Compliance Engineer - Public Sector
About the role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Compliance Engineer - Public Sector based in the United States. This is a senior individual contributor role focused on engineering scalable compliance solutions for highly regulated government cloud environments.
Responsibilities
- Lead the technical roadmap for FedRAMP Continuous Monitoring, transitioning manual reporting processes toward automated, real-time telemetry and validation.
- Translate NIST SP 800-53 Rev. 5, FedRAMP High, CR26, and applicable DoW SRG requirements into scalable engineering, product, and compliance-as-code solutions.
- Design and implement compliance-as-code frameworks, evidence-generation capabilities, and automated validation processes to reduce manual effort during assessments and audits.
- Conduct technical risk assessments, investigate root causes of compliance findings, and recommend compensating controls, remediation strategies, and cloud-hardening measures.
- Own the technical lifecycle of compliance documentation, including Security Decision Records and supporting evidence.
- Partner with legal, product, engineering, DevOps, architecture, security, and federal customer teams to define compliance verification requirements for new services and features.
- Evaluate and improve compliance processes, identifying opportunities to automate workflows, simplify operations, and increase productivity and audit readiness.
- Mentor colleagues on FedRAMP and Department of Defense compliance practices and contribute to internal training and knowledge-sharing initiatives.
Requirements
- 6+ years of experience across security engineering, DevOps, systems engineering, or closely related disciplines, including a demonstrated ability to develop processes and write code that addresses security and compliance challenges.
- 4+ years of hands-on expertise with NIST SP 800-53, FedRAMP High baselines, and DoW SRG overlays, including experience assessing and reducing compliance risk.
- Strong understanding of the FR 20x and CR26 rulesets for Revision 5 authorizations and their implications for Cloud Service Providers.
- Experience working in cloud-native environments using DevSecOps practices, including CI/CD, containers, Kubernetes, and modern observability or security tooling.
- Strong scripting and Infrastructure as Code capabilities, particularly with Shell scripting, Python, Terraform or OpenTofu; familiarity with AI-assisted development tools such as Claude Code or OpenAI Codex is preferred.
- Experience with cloud platforms supporting government or public-sector environments.
- Experience with AWS GovCloud is preferred, along with exposure to Azure Government, Google Cloud for Government/Assured Workloads, or equivalent environments.
- Familiarity with Microservices, GitOps, SIEM, logging, observability, Configuration as Code, Policy as Code, Packer, and cloud-native compliance automation is advantageous.
- Strong analytical, risk assessment, problem-solving, and communication skills, with the ability to translate complex regulatory requirements into practical technical solutions.
- Collaborative mindset with the ability to work effectively across highly technical and business-oriented teams.
Benefits
Base salary range of $174,000–$238,000 USD for full-time U.S. employment. Additional performance-based bonus and equity opportunities. Comprehensive employee benefits. Opportunity to work on high-impact cloud and AI security challenges within the public sector. Significant autonomy and ownership over compliance engineering strategy and technical roadmaps. Remote opportunity for eligible candidates residing in the contiguous United States. Applicants must meet the applicable U.S. person requirements under EAR Part 772 and ITAR 120.
Schedule
Full-time position.
Pay
Base salary range of $174,000–$238,000 USD for full-time U.S. employment.
Application Deadline
October 30, 2026.