SlipstreamJobsFresh Startup & VC-Backed Jobs

Compliance Engineer - Public Sector

Wiz - Remote - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Wiz is seeking an experienced Compliance Engineer to lead the technical strategy for its FedRAMP CR26 initiative. This is a strategic individual contributor role that bridges complex federal regulatory requirements with scalable engineering practices, ensuring Wiz's cloud services meet stringent federal and defense standards. You will define the long-term technical roadmap by architecting comprehensive compliance-as-code solutions, leveraging both Wiz's native features and custom-developed automations to address CR26 Class D rule changes. Key responsibilities include leading the technical roadmap for FedRAMP Continuous Monitoring, transitioning from manual reporting to automated, real-time telemetry; architecting compliance outcomes by translating NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering solutions; and engineering evidence generation frameworks that significantly reduce manual effort for third-party assessments. You will conduct technical risk assessments, perform root-cause analysis on compliance findings, and provide guidance for implementing compensating controls or hardening measures in cloud environments. You'll own the technical compliance documentation lifecycle, including Security Decision Records, and collaborate cross-functionally with legal, product, engineering, DevOps, architecture, security, and federal customer teams to scope technical compliance verification and validation requirements. The role requires mentoring others on FedRAMP and DoW compliance best practices and contributing to internal training programs. You'll work to simplify compliance processes, increase operational productivity and efficiency, and promote collaboration across the organization. Minimum qualifications include 6+ years in security engineering, DevOps, and systems engineering; 4+ years of expertise in NIST SP 800-53, FedRAMP High baselines, and DoW SRG overlays; deep understanding of FR 20x and CR26 rulesets for Rev5 authorizations; experience in cloud-native environments with DevSecOps technologies (CI/CD, Containers, Kubernetes); strong proficiency in Shell Scripting, Python, Terraform/OpenTofu, and AI tools; and experience with cloud platforms in government spaces. Preferred qualifications include AWS GovCloud, Azure Government, Google Cloud for Government, DevSecOps technologies (Microservices, GitOps, Observability), and experience automating compliance validation.

Similar roles