SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 166,000 - 253,000 / annual
Anduril Industries, a defense technology company, is seeking a Security Engineer to lead the Governance, Risk, and Compliance (GRC) engineering function. You will build the technical core of the GRC program—automated pipelines and tooling that transform Anduril's systems into continuous, defensible evidence of compliance, eliminating manual audit scrambles.
Key responsibilities include:
- Design and build data collection pipelines that aggregate evidence from Anduril's systems and map it to normalized control models
- Develop reusable collectors and schemas as reference architectures to standardize control implementation across the organization
- Establish the system of record for controls, mappings, and evidence; lead build-vs-buy analysis for GRC platforms
- Detect control drift and route findings to system owners with clear remediation and risk-acceptance pathways
- Translate compliance frameworks (CMMC, NIST 800-171, FedRAMP/IL5) into automatable technical checks and pass/fail signals
- Set technical direction and mentor a growing engineering team
Required qualifications:
- 6+ years in security engineering, GRC, or related roles with hands-on automation or data pipeline experience
- Strong programming ability in general-purpose languages (Go, Python, Rust, etc.)
- Hands-on experience operationalizing compliance frameworks (CMMC, NIST 800-171, 800-53, FedRAMP, SOC 2)
- Experience designing data collection and integration across cloud and SaaS systems (APIs, log/event pipelines, data lakes)
- Production experience with infrastructure as code (Terraform, AWS CDK)
- Track record of setting technical direction and mentoring engineers
- Ability to work autonomously, own ambiguous problems, and drive cross-team alignment
- Eligible to obtain and maintain U.S. Secret clearance
Preferred qualifications include experience with continuous control monitoring platforms (Vanta, Drata, Hyperproof, OneTrust), security data lakes, STIG/ConMon scanning, CSPM, Kubernetes hardening, and fast-paced defense technology environments.