About the company
Our partner is looking for a Compliance Engineer - Public Sector based in United States. This is a senior individual contributor role focused on engineering scalable compliance solutions for highly regulated government cloud environments.
Responsibilities
- Lead the technical roadmap for FedRAMP Continuous Monitoring, transitioning manual reporting processes toward automated, real-time telemetry and validation.
- Translate NIST SP 800-53 Rev. 5, FedRAMP High, CR26, and applicable DoW SRG requirements into scalable engineering, product, and compliance-as-code solutions.
- Design and implement compliance-as-code frameworks, evidence-generation capabilities, and automated validation processes to reduce manual effort during assessments and audits.
- Conduct technical risk assessments, investigate root causes of compliance findings, and recommend compensating controls, remediation strategies, and cloud-hardening measures.
- Own the technical lifecycle of compliance documentation, including Security Decision Records and supporting evidence.
- Partner with legal, product, engineering, DevOps, architecture, security, and federal customer teams to define compliance verification requirements for new services and features.
- Evaluate and improve compliance processes, identifying opportunities to automate workflows, simplify operations, and increase productivity and audit readiness.
- Mentor colleagues on FedRAMP and Department of Defense compliance practices and contribute to internal training and knowledge-sharing initiatives.
Requirements
- 6+ years of experience across security engineering, DevOps, systems engineering, or closely related disciplines, including a demonstrated ability to develop processes and write code that addresses security and compliance challenges.
- 4+ years of hands-on expertise with NIST SP 800-53, FedRAMP High baselines, and DoW SRG overlays, including experience assessing and reducing compliance risk.
- Strong understanding of the FR 20x and CR26 rulesets for Revision 5 authorizations and their implications for Cloud Service Providers.
- Experience working in cloud-native environments using DevSecOps practices, including CI/CD, containers, Kubernetes, and modern observability or security tooling.
- Strong scripting and Infrastructure as Code capabilities, particularly with Shell scripting, Python, Terraform or OpenTofu; familiarity with AI-assisted development tools such as Claude Code or OpenAI Codex is preferred.
- Experience with cloud platforms supporting government or public-sector environments.
- Experience with AWS GovCloud is preferred, along with exposure to Azure Government, Google Cloud for Government/Assured Workloads, or equivalent environments.
- Familiarity with Microservices, GitOps, SIEM, logging, observability, Configuration as Code, Policy as Code, Packer, and cloud-native compliance automation is advantageous.
- Strong analytical, risk assessment, problem-solving, and communication skills, with the ability to translate complex regulatory requirements into practical technical solutions.
- Collaborative mindset with the ability to work effectively across highly technical and business-oriented teams.
Conditions
- Base salary range of $174,000–$238,000 USD for full-time U.S. employment.
- Additional performance-based bonus and equity opportunities.
- Comprehensive employee benefits.
- Opportunity to work on high-impact cloud and AI security challenges within the public sector.
- Significant autonomy and ownership over compliance engineering strategy and technical roadmaps.
- Cross-functional exposure to engineering, security, product, legal, architecture, and federal customer teams.
- Remote opportunity for eligible candidates residing in the contiguous United States.
- Applicants must meet the applicable U.S. person requirements under EAR Part 772 and ITAR 120.15 and must have the legal right to work without visa sponsorship.