Compliance Engineer - Public Sector

Wiz$174K — $238K *
US-AnywhereRemote in United States
Education, Government & Non-Profit
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in security engineering, DevOps, and systems engineering with coding experience to solve security/compliance issues.
  • 4+ years of knowledge in NIST SP 800-53, FedRAMP High baselines, and DoD SRG overlays, able to assess and reduce risk effectively.
  • Deep understanding of FR 20x and CR26 ruleset impacts on Cloud Service Providers (CSPs).
  • Cloud-native environment experience with DevSecOps, especially in CI/CD, Containers, and Kubernetes.
  • Proficient in scripting and Infrastructure as Code (IaC), including Shell Scripting, Python, Terraform, and preferred AI coding tools.
  • Experience with cloud platforms specific to government sectors.

Responsibilities

  • Lead the technical roadmap for automating FedRAMP Continuous Monitoring.
  • Architect compliance outcomes using NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into engineering solutions.
  • Develop frameworks for evidence generation to minimize manual effort for compliance assessments.
  • Conduct technical risk assessments and advise on compensating controls in cloud environments.
  • Manage compliance documentation, including Security Decision Records (SDRs).
  • Collaborate with cross-functional teams to define compliance verification for new features.
  • Mentor colleagues on FedRAMP/DoD compliance best practices and training.

Benefits

  • Comprehensive health and wellness plans.
  • Flexible working arrangements and remote work options.
  • Professional development programs and training opportunities.
  • Employee stock ownership plans and equity options.
  • Generous time-off policies, including paid sick leave and parental leave benefits.
Full Job Description


Minimum qualifications
  • 6+ years of experience in security engineering, DevOps, and systems engineering, with a proven ability developing processes and writing code to solve security/compliance problems.
  • 4+ years of expertise in NIST SP 800-53, FedRAMP High baselines, and DoW SRG overlays, with a proven ability to assess risk, reduce risk, and build engineering solutions that enable compliance.
  • Deep understanding of the differences between FR 20x and CR26 ruleset for Rev5 authorizations and the impacts these rule changes have on Cloud Service Providers (CSPs).
  • Experience working in a cloud-native environment with DevSecOps technologies, specifically including CI/CD, Containers, and Kubernetes.
  • Strong proficiency in scripting and Infrastructure as Code (IaC), with specific requirements for Shell Scripting, Python, Terraform or OpenTofu, and Preferred AI Harness (Claude Code, OpenAI Codex).
  • Experience with cloud platforms in government spaces.

Preferred qualifications
  • Experience with AWS GovCloud.
  • Experience in Azure Government, Google Cloud for Government (Assured Workloads), or equivalent and associated security services.
  • Experience with DevSecOps technologies including Microservices, GitOps, and Observability / Logging / SIEM / Platforms.
  • Experience with Packer, other Configuration as Code tools, and Policy as Code tools.
  • Experience automating compliance validation using cloud-native tools.

About the job

The Public Sector Compliance Operations Team aims to accelerate Wiz's growth by developing a comprehensive strategy, in tight partnership with all other organizations, to drive customer value and adoption. As we continue to grow at an incredible speed, we work to ensure each sales team member is set up for success at every phase. We take both a bird's eye view and dive into the weeds to solve problems as a team to drive employee success and revenue.

We are seeking an experienced Compliance Engineer to serve as the strategic technical lead for Wiz's FedRAMP CR26 initiative. You will define the long-term technical roadmap by architecting comprehensive compliance-as-code solutions, utilizing both Wiz's native features and custom-developed automations outside the platform to efficiently address CR26 Class D rule changes. This individual contributor role bridges complex regulatory requirements with scalable engineering practices, ensuring our cloud services meet stringent federal and defense standards while maintaining high availability, security, and audit-readiness.

You will be asked to quickly learn the challenges of the business and find ways to simplify processes within our compliance operations to increase productivity and efficiency. More importantly, the role requires a personality that promotes collaboration and unity.

Responsibilities
  • Lead the technical roadmap for FedRAMP Continuous Monitoring, moving from manual reporting to an automated, real-time telemetry model.
  • Architect compliance outcomes by translating NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering and product solutions.
  • Engineer evidence generation frameworks, significantly reducing manual effort required for 3PAO assessments and automating compliance validation for control implementation verification.
  • Conduct technical risk assessments, root-cause analysis on compliance findings, and provide guidance for implementation of compensating controls or hardening measures in cloud environments.
  • Own the technical compliance documentation lifecycle, including Security Decision Records (SDRs).
  • Collaborate cross-functionally with legal, product, engineering, devops, architecture, security, and federal customer teams to scope technical compliance verification and validation requirements for new features and services.
  • Mentor others on FedRAMP/DoW compliance best practices and contribute to internal training programs.


Candidates must meet EAR part 772 and ITAR 120.15 definition of a U.S. person (Any individual who is granted U.S. citizenship; or any individual who is granted U.S. permanent residence (green card holder); or any individual who is granted status as a "protected person") and that they reside in the contiguous United States.

Compensation + Benefits

Compensation for this full-time position includes base salary + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

The US base salary range for this full-time position is listed below.

US Base Pay Range

$174,000-$238,000 USD

Applicants must have the legal right to work in the country where the position is based, without the need for visa sponsorship. This role does not offer visa sponsorship.

About Wiz

Wiz is a cybersecurity company that provides cloud security solutions to protect enterprise assets. The company's platform provides visibility into cloud infrastructure, detects misconfigurations, and provides remediation recommendations. Wiz was founded in 2020 by a group of former Microsoft executives and cybersecurity experts. The company has raised over $100 million in funding and has partnerships with major cloud providers such as AWS, Azure, and Google Cloud.
Learn more about Wiz
Size
200 employees
Industry
Founded
2020
NASDAQ

Similar Jobs

More Jobs at Wiz

More Education, Government & Non-Profit Jobs

Find similar Compliance Engineer - Public Sector jobs: