Lead Security Engineer, GRCPosted today$356K
The opportunity
Anduril's Security Engineering team is looking for a Governance, Risk, and Compliance Engineering Lead to build the engineering core of our GRC program: the pipeline and tooling that turn Anduril's systems into continuous, defensible evidence of compliance, replacing the manual…
What you'll do
Build the pipeline that collects evidence from Anduril's systems and maps it to a normalized control model
Construct reusable collectors and schemas as reference architectures so each: new control is assembly, not reinvention
Stand up the system of record for controls, mappings, and evidence, and drive the build-vs-buy analysis
Surface control drift and route findings to system owners with clear remediation and risk-acceptance paths
Translate frameworks (CMMC, NIST 800-171, FedRAMP/IL5) into automatable technical checks and pass/fail signals
Set technical direction and mentor a growing engineering team
What they're looking for
- Experience with continuous control monitoring or GRC platforms (Vanta, Drata,: Hyperproof, OneTrust), or building bespoke equivalents
- Experience with security data lakes, log aggregation, or building data marts for querying
- Familiarity with STIG/ConMon scanning, CSPM, or Kubernetes hardening
- Experience in fast-paced, high-growth defense technology environments