Principal Compliance Engineer
Core
Lead the design and implementation of secure, compliant architectures within highly regulated cloud environments to enable system authorization and audit readiness.
Role type
Principal Compliance Engineer
Builds
Secure, audit-ready systems and services in AWS and Azure Government environments
Domain
Defense/Space sector, Cloud Security, Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
STIG development, encryption standards (FIPS 140-2/3, TLS 1.2+), vulnerability remediation, DevOps practices, SecOps practices, CI/CD pipeline integration, RMF (DoD IL5/IL6) frameworks, CMMC requirements, system documentation (SSPs, POA&Ms), incident response support, automated vulnerability response workflows
Technologies
AWS, Azure Government, STIGs, FIPS 140-2, FIPS 140-3, TLS 1.2+, CI/CD pipelines, ConMon
Responsibilities
Architect, implement, and maintain secure, audit-ready systems and services in AWS and Azure Government environments; Develop and maintain custom STIGs for cloud infrastructure, SaaS applications, and IaaS/PaaS configurations; Design and enforce secure configurations using encryption standards; Embed compliance and security checks into CI/CD pipelines; Lead the technical remediation of vulnerabilities identified through internal scans, third-party testing, or external audits; Support audits and assessments by managing detailed system documentation and serving as a technical point of contact
Seniority
Principal, hands-on IC