Compliance Engineer - Public Sector
Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.
About the job
Responsibilities
- Lead the technical roadmap for FedRAMP Continuous Monitoring, transitioning manual reporting to automated, real-time telemetry.
- Translate NIST SP 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering and product solutions.
- Architect compliance-as-code solutions using native platform capabilities and custom automations.
- Engineer evidence-generation frameworks to reduce manual effort for 3PAO assessments and automate compliance validation.
- Conduct technical risk assessments and root-cause analysis of compliance findings.
- Guide implementation of compensating controls and cloud hardening measures.
- Own the technical compliance documentation lifecycle, including Security Decision Records (SDRs).
- Collaborate with legal, product, engineering, DevOps, architecture, security, and federal customer teams on technical compliance verification and validation.
- Mentor colleagues on FedRAMP and Department of War compliance best practices and contribute to internal training.
Requirements
- 6+ years of experience in security engineering, DevOps, and systems engineering, including developing processes and writing code to solve security and compliance problems.
- 4+ years of expertise with NIST SP 800-53, FedRAMP High baselines, and DoW SRG overlays.
- Understanding of FR 20x and CR26 rulesets for Rev. 5 authorizations and their impact on cloud service providers.
- Experience in cloud-native environments with DevSecOps technologies, including CI/CD, containers, and Kubernetes.
- Strong scripting and Infrastructure as Code experience with Shell scripting, Python, and Terraform or OpenTofu.
- Experience with cloud platforms in government environments.
- Must meet the U.S. person definition under EAR Part 772 and ITAR 120.15 and reside in the contiguous United States.
Preferred Qualifications
- AWS GovCloud experience.
- Azure Government or Google Cloud for Government (Assured Workloads) experience, or equivalent government-cloud experience.
- Experience with microservices, GitOps, observability, logging, SIEM, and security platforms.
- Experience with Packer, configuration-as-code tools, and policy-as-code tools.
- Experience automating compliance validation with cloud-native tools.
- Familiarity with AI-assisted development tools such as Claude Code or OpenAI Codex.
Compensation
- Base salary range: $174,000–$238,000 USD.
- Compensation also includes bonus, equity, and benefits.
Skills
Nist Sp 800-53, FedRAMP, Kubernetes, CI/CD, Containers, Shell Scripting, Python, Terraform, Opentofu, Aws Govcloud, Azure Government, GCP, GitOps, SIEM, Policy As Code
Similar jobs
Security Engineering jobsThe Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.
Own and scale Jasper’s governance, risk, and compliance program for AI-native SaaS products, leading audits, risk and vendor programs, policy management, and AI governance. The role requires 8+ years of GRC experience, expertise in major security frameworks, cloud and AI fluency, and strong cross-functional communication.
Own and scale Starburst’s application and product security program through secure-by-default engineering, automated vulnerability management, threat modeling, and autonomous offensive testing. The role requires 5–7 years of security-focused experience, strong software supply chain expertise, and the ability to engage enterprise customers and lead engineers.
Leads product security incident response for Snowflake’s AI and agentic products, developing detection, containment, remediation, and automation capabilities. Requires 5+ years in security, incident command experience, cloud expertise, and knowledge of AI/ML attack surfaces.
Leads product security incident response for Snowflake’s AI products and infrastructure, developing detection, containment, and remediation capabilities for LLM and agentic threats. Requires 5+ years in security, incident command experience, cloud-native expertise, and strong knowledge of AI attack surfaces.