ABOUT THE JOBAs a Senior Compliance Analyst, you will serve as a key leader and subject matter expert (SME) in safeguarding our global enterprise. Alongside the Cybersecurity Risk and Compliance Team, you will work on the strategy, implementation, and maintenance of a unified cybersecurity compliance framework. Operating at the intersection of security, engineering, and business operations, you will proactively manage risks, lead external audit readiness, and translate complex regulatory requirements into actionable, scalable controls. This role requires a highly collaborative professional who can seamlessly interface with diverse business units-ranging from Manufacturing and Supply Chain to Legal and Engineering-ensuring our security posture supports business growth while meeting stringent global standards.
WHAT YOU'LL DOCompliance Strategy & Framework Management- Lead and maintain the enterprise-wide unified cybersecurity framework, ensuring continuous alignment with industry-leading standards.
- Own the lifecycle of certifications and recertifications for critical frameworks, including but not limited to CMMC/NIST SP 800-171, ISO 27001, Cyber Essentials, and GDPR.
- Author and optimize high-quality Governance, Risk, and Compliance (GRC) documentation, including System Security Plans, POA&Ms, policies, and standard operating procedures.
- Drive compliance automation by identifying, implementing, and optimizing GRC tools to streamline compliance tracking and reduce manual auditing efforts.
Risk Management & Auditing- Design and conduct comprehensive security risk assessments, vulnerability reviews, and internal audits to identify, evaluate, and mitigate risks across the global infrastructure.
- Facilitate external audits, acting as the primary point of contact for regulatory auditors and assessors, ensuring smooth processes and timely resolution of findings.
- Advise on M&A and supply chain security, assessing the risk posture of third-party vendors and newly acquired entities to ensure seamless compliance integration.
Cross-Functional Collaboration & Security Enablement- Partner with Leadership to translate technical compliance findings into risk-based decisions aligned with the company's risk appetite and strategic goals.
- Collaborate as a Trusted Advisor with cross-functional teams-including Engineering, IT, Legal, Manufacturing, and Supply Chain-to embed security controls into daily workflows and product development lifecycles.
- Champion a culture of security by designing and delivering high-impact compliance education, security enablement sessions, and cross-departmental awareness initiatives.
- Develop executive-ready metrics and dashboards that clearly communicate the enterprise's compliance posture and risk profile to senior leadership.
REQUIRED QUALIFICATIONS- Education: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Experience: Five or more years of progressive experience in cybersecurity GRC within a complex, enterprise environment.
- Framework Expertise: Deep hands-on experience implementing and auditing frameworks such as CMMC, ISO 27001, NIST 800-53/171, and GDPR.
- Communication: Exceptional written and verbal communication skills, with a proven ability to translate complex technical concepts into business-friendly language.
- Work Authorization: Must be authorized to work in the United States.
- Must be eligible to obtain and maintain a US Secret Clearance.
PREFERRED QUALIFICATIONS- Professional Certifications: Highly preferred: CISSP, CISA, CRISC, CISM, or equivalent compliance/security credentials.
- Advanced Degree: Master's degree in Business Administration (MBA), Cybersecurity, or a related discipline.
- GRC Tooling: Experience implementing and managing enterprise GRC platforms.
- Industry Experience: Experience in highly regulated industries such as Aerospace, Defense, Advanced Manufacturing, or high-tech.
US Salary Range
$146,000-$194,000 USD
The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including:
BenefitsAt Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you're supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits.