innovation for our clients in the IBM Quantum Network and the Qiskit Community. As IBM Quantum continues to expand its software, cloud, and infrastructure footprint, maintaining a strong security and compliance posture is critical to enabling trust, scalability, and regulatory readiness. We are seeking a Compliance Security Engineer (SOC 2 Compliance Focal) to help drive and automate our compliance program across Quantum software, cloud services, and infrastructure environments. IBM is seeking a Compliance Focal to join the IBM Quantum security team in the US, reporting to T. J. Watson Research Center in Yorktown Heights, NY. This role will focus on driving and automating the organization's compliance program for a high-tech and sensitive environment like quantum computing, ensuring that security controls, evidence collection, and audit processes are efficient, repeatable, and scalable. The candidate will own the design and automation of compliance workflows, reducing manual effort in control monitoring, evidence gathering, and audit readiness across the software and infrastructure stack. This position is critical in maintaining the organization's compliance posture against frameworks such as SOC 2, and supporting the pursuit of additional certifications such as FedRAMP, by proactively identifying control gaps, building automated compliance tooling, and working closely with teams such as IBM's CISO, security engineering, and development groups to embed compliance requirements throughout the product lifecycle. Good communication skills and the ability to handle fast-paced, complex work are essential. A self-motivated and driven individual who can work independently as well as in multi-team settings. 4+ years of experience in compliance, security engineering, audit, or related roles, with direct experience in SOC 2 compliance programs. Degree in Computer Science, Information Security, or equivalent work experience. Hands-on experience with SOC 2 compliance, including control design, evidence collection, readiness assessments, and supporting external audits. Experience building or operating compliance automation tooling to continuously monitor controls, collect evidence, and flag drift or gaps, reducing reliance on manual, point-in-time audit processes. Solid understanding of core security principles, including identity and access management (IAM), data encryption, vulnerability management, and security incident response, and how these map to compliance controls. Experience working with cloud infrastructure (IBM Cloud), containerization (e.g., Docker, Kubernetes), and cloud-based identity management systems in the context of compliance monitoring. Experience working in DevSecOps or secure software development lifecycle (SDLC) environments, partnering with engineering teams to integrate compliance checks into CI/CD pipelines and everyday development practices. Collaboration and Communication Skills: the ability to work effectively with cross-functional teams, including product development, operations, and the CISO team, is essential. Strong communication skills are required to articulate compliance requirements, risks, and remediation plans to both technical and non-technical stakeholders. Understanding of networking concepts and security best practices. Ability to independently manage compliance initiatives and coordinate activities across multiple stakeholders. Experience supporting FedRAMP, including familiarity with NIST SP 800-53 controls, system security plans (SSPs), continuous monitoring, and authorization processes. Experience or familiarity with the security and compliance needs of quantum computing environments, especially given the sensitivity and complexity of quantum software and infrastructure. Expertise in using security and compliance tooling, particularly governance, risk, and compliance (GRC) automation platforms. Understanding of additional regulatory frameworks such as GDPR, HIPAA, and other industry-specific regulations, and the ability to navigate multi-framework compliance audits. Experience developing automation solutions using scripting or programming languages such as Python, Bash, or similar technologies. Experience working in highly regulated, research-focused, or advanced technology environments. Familiarity with cloud security and compliance practices within IBM Cloud, AWS, Azure, or other enterprise cloud platforms. Experience implementing compliance controls within CI/CD pipelines and Infrastructure-as-Code (IaC) environments. United States Infrastructure & Technology Hybrid Professional Yorktown Heights, US (0147) International Business Machines Corporation