Senior Compliance Engineer

Anduril Anduril · Defense · Costa Mesa, CA +2 · Corporate Technology : Information Security : Corporate Assurance

Anduril Industries is a defense technology company building AI-powered military systems. This Senior Compliance Engineer role focuses on automating and enforcing compliance with federal frameworks (NIST, CMMC, FedRAMP, SOC 2) across corporate and product environments. The role requires a strong DevSecOps background, expertise in cloud security, and the ability to translate complex regulations into actionable engineering solutions and Infrastructure/Policy as Code. It is a hands-on builder role focused on enabling engineering teams to deploy secure, compliant applications by default.

What you'd actually do

  1. Design, develop, and maintain Infrastructure as Code (IaC) and Policy as Code (PaC) that enforce compliance with NIST SP 800-171 and 800-53, CMMC, and other applicable frameworks, enabling developers to deploy CMMC-certified applications using pre-packaged, compliant infrastructure templates.
  2. Architect, build, and deploy robust, scalable security controls across Anduril's corporate, development, and production cloud environments (AWS, Azure, GCP) and on-premise environments.
  3. Develop and automate IaC pipelines for managing and scaling cloud deployments securely and efficiently, including automated pipelines for deploying infrastructure, applications, and updates.
  4. Build automation for procedural compliance controls, generating compliance and audit artifacts at scale without manual intervention.
  5. Analyze, interpret, and operationalize federal and industry cybersecurity regulations, including NIST SP 800-171 and 800-53, CMMC, FedRAMP, and SOC 2, translating regulatory language into actionable engineering guidance and enforceable technical controls.

Skills

Required

  • Infrastructure as Code (IaC)
  • Policy as Code (PaC)
  • NIST SP 800-171
  • NIST SP 800-53
  • CMMC
  • FedRAMP
  • SOC 2
  • DevSecOps
  • cloud security (AWS, Azure, GCP)
  • embedded systems security
  • automation
  • security controls
  • compliance engineering
  • technical writing
  • interpreting regulations

Nice to have

  • Terraform
  • DISA STIG scanning
  • Continuous Monitoring (ConMon)

What the JD emphasized

  • compliance engineer
  • compliance frameworks
  • NIST SP 800-171
  • 800-53
  • CMMC
  • FedRAMP
  • SOC 2
  • DevSecOps
  • cloud infrastructure security
  • embedded systems security
  • federal compliance frameworks
  • Infrastructure as Code (IaC)
  • Policy as Code (PaC)
  • automated compliance
  • automated pipelines
  • automation for procedural compliance controls
  • Continuous Monitoring (ConMon)
  • DISA STIG scanning
  • compliance reporting
  • rapid, secure deployments
  • security models
  • security controls
  • technical controls
  • compliance testing
  • compliance obligations