Wiz

Secure everything you build and run in the cloud

Senior Compliance Operations Engineer

ComplianceComplianceFull TimeRemoteTeam 201-500H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

38 days ago

Salary

$204K - $281K / year

Professional Certificate7 yrs expEnglishAnsibleAWSAzureChefCloudGoogle Cloud PlatformPuppetPythonTerraform

Job Description

• Document security controls and architectures that satisfy FedRAMP High baseline requirements and DoD Cloud Computing Security Requirements Guide (SRG) overlays for Impact Level 5 (including handling of high-sensitivity CUI and unclassified National Security Systems). • Oversee continuous monitoring (ConMon) programs including vulnerability scanning, configuration monitoring, log aggregation/analysis, boundary protection validation, and monthly/ongoing reporting to meet FedRAMP and DoD expectations. • Translate NIST 800-53 Rev. 5 controls and DoD-specific enhancements into operational requirements; partner with engineering, DevOps, and product teams to embed compliance into their processes. • Lead preparation, evidence collection, and remediation for FedRAMP reassessments, 3PAO audits, DoD Provisional Authorizations, Significant Change Requests (SCRs), and contribute to Plan of Action & Milestones (POA&M) management. • Automate compliance validation for control implementation verification and drift detection. • Conduct technical risk assessments, root-cause analysis on compliance findings, and provide guidance for implementation of compensating controls or hardening measures in cloud environments. • Support incident response and boundary protection activities in IL5 environments, ensuring alignment with DoD policies for mission-critical workloads. • Maintain and update compliance documentation including System Security Plans (SSP), control implementation descriptions, architectural diagrams, and boundary definitions. • Collaborate cross-functionally with legal, product, engineering, and federal customer teams to scope new features/services while preserving authorization boundaries. • Mentor others on FedRAMP/DoD compliance best practices and contribute to internal training programs. • Align and coordinate complex, cross-functional federal programs/projects which include FedRAMP and/or DoD authorizations and/or the operational process requirements needed to meet ongoing operational requirements.

Job Requirements

  • 7+ years of hands-on experience in cloud security engineering, compliance operations, or GRC roles, with at least 4+ years directly supporting FedRAMP Moderate/High and DoD IL4/IL5 authorizations.
  • In-depth expertise in NIST SP 800-53 Rev. 5, FedRAMP baselines (especially High), DoD Cloud SRG, and associated control overlays for IL5.
  • Proven track record implementing and operating continuous monitoring in production FedRAMP and DoD IL4/IL5 environments, including vulnerability management, configuration compliance, and audit evidence generation.
  • Experience with DoD-specific tools/processes (e.g., eMASS, ACAS, HBSS, STIGs).
  • Experience with DoD BCAP architecture and configuration.
  • Strong experience with cloud platforms in government spaces (AWS GovCloud, Azure Government, Google Cloud for Government, or equivalent) and associated security services.
  • Proficiency in automation/scripting (Python, Bash, PowerShell) and Infrastructure as Code (Terraform, Ansible, Puppet/Chef preferred).
  • Familiarity with tools for compliance automation and scanning (e.g., Chef InSpec, OpenSCAP, Qualys, Tenable, AWS-native tools, Azure Security Center).
  • U.S. Citizenship required (due to handling of CUI and potential access to controlled environments).
  • Ability to obtain and maintain a U.S. Secret or higher security clearance (active clearance strongly preferred).
  • Active security certifications such as CISSP, CCSP, CISM, AWS/GCP/Azure Security Specialty, or DoD 8570/8140 IAT Level III / IAM Level III.
  • Knowledge of additional frameworks that overlap with FedRAMP/DoD (e.g., CMMC, NIST 800-171/172, FISMA).

Benefits

  • Medical, dental and vision insurance
  • Home Office Setup reimbursement
  • Flexible Spending Accounts
  • Monthly Connectivity reimbursement
  • Employee Assistance Program (EAP)
  • Short- and Long-term Disability Insurance
  • Life & Accident Insurance
  • 401(k) Retirement Savings Plan (with employer match)
  • Flexible paid time off + 11 paid holidays
  • Paid leave programs, including parental, pregnancy health, medical and bereavement leave

Related Categories

Related Job Pages

More Compliance Jobs

Compliance Analyst

Riverside Insights

Providing Insights That Elevate Potential

Compliance38 days ago
Full TimeRemoteTeam 201-500Since over 80 yearsH1B No Sponsor

Compliance Analyst supporting Riverside’s enterprise governance and compliance foundation

United States
$80K - $90K / year

Field Operation Specialist

Turf Tank

Inventors of Autonomous Line Marking. Flexible subscriptions, global expertise, local presence.

Compliance38 days ago
Full TimeRemoteTeam 51-200Since 2014H1B No Sponsor

The Field Operations Specialist is a part of Turf Tank's Operations department and will report to Field Operations Management. Specialists are responsible for delivering high-quality customer onboarding and on-field customer support, ensuring customers are set up for long-term su...

United States

Regulatory Compliance Analyst

Virta Health

Pioneering diabetes reversal for 100 million people

Compliance38 days ago
Full TimeRemoteTeam 201-500H1B Sponsor

Regulatory Compliance Analyst supporting compliance in healthcare at Virta Health

Alaska + 9 moreAll locations: Alaska, Hawaii, Maine, New Mexico, Oklahoma, Mississippi, Rhode Island, South Dakota, Vermont, Wisconsin
$60K - $70K / year

Senior Director, CMC Regulatory Affairs

MDWerks Inc.

MDWerks is a forward-thinking company that is leading the charge in the world of sustainable technology.

Compliance38 days ago
Full TimeRemoteTeam 1-10H1B No Sponsor

Senior Director leading global CMC regulatory strategy at Mineralys Therapeutics

United States
$240K - $270K / year