Jobgether

Senior Security Compliance Engineer, Public Sector

Jobgether United States · $139K–$196K/yr

Internet Marketplace Platforms · 11-50 employees

13 h ago
Remote Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

Develop and manage GRC strategies to ensure compliance with regulatory standards like FedRAMP and IRAP across public-sector cloud environments. Collaborate with cross-functional teams to automate control testing and maintain continuous monitoring of security documentation.

What they look for

Governance, Risk, and Compliance FedRAMP Cybersecurity Security auditing Compliance-as-code Policy-as-code Automation Cloud security Risk management Regulatory compliance Technical documentation Stakeholder management Project management Information technology Security assessments

Requirements

Requires U.S. citizenship and at least 5 years of experience in cybersecurity or GRC within highly regulated industries. Candidates must possess a bachelor's degree and demonstrate proficiency in cloud security frameworks and compliance automation.

Benefits

Equity compensation Employee stock purchase plan Health benefits Financial security benefits Flexible paid time off Parental leave Growth and development funding Employee resource groups

Full description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Compliance Engineer, Public Sector based in the United States.

This is a senior security and compliance opportunity focused on strengthening trust across highly regulated public-sector environments. You will help advance compliance programs supporting government-focused cloud offerings while contributing to the broader security posture of the organization. The role combines hands-on Governance, Risk, and Compliance (GRC) engineering with regulatory expertise, automation, and customer engagement. You will work across Security, Engineering, Product, Information Technology, Legal, and other teams to translate complex requirements into practical controls and processes. A key focus will be supporting certifications, audits, continuous monitoring, and compliance-as-code initiatives across evolving technology environments. You will also serve as a trusted advisor to internal stakeholders, customers, auditors, and senior leaders on complex compliance matters. This position is ideal for a technically capable compliance professional who thrives in regulated environments and enjoys solving complex problems with meaningful business and customer impact.

\n

Accountabilities

  • Develop, implement, and manage Governance, Risk, and Compliance strategies and processes supporting regulatory and industry standards, including FedRAMP, IRAP, and related frameworks.
  • Partner with highly regulated customers to understand their compliance requirements and develop practical solutions aligned with applicable frameworks and certifications.
  • Lead security assessments, audits, certification activities, and related evidence-gathering processes to ensure timely and successful completion.
  • Support ongoing FedRAMP continuous monitoring commitments, including maintaining compliance evidence, controls, documentation, and operational processes.
  • Collaborate with Information Technology, Product, Engineering, Security, Legal, and other cross-functional teams to integrate compliance requirements into business operations and technology environments.
  • Develop and maintain comprehensive security and compliance documentation, including policies, procedures, controls, and supporting evidence.
  • Use scripting and coding capabilities to automate GRC workflows, control testing, evidence collection, and compliance-as-code or policy-as-code implementations.
  • Monitor regulatory developments, industry trends, and emerging requirements to identify compliance gaps and continuously strengthen the overall program.
  • Provide training, guidance, and practical support to internal teams and customers on GRC, security, and regulatory requirements.
  • Serve as a subject matter expert on security compliance, providing strategic recommendations to senior leaders and stakeholders.
  • Help mature compliance capabilities across cloud-based and self-managed environments while supporting customer trust and regulatory readiness.
  • Manage multiple priorities independently and maintain strong execution in a fast-paced, highly regulated environment.

Requirements

  • U.S. citizenship and residency, with valid proof of eligibility to meet government requirements.
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or equivalent relevant experience.
  • At least 5 years of experience in Governance, Risk, and Compliance, cybersecurity, security assurance, or a related field, preferably within highly regulated industries.
  • Demonstrated experience achieving and maintaining security certifications or authorizations such as FedRAMP, Cybersecurity Maturity Model Certification (CMMC), System and Organization Controls 2 (SOC 2), Information Security Registered Assessors Program (IRAP), or ISO 27001.
  • Strong understanding of regulatory and compliance requirements applicable to public-sector organizations and other highly regulated environments.
  • Experience implementing compliance-as-code or policy-as-code and automating control testing, evidence collection, or related GRC processes.
  • Working knowledge of FedRAMP requirements, processes, documentation, and continuous monitoring expectations.
  • Familiarity with major cloud hyperscalers and their underlying services, such as Amazon Web Services (AWS) and Google Cloud Platform (GCP).
  • Strong analytical, problem-solving, organizational, and project-management skills, with the ability to navigate complex compliance challenges.
  • Excellent communication and interpersonal skills, with the ability to work effectively with customers, auditors, regulatory stakeholders, and cross-functional technical and business teams.
  • Ability to operate independently, manage multiple projects simultaneously, and adapt to changing priorities.
  • Relevant professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or similar are highly desirable.

Benefits

  • U.S. base salary range of $139,200–$196,000 annually.
  • Equity compensation opportunities and employee stock purchase plan.
  • Comprehensive benefits supporting health, financial security, and overall well-being.
  • Flexible paid time off.
  • Parental leave.
  • Growth and development funding to support ongoing professional learning.
  • Employee resource groups and initiatives supporting inclusion and community.
  • Opportunity to work on complex public-sector security and compliance initiatives with significant customer impact.
  • Exposure to cross-functional teams spanning Security, Engineering, Product, Legal, and commercial functions.
  • Opportunity to contribute to the evolution of compliance engineering, automation, and security assurance practices.

\nHow Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1