Lead Security Engineer, GRCPosted today$356K

The opportunity

Anduril's Security Engineering team is looking for a Governance, Risk, and Compliance Engineering Lead to build the engineering core of our GRC program: the pipeline and tooling that turn Anduril's systems into continuous, defensible evidence of compliance, replacing the manual…

What you'll do

  • Build the pipeline that collects evidence from Anduril's systems and maps it to a normalized control model

  • Construct reusable collectors and schemas as reference architectures so each: new control is assembly, not reinvention

  • Stand up the system of record for controls, mappings, and evidence, and drive the build-vs-buy analysis

  • Surface control drift and route findings to system owners with clear remediation and risk-acceptance paths

  • Translate frameworks (CMMC, NIST 800-171, FedRAMP/IL5) into automatable technical checks and pass/fail signals

  • Set technical direction and mentor a growing engineering team

What they're looking for

  • Experience with continuous control monitoring or GRC platforms (Vanta, Drata,: Hyperproof, OneTrust), or building bespoke equivalents
  • Experience with security data lakes, log aggregation, or building data marts for querying
  • Familiarity with STIG/ConMon scanning, CSPM, or Kubernetes hardening
  • Experience in fast-paced, high-growth defense technology environments
Lead Security Engineer, GRC at Anduril Industries | Role Match