Lead Security Engineer, GRC

Anduril
Boston, Seattle, Washington
Workplace: OnsiteFull timeUSD 166,000 - 253,000 annuallyFunction: CybersecurityExperience: 6+ yearsSkills: ["Technical direction","Mentoring","Ownership","Autonomous execution","Cross-team alignment"]

Build the engineering core of a continuous GRC program by creating pipelines that collect evidence from systems and map it to a normalized control model. Stand up the system of record for controls, mappings, and evidence, drive build-vs-buy decisions, and surface control drift with clear remediation paths. Translate frameworks like CMMC, NIST 800-171, and FedRAMP/IL5 into automatable technical checks, while setting technical direction and mentoring a growing security engineering team.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Anduril
Anduril
2 days ago

Lead Security Engineer, GRC

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live

Job Summary

Build the engineering core of a continuous GRC program by creating pipelines that collect evidence from systems and map it to a normalized control model. Stand up the system of record for controls, mappings, and evidence, drive build-vs-buy decisions, and surface control drift with clear remediation paths. Translate frameworks like CMMC, NIST 800-171, and FedRAMP/IL5 into automatable technical checks, while setting technical direction and mentoring a growing security engineering team.
Location: Boston, Seattle, Washington
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Manager level

Key Responsibilities

  • •Build the evidence-collection pipeline that maps compliance evidence to a normalized control model.
  • •Create reusable collectors and schemas as reference architectures to accelerate new controls.
  • •Stand up and operate the system of record for controls, mappings, and evidence, including build-vs-buy decisions.
  • •Detect control drift and route findings to system owners with remediation and risk-acceptance paths.
  • •Translate compliance frameworks (CMMC, NIST 800-171, FedRAMP/IL5) into automatable technical checks and pass/fail signals; set technical direction and mentor the team.

Pay and Benefits

Salary: USD 166,000 - 253,000 annually
Equity and Bonus:Equity

Key Requirements

  • •6+ years in security engineering, GRC, or a related role, including hands-on building of automation or data pipelines.
  • •Strong programming ability in a general-purpose language (e.g., Go, Python, Rust).
  • •Hands-on experience operationalizing compliance frameworks including CMMC, NIST 800-171 and 800-53, FedRAMP, and SOC 2.
  • •Experience designing data collection and integration across cloud and SaaS systems (APIs, log/event pipelines, data lakes).
  • •Experience with infrastructure as code (e.g., Terraform, AWS CDK) and a track record of setting technical direction and mentoring engineers.
Experience:6+ yearsGRCSecurity engineeringDefense technologyContinuous control monitoring
Skills:Technical directionMentoringOwnershipAutonomous executionCross-team alignment
Languages:English
Tech Stack:GoPythonRustTerraformAWS CDKAPIsLog/event pipelinesData lakesCMMCNIST 800-171NIST 800-53FedRAMPSOC 2STIGConMonCSPMKubernetesSystem of record

Eligibility

Security Clearance:Secret

Company Brief

Anduril
Designs and builds advanced defense systems combining autonomous aircraft, sensors, and AI-driven software for military and national security applications, focused on modernizing battlefield capabilities and distributed sensing.
Industry: Defense Technology
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series E+
Headquarters: Costa Mesa, United States
Founded: 2017
WebsiteLinkedIn