Senior Compliance Automation Engineer
Listed on 2026-06-06
-
IT/Tech
Cybersecurity, Systems Engineer
Denver, CO or Long Beach, CA or SF Bay area, CA or Washington, DC
Our MissionTrue Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors to secure the space environment and counter threats from the ultimate high ground.
Our Values- Be the offset. We create asymmetric advantages with creativity and ingenuity.
- What would it take? We challenge assumptions to deliver ambitious results.
- It’s the people. Our team is our competitive advantage and we are better together.
We are seeking a Senior Compliance Automation Engineer to join our Governance, Risk, and Compliance (GRC) team and design and build True Anomaly's compliance automation platform from the ground up. This is a greenfield engineering role focused on building a purpose‑built, continuous compliance monitoring platform for a hybrid environment of on‑premises classified systems and multi‑cloud infrastructure (AWS Gov Cloud, Azure Government).
This role sits at the intersection of software engineering, Dev Sec Ops , and compliance. The candidate must write production‑quality code, design robust API and webhook integration frameworks, and translate NIST SP 800‑53 Rev. 5 and NIST SP 800‑171 Rev. 3 control requirements into automated, evidence‑generating technical workflows. The architect will own the platform’s architecture, build pipelines, and integrate data across the enterprise to deliver a real‑time, auditable, and scalable compliance posture.
Security clearance:
Must obtain and maintain a U.S. security clearance (SECRET preferred; TS/SCI strongly preferred).
Compliance Automation Platform Engineering
- Architect and build a greenfield Continuous Compliance Monitoring (CCM) platform.
- Design modular, API‑first architecture with well‑documented internal APIs and extensible data models.
- Develop webhook‑driven integration pipelines for telemetry and compliance signals from cloud services, SIEM platforms, vulnerability scanners, configuration management tools, and identity providers.
- Build control validation microservices that programmatically test NIST SP 800‑53 and 800‑171 controls, generate machine‑readable evidence, and surface gaps with remediation guidance.
- Implement evidence collection and artifact management framework for audit‑ready packages.
- Develop continuous authorization workflows, replacing point‑in‑time assessment cycles.
Dev Sec Ops and Pipeline Integration
- Embed compliance enforcement gates into CI/CD pipelines (Git Hub Actions, Git Lab CI, Jenkins).
- Develop policy‑as‑code libraries using OPA, Terraform Sentinel, AWS Config Rules, and Azure Policy.
- Integrate compliance telemetry with provisioning workflows using Terraform, Ansible, and Pulumi.
- Build automated STIG validation workflows using InSpec, OpenSCAP, and custom scripts.
- Partner with Dev Ops to implement secure baseline enforcement automation and drift detection.
Hybrid Architecture and On‑Premises Integration
- Design integration patterns and secure data collection agents for on‑premises and air‑gapped environments.
- Build bidirectional sync mechanisms between on‑premises systems and cloud services.
- Develop solutions for classified compliance monitoring within IL5 and IL6 boundaries.
- Architect data pipeline and storage with CUI, ITAR‑controlled data handling requirements.
NIST Framework Implementation and Control Automation
- Technical authority on programmatic implementation of NIST SP 800‑53 Rev. 5 control families.
- Build automation coverage for NIST SP 800‑171 Rev. 3 requirements.
- Develop automated SSP population workflows.
- Implement POA&M lifecycle automation with ticketing integration.
- Build CMMC Level 3 readiness automation tooling.
Platform Observability and Reporting
- Design and implement compliance posture dashboard and reporting layer.
- Build automated compliance scoring and trend analysis.
- Develop alerting and escalation workflows.
- Implement structured audit log generation across all platform components.
- 7+ years of experience in security engineering, compliance engineering, Dev Sec Ops .
- Proven ability to design and build production‑quality software…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).