Careers
Build GRC programs that outlast the engagement.
Semper Sec is a fully remote firm of security and compliance practitioners. We are hiring consultants and auditors who want to own client programs end to end, across ISO 27001, SOC 2, HITRUST, PCI, and NIST.
What we’re building.
A firm where the work speaks for itself: enterprise GRC programs that still run after we hand them over. Everyone we hire works on that outcome directly. About Semper Sec →
What working here looks like.
We invest in our people. In practice that means the work itself, the range of it, who you do it beside, and a remote model with documented benefits.
Client work that matters
You work on programs enterprises depend on, through the full lifecycle from assessment to an operating capability. You see decisions through instead of handing them off.
Breadth of frameworks and industries
Engagements span ISO 27001, SOC 2, HITRUST, PCI, and NIST across a range of client industries, so your exposure widens faster than it would inside a single organization.
Senior practitioners beside you
Engagements are led by practitioners who have run these programs from the inside, and they do the work rather than reviewing it from a distance.
Room to grow
Scope, framework exposure, and client responsibility widen as you take them on. Growth here comes from the work you lead.
Supportive and structured
Remote does not mean unsupported. Engagements carry defined scope, priorities, and timelines, and colleagues who have solved the problem before.
Remote and flexible
Every role is remote. Full-time employees have Flexible Time Off alongside health, dental, vision, and 401(k).
Open roles.
Three roles are open. Each is remote. Click a card for the full description, compensation, and how to apply.
Security Consultant
Full-time employee • $120,000–$150,000 • Remote
Design and implement unified compliance programs across ISO 27001, SOC 2, HITRUST, and related frameworks, from readiness through audit and certification.
Security Consultant, Part-Time Contractor
Independent contractor • $50–$70/hour • Remote
The consulting scope of the full-time role on a part-time contract, compensated hourly. Employee benefits do not apply.
IT Security Auditor
Full-time employee • $80,000–$120,000 • Remote
Own the internal audit lifecycle for client information security management systems, and lead readiness work across ISO 27001, SOC 2, PCI, and NIST.
How to apply.
Send your resume/CV to jobs@sempersec.com with the job title in the subject line. If none of the open roles fit, write anyway and tell us which part of the program you want to work on.
Benefits for full-time employees.
These are the benefits the full-time job descriptions document. We do not list anything beyond them.
Health and dental
Vision
Flexible Time Off
401(k)
Part-time contractor engagements are compensated at an hourly rate and do not include these employee benefits.
Employee perspectives.
Published on our careers page by people who work here.
Working at Semper Sec has provided me with the freedom and flexibility I value, all within a supportive and structured environment. Even in a fully remote setting, there’s a strong sense of teamwork and collaboration. Being part of this team has truly helped me grow professionally.
Semper Sec’s fully remote work model offers a flexible and supportive environment, allowing employees to manage personal needs in the comfort and privacy of their own homes. This approach promotes both productivity and well-being throughout the workday.
Semper Sec is a fantastic place to work, thanks to exceptional leadership that truly inspires and supports the team. The positive work environment and strong sense of collaboration make it a rewarding and motivating organization to be part of.
Feedback shared by current Semper Sec employees; names withheld.
Before you write.
It helps to know how we work first: read why Semper Sec exists, how our service lines fit together, and who leads the engagements you would be joining.
Start with the program, not the framework.
Talk with a senior advisor about the decisions, ownership, and operating capability your organization needs next.
A conversation with a senior practitioner, not a sales gatekeeper.