Own the architecture and implementation of Onebrief's GRC framework for defense/government compliance (FedRAMP, CMMC, RMF, SOC 2). Translate regulatory requirements into technical security controls in close partnership with engineering teams.
160k – 200k/yr
Remote5+ YOESecurity Engineering
About the role
What You’ll Do
Own the design and implementation of Onebrief's GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.
Build and manage the control environment, including policies, procedures, and evidence collection systems.
Design and implement technical security controls in partnership with Product, Engineering, Infrastructure and Corporate IT including access management, logging, encryption, and vulnerability management practices.
Partner with Engineering, Infrastructure, and Corporate IT to translate compliance requirements into working technical controls, not just documented ones.
Minimum Qualifications
5+ years of experience in GRC, security engineering, or a combined compliance and technical security role
Direct experience with RMF, FedRAMP, CMMC, or equivalent federal compliance frameworks
Hands-on experience implementing technical security controls, such as IAM, logging and monitoring, network segmentation, or encryption
Working knowledge of security control frameworks such as NIST 800-53 or NIST 800-171
Experience managing third-party audits and assessor relationships
Strong written communication skills, with the ability to translate regulatory language into clear technical and internal guidance
Preferred Qualifications
Experience in a startup or scaling company environment
Background in military, defense, or government contracting
Relevant certifications, such as CISSP, CISA, CRISC, or a technical security certification (AWS Solutions Architect)
Experience building GRC automation using infrastructure-as-code or scripting
Indicators of Success
Identify and remediate at least one significant security control gap before it surfaces in an external audit
Serve as the trusted point of contact for customer security questionnaires and compliance inquiries
Be recognized by engineering and security teams as a partner who makes compliance workable and technically sound, not just another gate to pass
Win buy-in from engineering leads who previously treated compliance requests as low priority
Get through a customer or third-party security review without escalations or fire drills
Tools, Systems & Technologies
GRC platforms (such as RegScale, eMASS, or similar)
Cloud security tooling relevant to Federal environments
Logging systems
CI/CD pipelines
Infrastructure-as-code for control automation
Skills
GRCFedRAMPcmmcrmfSOC 2nist 800-53nist 800-171IAMcisspcisacriscaws solutions architectInfrastructure As Code
Build automation and internal tooling to enforce security controls, integrate identity/cloud systems, automate compliance evidence collection, and enable self-remediation across Skydio's multi-tenant cloud and corporate environments. Requires 3+ years software/security engineering experience and strong coding skills in Python or Go.
160k – 210k/yr
Hybrid3+ YOESecurity Engineering
Software Engineer - Secret, Cryptographic and Identity Infrastructure
SnowflakeBellevue, WA
Build and scale core security infrastructure for secret management, identity, authentication, and end-to-end encryption across Snowflake's multi-cloud platform.
160k – 230k/yr
On-siteSecurity Engineering
Software Engineer - Trust Center
SnowflakeBellevue, WA
Build and operate large-scale security, governance, and compliance platform features at Snowflake. Design extensible frameworks and high-availability services using Java, Python, and SQL.
160k – 230k/yr
On-site5+ YOESecurity Engineering
Security Engineer
JuiceboxSan Francisco, CA
Builds foundational security systems for AI SaaS infrastructure, including secure execution for AI agents, AWS guardrails with Terraform, identity management, and observability. Requires strong application security, DevOps, and AWS experience with a focus on automation and developer-friendly tools.
160k – 250k/yr
On-siteSecurity Engineering
Security Infrastructure Engineer
PointOneNew York, NY
Hands-on engineer owning security, scalability, and cost optimization of AWS infrastructure. Hardens IAM, networking, secrets management; leads threat modeling, incident response, and architecture reviews for high-sensitivity legal systems. Requires 5+ years AWS production experience.