SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 105,000 - 175,000 / annual
True Anomaly is seeking an experienced Compliance Engineer III to lead the design and implementation of secure, compliant architectures within highly regulated cloud environments. This is a hands-on technical role that treats GRC (Governance, Risk, and Compliance) as a product, requiring deep expertise in STIG development, vulnerability remediation, DevOps, and SecOps practices—particularly within AWS and Azure Government platforms.
You will work cross-functionally to align cloud infrastructure and training with frameworks such as RMF (DoD IL5 and IL6) and CMMC. The role combines technical security engineering with internal marketing and enablement: you will build controls, then package, promote, and prove them across the enterprise through training, video, live demonstration, and customer-facing evidence.
Key responsibilities include:
**Security & Compliance Engineering:** Implement and maintain secure, audit-ready systems in AWS and Azure Government environments. Develop and maintain custom STIGs for cloud infrastructure, SaaS applications, and IaaS/PaaS configurations.
**Training Integration:** Embed compliance and security training across the enterprise through video and hands-on programs. Automate scoring and tracking of training requirements for readiness assessments and audits. Partner with cybersecurity operations teams to support incident response and system hardening.
**Vulnerability Management:** Assist in technical remediation of vulnerabilities identified through internal scans, third-party testing, or external audits. Work with engineering and DevOps teams to drive secure patch management, system baseline enforcement, and automated vulnerability response workflows. Maintain and operationalize vulnerability metrics dashboards aligned with continuous monitoring plans.
**Audit Readiness & Documentation:** Support and manage detailed system documentation including SSPs, network diagrams, control implementations, and POA&Ms. Serve as a technical point of contact during audits and assessments, demonstrating compliance posture through hands-on walkthroughs and evidence collection.
**Cross-Functional Collaboration & Leadership:** Partner with product, engineering, and compliance teams to implement secure system boundaries and customer segmentation strategies. Provide technical mentorship to junior compliance engineers. Track emerging requirements and proactively update configurations to meet evolving DoD IL5, IL6, and CMMC mandates.
**GRC Enablement & Marketing:** Productize the GRC function by packaging controls, training, and inherited compliance into clearly defined service offerings. Build internal messaging and positioning for GRC, translating IL5, IL6, and CMMC requirements into plain language for engineering, program, and business teams. Develop customer-facing compliance collateral including trust one-pagers, control inheritance summaries, shared responsibility matrices, and briefing decks. Support capture and business development by responding to security questionnaires, RFP compliance sections, and customer due diligence requests. Run internal campaigns that drive training completion, control adoption, and audit readiness. Produce video, demo, and walkthrough content that markets the GRC program. Establish a compliance brand across the enterprise so GRC is seen as an enabler of speed and customer trust. Define and track adoption metrics for GRC services. Maintain an internal GRC knowledge base and self-service portal.
**Requirements:**
- 5+ years of experience in cybersecurity engineering, cloud compliance, or DevSecOps roles
- Hands-on experience with vulnerability scanning, remediation planning, and automated patching workflows
- Familiarity with DoD RMF (IL5 and IL6), CMMC, and related audit frameworks
- Proficiency with tools such as JIRA, Nessus, and Docebo
- Experience with marketing methodologies to productize the GRC role
- Experience building training programs and videos
- Demonstrated experience marketing or productizing a security, compliance, or GRC capability to internal or external stakeholders
- Strong written and verbal communication skills, with ability to brief both engineers and executives on compliance posture
- Experience creating enablement content such as one-pagers, briefing decks, demo videos, and knowledge base articles
- Experience supporting security questionnaires, RFP responses, or customer audits in a sales or capture context
- Active TS/SCI clearance required
- U.S. citizenship or lawful permanent resident status (ITAR compliance)
**Preferred Skills:**
- Experience with DoD RMF (IL5 and IL6) cloud environments
- Working knowledge of security training and how it applies to IL 5/6 environments and inheritability from the enterprise
- Basic people leadership experience, including mentoring or technical guidance responsibilities
- Industry certifications such as Security+