SREs often work with compliance requirements.
SOC 2:
- Trust Services Criteria: security, availability, confidentiality, privacy, processing integrity
- Requires documented controls and audits
- Common for SaaS companies
PCI-DSS:
- Payment card data protection
- Strict network segmentation
- Encryption requirements
HIPAA:
- Healthcare data protection
- Audit logging requirements
Interview tip: You don't need deep compliance knowledge. Know that compliance affects infrastructure decisions (logging, encryption, access control) and that you'd work with security teams.