Application close date:
Applications will be accepted on an ongoing basis until the requisition is closed.
This role is part of Enterprise Technology (ET), where we’re developing the digital infrastructure needed to build the road to space, with an emphasis on digital capabilities required to advance Blue Origin’s mission. Enterprise Technology is the center of excellence for digital technology at Blue Origin, providing oversight and governance to align technology and business strategies.
The Blue Origin Cybersecurity GRC team is reducing the cost of security compliance through automation and engineering. This is primarily an engineering role: you will design, build, and operate the automation that makes compliance measurable, repeatable, and efficient, applying software and infrastructure engineering practices to the governance, risk, and compliance domains. It is well suited to software, SRE, platform, or DevOps engineers seeking to apply their automation expertise to security operations. Passion for our mission and vision is required!
Responsibilities include but are not limited to:
- Automating the collection of compliance artifacts and evidence across multiple cloud, SaaS, and internal platforms by integrating their APIs and normalizing the data.
- Building and operating CI/CD pipelines and Compliance-as-Code so compliance content is version-controlled, tested, and validated automatically.
- Automating configuration management and configuration monitoring - continuously validating system and platform configurations against approved baselines, detecting drift, and capturing results as evidence.
- Supporting continuous monitoring by integrating and correlating security telemetry and findings from partner-team platforms (including vulnerability management and SIEM/observability) into control-status reporting.
- Building GRC dashboards that integrate observability solutions to enable data-driven decisions.
- Developing outcome-driven metrics and KPIs to measure control effectiveness.
- Identifying manually intensive processes and engineering them away.
- Supporting risk assessments and maintaining policies aligned with security frameworks.
Minimum Qualifications
- 7+ years building and operating production software or infrastructure automation (software, SRE, DevOps, platform, or security engineering).
- Proficiency in a general-purpose programming language (Python strongly preferred; Go, JavaScript/TypeScript, or similar welcome), with maintainable, tested, version-controlled code.
- Experience integrating disparate systems via REST APIs and automating data/evidence collection across multiple cloud and SaaS platforms.
- Hands-on experience with CI/CD pipelines (e.g., GitLab CI) and infrastructure-as-code (Terraform, Bicep, or similar).
- Experience with configuration management and configuration monitoring - config-as-code and continuous validation of system state against baselines, including drift detection.
- Ability to translate ambiguous, multi-stakeholder requirements into reliable automation.
- Aptitude and appetite to learn security compliance frameworks (NIST, ISO, CMMC); extensive prior GRC experience is not required.
- Bachelor's degree or certification in a technical field, or equivalent experience.
Preferred Qualifications
- Familiarity with GRC/compliance frameworks: NIST 800-53/800-171, ISO 27001, ISO 28000, SOC, CMMC, and privacy frameworks.
- Compliance-as-Code / OSCAL / policy-as-code (OPA/Rego, InSpec) experience.
- Configuration compliance and desired-state tooling (SCAP, CIS Benchmarks, Ansible, Salt, Chef/Puppet, or PowerShell DSC).
- Continuous vulnerability monitoring - automating collection and correlation of findings from vulnerability management platforms (enterprise scanning is owned by a partner team).
- SIEM / observability integration.
- Aerospace, manufacturing, or OT/safety-critical environment experience.
Base Pay Range for:
WA applicants is $156,802.00 - $219,522.45
Other site ranges may differ
Culture Statement
Don’t meet all desired requirements? Studies have shown that some people are less likely to apply to jobs unless they meet every single desired qualification. At Blue Origin, we are dedicated to building an authentic workplace, so if you’re excited about this role but your past experience doesn’t align perfectly with every desired qualification in the job description, we encourage you to apply anyway. You may be just the right candidate for this or other roles.
Export Control Regulations
Applicants for employment at Blue Origin must be a U.S. citizen or national, U.S. permanent resident (i.e. current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.
Background Check
- Required for all positions: Blue’s Standard Background Check
- Required for Certain Job Profiles: Defense Biometric Identification System (DBIDS) background check if at any time the role requires one to be on a military installation
- Required for Certain Job Profiles: Drivers who operate Commercial Motor Vehicles with a Gross Vehicle Weight (GVW), Gross Vehicle Weight Rating (GVWR) or combination of power unit and trailer that meets or exceeds 10,001 lbs. and/or transports placardable amounts of hazardous materials by ground in any vehicle on a public road while in commerce, may be subject to additional Federal Motor Carrier Safety Regulations including: Driver Qualification Files, Medical Certification (obtained before onboarding), Road Test, Hours of Service, Drug and Alcohol Testing, vehicle inspection requirements, CDL requirements (if applicable) and hazardous materials transportation/shipping training.
- Required for certain Job Profiles: Ability to obtain and maintain Merchant Mariner Credential, which includes pre-employment and random drug testing as well as DOT physical
Benefits
- Benefits include: Medical, dental, vision, basic and supplemental life insurance, paid parental leave, short and long-term disability, 401(k) with a company match of up to 5%, and an Education Support Program.
- Stock Options for all regular employees (working at least 20 hours/week)
- Paid Time Off: Up to four (4) weeks per year based on weekly scheduled hours, and up to 14 company-paid holidays.
- Dependent on role type and job level, employees may be eligible for benefits and bonuses based on the company's intent to reward individual contributions and enable them to share in the company's results, or other factors at the company's sole discretion. Bonus amounts and eligibility are not guaranteed and subject to change and cancellation. Please check with your recruiter for more details.