Senior Compliance Engineer (Remote From Anywhere In CO)

State of Colorado

$110K — $125K *
US-AnywhereRemote in Colorado, US
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Five years in a technology engineering role (application development, systems administration).
  • Three years supporting audit or compliance programs (NIST 800-53, HIPAA, CJIS, etc.).
  • Experience writing and maintaining security policies and standards.
  • Familiarity with automated compliance guardrails and Policy as Code.
  • Professional certifications in security are preferred.

Responsibilities

  • Develop and maintain security policies aligned to NIST, HIPAA, and CJIS.
  • Map controls to various regulatory frameworks to ensure compliance.
  • Implement continuous monitoring for assessing control effectiveness.
  • Translate compliance requirements into actionable technical specifications.
  • Develop training materials for staff on compliance obligations.
  • Monitor updates to regulatory frameworks to keep policies current.
  • Produce metrics and reports on compliance posture.

Benefits

  • Eligible for state employee benefits.
  • Locations permitted for remote work from anywhere in Colorado.
  • Potential for position extension based on circumstances.
  • Opportunities for professional development and mentorship.
  • Flexibility to work independently with minimal supervision.
Full Job Description
Salary: $110,000.00 - $125,000.00 Annually
Location : Statewide, CO
Job Type: Full Time
Job Number: EGB93815
Department: Governor's Office of Information Technology
Opening Date: 09/04/2026
Closing Date: 9/16/2026 11:59 PM Mountain
FLSA: Determined by Position
Primary Physical Work Address: (Remote From Anywhere In CO)
FLSA Status: Exempt; position is not eligible for overtime compensation.
Department Contact Information:
Type of Announcement: This announcement is not governed by the selection processes of the classified personnel system. Applications will be considered from residents and non-residents of Colorado.
How To Apply: Please submit an online application for this position at https://www.governmentjobs.com/careers/colorado. Reach out to the Department Contact to apply using a paper application, including any supplemental questions. Failure to submit a complete and timely application may result in the rejection of your application. Applicants are responsible for ensuring that application materials are received by the appropriate Human Resources office before the closing date and time listed.

Description of Job
TERM LIMITED POSITION: This position is term limited with an anticipated end date of approximately one year from the date of hire. This position is eligible for State employee benefits and may be extended as the situation warrants. This video explains the many benefits of working at the State of Colorado on a term limited basis

IMPORTANT NOTE: Please review your application to ensure completion. For the most equitable applicant experience, OIT's hiring team considers only the contents of your application to review your qualifications. Please do not include any attachments (such as resume or cover letter) with your application as these items are not used by OIT's hiring team.
Are you a security-minded strategist ready to protect the heart of Colorado's digital infrastructure? The Governor's Office of Information Technology is seeking a Senior Compliance Engineer to anchor our Information Security Office. In this high-impact role, you will be the guardian of the state's data assets, leading the development and execution of our compliance program against rigorous standards like the NIST Cybersecurity Framework, HIPAA, CJIS, and IRS Publication 1075. You won't just write policies-you'll translate complex technical realities into clear, actionable strategies that empower leadership and stakeholders to make informed, risk-aware decisions. By bridging the gap between technical operations and regulatory requirements, you will ensure our state's public services remain resilient, secure, and worthy of our citizens' trust.

Essential Functions:

  • Policy & standard development (Govern - GV.PO) - Write, maintain, and version-control security policies, standards, and secure configuration baselines aligned to NIST 800-53 control families, incorporating requirements from IRS Publication 1075 (federal tax information safeguards), HIPAA Security Rule, and the FBI CJIS Security Policy where applicable. Where feasible, codify standards as Policy as Code so requirements are machine-enforceable rather than documentation-only. Outcome: a current, approved policy library that maps directly to control families, satisfies overlapping regulatory obligations without gaps, and is enforceable through automated guardrails.
  • Control mapping & framework alignment (Identify - ID.RA / Govern - GV.OC) - Map internal technical and administrative controls to NIST CSF categories and NIST 800-53 controls, cross-walking to IRS Pub 1075, HIPAA, and CJIS requirements to identify overlaps and unique obligations across regulatory regimes. Outcome: a unified control matrix showing full framework coverage with clear ownership, avoiding duplicate or conflicting control implementations.
  • Compliance monitoring & evidence collection (Detect - DE.CM) - Design and operate continuous monitoring processes to assess control effectiveness and automate evidence collection to support NIST, IRS Safeguards, HIPAA, and CJIS audit requirements, leveraging Policy as Code scans and Infrastructure as Code drift detection to continuously validate control state. Outcome: audit-ready evidence available on demand across all applicable regulatory regimes, with control drift caught automatically rather than at audit time.

  • Technical control implementation guidance (Protect - PR.PS / PR.AA) - Translate NIST, IRS Pub 1075, HIPAA, and CJIS control requirements into technical specifications engineering and IT teams can implement (e.g., FTI data handling and encryption per IRS Pub 1075, PHI access controls per HIPAA, criminal justice data handling and advanced authentication per CJIS). Partner with engineering to embed these requirements directly into Infrastructure as Code templates (e.g., Terraform, CloudFormation modules) so compliant configurations are the default at deployment time. Outcome: controls that satisfy the most stringent applicable requirement, are functionally effective in production, and are consistently applied through reusable, version-controlled infrastructure templates.

  • Procedure & runbook documentation (Govern - GV.PO / Protect - PR.PS) - Author standard operating procedures and control-testing runbooks that support repeatable compliance activities, including regime-specific procedures (e.g., FTI incident reporting per IRS Pub 1075, breach notification per HIPAA, CJIS personnel security screening), and document how Policy as Code rules and Infrastructure as Code modules map back to the controls they satisfy. Outcome: processes that don't rely on institutional knowledge held by one person, and can be handed off, independently audited, or traced from control to enforced code.

  • Regulatory & framework change management (Govern - GV.OC) - Monitor updates to NIST publications, IRS Publication 1075, HIPAA regulations, and the CJIS Security Policy, updating internal policies, standards, and corresponding Policy as Code rules and IaC baseline templates accordingly. Outcome: the policy library and its codified enforcement mechanisms stay current with minimal lag after any framework or regulatory change takes effect.

  • Cross-functional compliance training (Govern - GV.RR) - Develop and deliver training and reference documentation to help engineering, IT, and program staff understand and apply NIST, IRS Pub 1075, HIPAA, and CJIS requirements relevant to their roles, including how to work within Policy as Code guardrails and approved IaC modules rather than around them. Outcome: fewer compliance violations caused by lack of awareness, and higher developer adoption of compliant-by-default infrastructure patterns.

  • Metrics & compliance reporting (Govern - GV.OV) - Define and track compliance KPIs mapped to control maturity across NIST, IRS Safeguards, HIPAA, and CJIS (e.g., % of controls assessed, time-to-remediate findings, policy review currency, audit finding closure rates by regime, % of infrastructure provisioned through compliant IaC templates, Policy as Code rule pass/fail rates). Outcome: leadership has a clear, quantifiable view of compliance posture, trends, and the degree to which compliance is automated versus manually enforced.

Additional Functions:
Self-Direction & Autonomy
  • Operates independently with minimal supervision; exercises sound judgment in ambiguous or evolving situations
  • Prioritizes and manages a complex workload across competing deadlines without day-to-day direction
  • Recognizes when to escalate versus when to resolve independently

Continuous Improvement Ownership
  • Proactively identifies gaps or inefficiencies in the compliance program and drives improvements without being asked
  • Stays current on evolving threats, regulatory changes, and framework updates (e.g., NIST CSF, CJIS, IRS revisions) and incorporates them into practice
  • Seeks feedback on their own work product and iterates on methodologies, templates, and reporting over time

Mentorship & Influence
  • Mentors others
  • Influences stakeholders and leadership without formal authority - builds credibility through sound analysis rather than positional power
  • Acts as a subject-matter resource other teams turn to for compliance-related questions

Accountability & Ownership
  • Takes ownership of outcomes, not just tasks - follows through on remediation and reporting until issues are genuinely resolved
  • Documents decisions and rationale clearly enough to withstand audit or leadership scrutiny

Judgment Under Ambiguity
  • Comfortable making recommendations with incomplete information
  • Balances competing priorities (security, budget, mission delivery, public accountability) rather than defaulting to a single lens

Communication & Composure
  • Communicates effectively under pressure, including during incidents or audit findings
  • Adapts communication style for technical staff, program managers, and non-technical executives or elected oversight bodies

Professional Development
  • Maintains and pursues relevant certifications (CISSP, CRISC, CISA, CGRC, GRCP) as a mark of ongoing self-investment
  • Participates in professional communities to bring outside perspective back into the agency

Minimum Qualifications, Substitutions, Conditions of Employment & Appeal Rights
A wide salary range is posted for this position and any job offer is based upon a salary analysis to comply with the Colorado Equal Pay for Equal Work Act. The salary analysis considers relevant experience, education, certifications, and state seniority as compared to others doing substantially similar work. While most salary offers are made within the posted range, occasionally an offer is made below or above the posted range based upon this salary analysis.

This is a skills-based job announcement. The required minimum qualifications and/or education (if substituting for the proven experience, knowledge, and skills), are as follows:
To better understand your qualifications and increase your opportunity to move forward in the selection process, please indicate in your work history for each job the outcomes you have achieved that you believe are most relevant to this job.
Minimum Qualifications:
At Least five (5) years of experience in a technology engineering role such as application developer or system administrator. At least three (3) years of experience supporting audit or compliance programs (e.g., NIST 800-53 CJIS, IRS, HIPAA, SSA, SOC 2, or similar).
Substitutions:

  • Additional appropriate education will substitute for the required experience on a year-for-year basis, but cannot completely substitute for these qualifications.
  • Training or Certification related to the work assigned to the position will be assigned credit towards substitution for experience and/or education, but cannot completely substitute for these qualifications.
  • If the minimum qualifications include a degree requirement, additional appropriate paid or unpaid experience will substitute for the required education on a year-for-year basis.

Preferred Qualifications:

  • 1 year of experience implementing automated compliance guardrails using Policy as Code (e.g., OPA/Rego, Sentinel, Checkov, or cloud-native policy services) within CI/CD pipelines or infrastructure provisioning workflows.
  • Professional security certification.
  • Exposure to Governance, Risk and Compliance (GRC) tooling, such as ServiceNow GRC, Archer, or similar platforms.
  • Project management experience.


Conditions of Employment:
OIT employees must comply with any screening procedures in place at state agency locations where they might perform work.

This position may require travel within the specified geographic area, and to locations across the state as needed.

This position may require on-call duties as needed by the position.
Supplemental Information
If this posting indicates "remote from anywhere in CO" in the title, periodic reporting to the primary state work location designated for the position is required. All remote work must be performed in Colorado.

While candidates from out of state will be considered for this role, the candidate selected for the position must relocate and reside in Colorado on the first day of their new position. A reasonable timeframe for relocation will be established on an individual basis, while considering business needs, and determining a start date.
We know it's important to support each other, and that means having a healthy balance of work and personal time. Visit our benefits to learn more about some of our great o

Similar Jobs

More Jobs at State of Colorado

More Information Technology Jobs

Find similar Senior Compliance Engineer (Remote From Anywhere In CO) jobs: