Source Job

US Unlimited PTO

  • Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
  • Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
  • Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.

Cybersecurity Compliance FedRAMP GRC Cloud

20 jobs similar to Senior Security Compliance Engineer, Public Sector

Jobs ranked by similarity.

$150,000–$200,000/yr
US

  • Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
  • Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
  • Represent the compliance program in customer-facing discussions and security due diligence reviews.

Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.

US

  • Lead technical roadmap for FedRAMP Continuous Monitoring, transitioning manual reporting to automated telemetry and validation.
  • Design compliance-as-code frameworks and automated evidence generation to reduce manual effort during assessments and audits.
  • Partner with cross-functional teams to define compliance verification requirements and mentor on FedRAMP practices.

Our partner is a technology company specializing in security and compliance for public sector cloud environments. They foster a collaborative, fast-moving culture with significant autonomy and cross-functional exposure.

$174,000–$238,000/yr
US

  • Lead the technical roadmap for FedRAMP Continuous Monitoring, moving from manual reporting to automated, real-time telemetry.
  • Architect compliance outcomes by translating NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering solutions.
  • Engineer evidence generation frameworks to reduce manual effort for 3PAO assessments and automate compliance validation.

Wiz provides an AI-powered platform to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. It is one of the fastest-growing startups, trusted by over 65% of the Fortune 100, with a global team and a culture that values world-class talent.

US Unlimited PTO 16w maternity 16w paternity

  • Build and own federal compliance frameworks for FedRAMP, NIST, and CMMC.
  • Interpret controls at the mechanics level and author precise technical guidance.
  • Lead Vanta's machine-readable future with OSCAL and FedRAMP 20x.

Vanta helps businesses earn and prove trust by automating security monitoring and compliance. Founded in 2018, the company has a kind and talented team and is used by thousands of companies.

$230,000–$270,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Own and manage federal compliance frameworks including FedRAMP, NIST, CMMC, DFARS, and StateRAMP.
  • Translate regulatory controls into automated tests and machine-readable specifications for continuous authorization.
  • Collaborate with Engineering, Product, and Design to shape product capabilities and influence strategy.

Our partner company is a technology organization focused on federal compliance automation, serving organizations from emerging companies to large enterprises. They operate with a remote-first culture and value autonomy, accuracy, and scalability.

US

  • Execute NIST SP 800-53 control mappings and implement security baselines.
  • Develop and maintain SSPs, POA&Ms, and authorization documentation.
  • Support continuous monitoring and gap assessments for ATO and FedRAMP.

This company provides cybersecurity and compliance consulting services, supporting defense contractors and federal organizations with NIST and FedRAMP requirements. It is an early-stage, remote-first company with a collaborative culture focused on federal cybersecurity.

$115,000–$186,000/yr
US

  • Lead compliance assessments and build-out of IL4/IL5 authorizations for DoD Cloud Computing Security Requirements Guide.
  • Maintain and evolve compliance posture for FedRAMP High, NIST SP 800-53, and other federal frameworks.
  • Serve as GRC liaison to engineering teams, translating complex federal compliance requirements into technical specifications for AWS environments.

Horizon3 is a fast-growing, remote cybersecurity company that provides autonomous pentesting through its NodeZero platform. The company is a fusion of former Special Operations cyber operators and engineers, fostering a culture of respect, collaboration, ownership, and results.

US

  • Support day-to-day information security operations and maintain strong operational security posture across the platform.
  • Develop and maintain the System Security Plan and other cybersecurity documentation for security authorization and compliance.
  • Support FedRAMP High and DoD IL5 compliance activities including continuous monitoring, audits, assessments, and remediation.

The partner company operates a secure, mission-focused technology platform supporting government and commercial teams. It is an equal opportunity workplace committed to considering qualified candidates from all backgrounds.

US Unlimited PTO

  • Own the security program day-to-day, pursuing ISO 27001 certification and FedRAMP readiness.
  • Manage GRC tool (Vanta), maintain SOC 2 Type II, and run vendor security reviews.
  • Answer customer security questionnaires and ensure compliance documents are accurate.

Massed Compute is building a modern GPU cloud platform for AI and high-performance compute workloads. We are a lean, ambitious team operating in one of the most important technology markets in the world.

$114,800–$173,250/yr
US

  • Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, and remediation.
  • Drive recurring continuous monitoring and evidence workflows across multiple teams.
  • Support vulnerability detection and response, including reconciling findings from tools like Wiz, Nessus, and Burp.

Abnormal protects the humans behind the world's most critical organizations from AI-powered cybercrime. 4,500+ enterprises trust their behavioral AI platform.

Canada

  • Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
  • Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
  • Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.

Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.

Global 5w PTO

  • Automate governance, risk, and compliance frameworks including ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials.
  • Engineer GRC workflows with internal systems to support compliance by design.
  • Translate compliance requirements into technical specifications for engineering teams and non-technical stakeholders.

Pleo builds spend solutions that make managing money seamless for finance teams and employees. They are a driven, progressive team of 850+ people from over 100 nationalities, committed to delivering the future of business spending.

United States Unlimited PTO

  • Own and strengthen the controls environment, ensuring compliance requirements are effectively implemented and maintained.
  • Support and mature the GRC program, including SOC 2 operations and alignment with frameworks such as NIST.
  • Manage vendor risk assessments, regulatory licensing, and security issue lifecycle across jurisdictions.

Mesh enables consumers to pay and be paid with any asset, bridging crypto payments into everyday commerce. Backed by investors like PayPal Ventures and Paradigm, the company is building infrastructure for the global economy with a small, fast-moving team.

$139,000–$218,000/yr
US

  • Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and Management Review Meetings.
  • Support ISO 27001 and SOC 2 Type 2 audits from readiness through certification, including evidence preparation.
  • Lead the security policy program and collaborate across teams to translate compliance requirements into practical practices.

Mozilla Corporation is a non-profit-backed tech company behind Firefox, focused on making the internet better. With 225+ million monthly users, it is a wholly owned subsidiary of the Mozilla Foundation, promoting privacy, AI, and open-source.

US Unlimited PTO

  • Define cross-domain product strategy and multi-quarter roadmap for the U.S. public sector cloud portfolio, balancing parity, compliance, and scalability.
  • Shape the market point of view for regulated public sector, anticipating parity blockers and validating federal, DoD, and SLED nuances.
  • Lead multi-team and multi-VP programs, influencing engineering, security, legal, and go-to-market teams to align on strategy and unblock delivery.

ServiceNow is the AI control tower for business reinvention, helping 85% of the Fortune 500 work smarter, faster, and better. They are building an AI-native culture where technology and talent are unstoppable together.

US

  • Lead and mature the GRC program across SOC 2, ISO 27001, PCI DSS, and other compliance frameworks, including audit preparation and evidence collection.
  • Own the annual security risk assessment process using NIST SP 800-30 methodology, including stakeholder interviews and risk scoring.
  • Drive security awareness training, AI governance, and Data Loss Prevention program development while collaborating with cross-functional teams.

RainFocus is a rapidly growing software company that provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, growing fast, and building a culture that is challenging, fun, and exciting.

Global

  • Spearhead FedRAMP authorization and international sovereign cloud strategy.
  • Bridge federal security controls with scalable engineering execution.
  • Transform customer requirements into technical solutions meeting regulatory mandates.

Vultr makes high-performance cloud infrastructure easy, affordable, and locally accessible for enterprises and AI innovators. As the world's largest privately-held cloud infrastructure company with a $3.5 billion valuation, it serves hundreds of thousands of customers across 185 countries.

US Unlimited PTO 18w maternity 12w paternity

  • Design and operate a continuous monitoring and authorization capability portable across frameworks.
  • Translate CMMC 2.0 and FedRAMP requirements into practical controls and evidence pipelines.
  • Partner with engineering and product security to connect federal requirements to cloud-native systems.

Chainguard delivers hardened, secure builds of open source software to help organizations build faster and stay compliant. They are venture-backed by leading investors and serve Fortune 500 enterprises including OpenAI, Snap Inc., and Snowflake.

$170,000–$190,000/yr
US

  • Lead end-to-end service delivery for cybersecurity professional services, ensuring quality, timelines, and compliance for a portfolio of customers.
  • Drive operational strategy, governance frameworks, and KPIs for predictable delivery across FedRAMP advisory, implementation, and continuous monitoring programs.
  • Mentor and grow high-performing technical teams including project managers, cloud architects, security engineers, and analysts.

Quantum Sky engineers cybersecurity and cloud solutions for U.S. Federal agencies, focusing on FedRAMP, RMF, and post-quantum mission needs. The company fosters a collaborative, innovative, mission-driven culture with a high-performing team of technical professionals.

US

  • Support enterprise cybersecurity governance, compliance, and risk management programs.
  • Conduct security control assessments, audit readiness, and policy development.
  • Coordinate with technical teams and executive leadership to drive cybersecurity modernization.

ERP International is a nationally respected provider of health, science, and technology solutions supporting government and commercial clients. The company has been named a Top Workplace by WTOP News for 7 years and offers a culture of employee recognition, community outreach, and professional development.