SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Anduril Industries, a defense technology company transforming U.S. and allied military capabilities, seeks a Senior Compliance Analyst to serve as a key subject matter expert in cybersecurity governance, risk, and compliance (GRC). This role operates at the intersection of security, engineering, and business operations, requiring a highly collaborative professional who can interface seamlessly with diverse business units including Manufacturing, Supply Chain, Legal, and Engineering.
You will lead and maintain the enterprise-wide unified cybersecurity compliance framework, ensuring continuous alignment with industry-leading standards. Key responsibilities include owning the lifecycle of critical certifications and recertifications (CMMC/NIST SP 800-171, ISO 27001, Cyber Essentials, GDPR), authoring high-quality GRC documentation including System Security Plans and POA&Ms, and driving compliance automation through GRC tool implementation and optimization.
In risk management and auditing, you will design and conduct comprehensive security risk assessments, vulnerability reviews, and internal audits across global infrastructure. You'll facilitate external audits as the primary point of contact for regulatory auditors and assessors, and advise on M&A and supply chain security by assessing third-party vendor and acquired entity risk postures.
Cross-functional collaboration is essential. You will partner with leadership to translate technical compliance findings into risk-based business decisions, collaborate with Engineering, IT, Legal, Manufacturing, and Supply Chain teams to embed security controls into workflows and product development, champion security culture through compliance education and awareness initiatives, and develop executive-ready metrics and dashboards communicating enterprise compliance posture to senior leadership.
Required: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field; five or more years of progressive cybersecurity GRC experience in complex enterprise environments; deep hands-on experience implementing and auditing CMMC, ISO 27001, NIST 800-53/171, and GDPR; exceptional written and verbal communication skills; U.S. work authorization; and eligibility to obtain and maintain a U.S. Secret Clearance. Preferred: CISSP, CISA, CRISC, CISM, or equivalent certifications.