Overview
Compliance Engineer for Wiz’s Public Sector Compliance Operations, serving as the strategic technical lead for the FedRAMP CR26 initiative.
What you'll do
- Lead the technical roadmap for FedRAMP Continuous Monitoring, moving from manual reporting to automated real-time telemetry.
- Translate NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable compliance-as-code engineering and product solutions.
- Engineer evidence generation frameworks to reduce manual effort for 3PAO assessments and automate compliance validation.
- Perform technical risk assessments and root-cause analysis on compliance findings, advising compensating controls or hardening measures.
- Own the technical compliance documentation lifecycle, including Security Decision Records (SDRs).
- Collaborate cross-functionally to scope technical compliance verification and validation requirements for new features and services.
What you'll need
- 6+ years of experience in security engineering, DevOps, and/or systems engineering.
- 4+ years of expertise in NIST SP 800-53, FedRAMP High baselines, and DoW SRG overlays.
- Deep understanding of differences between FR 20x and CR26 ruleset for Rev5 authorizations and impacts on Cloud Service Providers (CSPs).
- Experience with cloud-native DevSecOps technologies including CI/CD, containers, and Kubernetes.
- Strong scripting and Infrastructure as Code skills, including Shell Scripting, Python, Terraform or OpenTofu.
- Experience with cloud platforms in government spaces.
Details
- Work mode: Remote - USA.
- Employment type: Full-time.
- US person requirement: must meet EAR part 772 and ITAR 120.15 definition of a U.S. person and reside in the contiguous United States.
Read the full description and apply on the company’s own careers page.