Senior Compliance EngineerNew$356K
The opportunity
The Corporate Assurance Team manages enterprise cybersecurity governance, risk, and compliance (GRC) by implementing and operationalizing global compliance frameworks across Anduril's corporate and product environments. The team serves as the bridge between regulatory…
What you'll do
Design, develop, and maintain Infrastructure as Code (IaC) and Policy as Code: (PaC) that enforce compliance with NIST SP 800-171 and 800-53, CMMC, and other applicable frameworks, enabling developers to deploy CMMC-certified applications using pre-packaged, compliant infrastructure templates.
Architect, build, and deploy robust, scalable security controls across: Anduril's corporate, development, and production cloud environments (AWS, Azure, GCP) and on-premise environments.
Develop and automate IaC pipelines for managing and scaling cloud deployments: securely and efficiently, including automated pipelines for deploying infrastructure, applications, and updates.
Build automation for procedural compliance controls, generating compliance: and audit artifacts at scale without manual intervention.
Develop security models that integrate Continuous Monitoring (ConMon), DISA: STIG scanning, and compliance reporting into a unified, automated workflow.
Ensure that compliance requirements for rapid, secure deployments translate: into robust, repeatable tool chains.
What they're looking for
- Experience hardening and monitoring Kubernetes clusters (EKS, GKE, AKS).
- Experience with Cloud Security Posture Management (CSPM) or cloud-native threat detection tooling.
- Familiarity with CI/CD pipelines and experience securing the software supply chain.
- Experience with security assessment methodologies and vulnerability management programs.
- Relevant certifications such as AWS Solutions Architect, Certified Kubernetes: Administrator (CKA), CISSP, CISM, or CompTIA Security+.
- Experience working in fast-paced, high-growth defense technology environments