Senior Compliance Analyst
Listed on 2026-08-24
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center.
As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.
As a Senior Compliance Analyst, you will serve as a key leader and subject matter expert (SME) in safeguarding our global enterprise. Alongside the Cybersecurity Risk and Compliance Team, you will work on the strategy, implementation, and maintenance of a unified cybersecurity compliance framework. Operating at the intersection of security, engineering, and business operations, you will proactively manage risks, lead external audit readiness, and translate complex regulatory requirements into actionable, scalable controls.
This role requires a highly collaborative professional who can seamlessly interface with diverse business units—ranging from Manufacturing and Supply Chain to Legal and Engineering—ensuring our security posture supports business growth while meeting stringent global standards.
Compliance Strategy & Framework Management
- Lead and maintain the enterprise-wide unified cybersecurity framework, ensuring continuous alignment with industry-leading standards.
- Own the lifecycle of certifications and recertifications for critical frameworks, including but not limited to CMMC/NIST SP 800-171, ISO 27001, Cyber Essentials, and GDPR.
- Author and optimize high-quality Governance, Risk, and Compliance (GRC) documentation, including System Security Plans, POA&Ms, policies, and standard operating procedures.
- Drive compliance automation by identifying, implementing, and optimizing GRC tools to streamline compliance tracking and reduce manual auditing efforts.
- Design and conduct comprehensive security risk assessments, vulnerability reviews, and internal audits to identify, evaluate, and mitigate risks across the global infrastructure.
- Facilitate external audits, acting as the primary point of contact for regulatory auditors and assessors, ensuring smooth processes and timely resolution of findings.
- Advise on M&A and supply chain security, assessing the risk posture of third‑party vendors and newly acquired entities to ensure seamless compliance integration.
- Partner with Leadership to translate technical compliance findings into risk‑based decisions aligned with the company’s risk appetite and strategic goals.
- Collaborate as a Trusted Advisor with cross-functional teams—including Engineering, IT, Legal, Manufacturing, and Supply Chain—to embed security controls into daily workflows and product development life cycles.
- Champion a culture of security by designing and delivering high-impact compliance education, security enablement sessions, and cross‑departmental awareness initiatives.
- Develop executive‑ready metrics and dashboards that clearly communicate the enterprise’s compliance posture and risk profile to senior leadership.
- Education: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Experience: Five or more years of progressive experience in cybersecurity GRC within a complex, enterprise environment.
- Framework Expertise: Deep hands‑on experience implementing and auditing frameworks such as CMMC, ISO 27001, NIST 800‑53/171, and GDPR.
- Communication: Exceptional written and verbal communication skills, with a proven ability to translate complex technical concepts into business‑friendly language.
- Work Authorization: Must be authorized to work in the United States.
- Must be eligible to obtain and maintain a US Secret Clearance.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).