Skip to content
WizWiz

Compliance Engineer - Public Sector

Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.

About the job

Responsibilities

  • Lead the technical roadmap for FedRAMP Continuous Monitoring, transitioning manual reporting to automated, real-time telemetry.
  • Translate NIST SP 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering and product solutions.
  • Architect compliance-as-code solutions using native platform capabilities and custom automations.
  • Engineer evidence-generation frameworks to reduce manual effort for 3PAO assessments and automate compliance validation.
  • Conduct technical risk assessments and root-cause analysis of compliance findings.
  • Guide implementation of compensating controls and cloud hardening measures.
  • Own the technical compliance documentation lifecycle, including Security Decision Records (SDRs).
  • Collaborate with legal, product, engineering, DevOps, architecture, security, and federal customer teams on technical compliance verification and validation.
  • Mentor colleagues on FedRAMP and Department of War compliance best practices and contribute to internal training.

Requirements

  • 6+ years of experience in security engineering, DevOps, and systems engineering, including developing processes and writing code to solve security and compliance problems.
  • 4+ years of expertise with NIST SP 800-53, FedRAMP High baselines, and DoW SRG overlays.
  • Understanding of FR 20x and CR26 rulesets for Rev. 5 authorizations and their impact on cloud service providers.
  • Experience in cloud-native environments with DevSecOps technologies, including CI/CD, containers, and Kubernetes.
  • Strong scripting and Infrastructure as Code experience with Shell scripting, Python, and Terraform or OpenTofu.
  • Experience with cloud platforms in government environments.
  • Must meet the U.S. person definition under EAR Part 772 and ITAR 120.15 and reside in the contiguous United States.

Preferred Qualifications

  • AWS GovCloud experience.
  • Azure Government or Google Cloud for Government (Assured Workloads) experience, or equivalent government-cloud experience.
  • Experience with microservices, GitOps, observability, logging, SIEM, and security platforms.
  • Experience with Packer, configuration-as-code tools, and policy-as-code tools.
  • Experience automating compliance validation with cloud-native tools.
  • Familiarity with AI-assisted development tools such as Claude Code or OpenAI Codex.

Compensation

  • Base salary range: $174,000–$238,000 USD.
  • Compensation also includes bonus, equity, and benefits.

Skills

Nist Sp 800-53, FedRAMP, Kubernetes, CI/CD, Containers, Shell Scripting, Python, Terraform, Opentofu, Aws Govcloud, Azure Government, GCP, GitOps, SIEM, Policy As Code

Jasper

Jasper

United States

Senior Security Engineer
$174k+/yrRemote8+ YOESecurity Engineering

The Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.

Jasper

Jasper

United States

Senior GRC Lead
$174k+/yrRemote8+ YOESecurity Engineering

Own and scale Jasper’s governance, risk, and compliance program for AI-native SaaS products, leading audits, risk and vendor programs, policy management, and AI governance. The role requires 8+ years of GRC experience, expertise in major security frameworks, cloud and AI fluency, and strong cross-functional communication.

Starburst

Starburst

Boston, MA

Senior Application Security Engineer
$175k+/yrOn-site5+ YOESecurity Engineering

Own and scale Starburst’s application and product security program through secure-by-default engineering, automated vulnerability management, threat modeling, and autonomous offensive testing. The role requires 5–7 years of security-focused experience, strong software supply chain expertise, and the ability to engage enterprise customers and lead engineers.

Snowflake

Snowflake

United States

Senior Security Engineer, Incident Response
$176k+/yrRemote5+ YOESecurity Engineering

Leads product security incident response for Snowflake’s AI and agentic products, developing detection, containment, remediation, and automation capabilities. Requires 5+ years in security, incident command experience, cloud expertise, and knowledge of AI/ML attack surfaces.

Snowflake

Snowflake

Menlo Park, CA
Senior Security Engineer, AI Incident Response
$176k+/yrHybrid5+ YOESecurity Engineering

Leads product security incident response for Snowflake’s AI products and infrastructure, developing detection, containment, and remediation capabilities for LLM and agentic threats. Requires 5+ years in security, incident command experience, cloud-native expertise, and strong knowledge of AI attack surfaces.