Software Engineer - AI Evaluation & Automation
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
- Act as the primary interface between Platform Engineering, Security/GRC, Compliance, and Audit teams.
- Own the audit evidence lifecycle, including evidence identification, collection, validation, organization, and submission.
- Translate regulatory and security-control requirements into clear, actionable engineering guidance.
- Identify audit gaps, weak controls, missing evidence, and remediation needs before they become formal findings.
- Support CMMC certification, FIPS encryption, application trust scoring, and related security initiatives.
- Challenge unnecessary, duplicative, or overly burdensome control requirements while maintaining compliance intent.
- Drive audit readiness, remediation tracking, and cross-functional stakeholder coordination.
- Represent Platform Engineering in leadership, compliance, and audit discussions.
Requirements
- Minimum of five years of hands-on experience in security compliance, audit readiness, technology risk, GRC, or security controls.
- Strong working knowledge of security and compliance frameworks such as CMMC, NIST 800-53 or 800-171, SOX, FedRAMP, ISO 27001, or SOC 2.
- Hands-on experience with audit evidence management, control documentation, gap identification, and remediation tracking.
- Ability to translate technical and regulatory requirements into clear engineering tasks and operational actions.
- Experience working directly with engineering, platform, cloud, SaaS, or PaaS teams.
- Strong critical-thinking and risk-prioritization skills, with the ability to identify control weaknesses across systems and processes.
- Exceptional professional English communication skills, including the ability to clearly translate complex technical and regulatory concepts for engineering, audit, and leadership audiences.
- Ability to operate independently and manage multiple priorities in a fast-moving, audit-driven environment.
Preferred Qualifications
- Seven or more years of relevant experience in security compliance, audit enablement, technology risk, or platform governance.
- Direct experience with CMMC certification or readiness assessments.
- Experience supporting FIPS 140-2 or FIPS 140-3 encryption initiatives.
- Exposure to ServiceNow, SURF, NowSupport, or similar enterprise platforms.
- Background in platform governance, internal product compliance, cloud security, or security assurance.
- Familiarity with application risk scoring, trust scoring, or control-maturity frameworks.
- Experience mapping controls across multiple frameworks to reduce duplicated audit effort.
- Relevant certifications are desirable, including CISSP, CISM, CISA, CRISC, CGRC, CCSP, CMMC etc.
Profile & Characteristics
- Ability to maintain a broad enterprise perspective while identifying detailed audit and control gaps.
- Strong judgment in determining which risks and compliance issues require immediate action.
- Ability to push back constructively on unclear, unnecessary, or duplicative compliance demands.
- Clear, concise, and confident communicator.
- Comfortable representing Platform Engineering in high-visibility leadership and audit meetings.
- Able to take ownership of identified gaps and drive them through remediation and closure.
Environment
Platforms include SURF and NowSupport within the ServiceNow ecosystem. The role works across Platform Engineering, GRC, Security, Compliance, and Audit stakeholders in a highly visible capacity., * LinkedIn profile and work experience validation is mandatory. Please provide your LinkedIn Profile ID:
- This is a remote role; however, client prefers candidates who are located in West Coast. Work during the PDT hours is required. Can you work during PDT hours?
- ServiceNow certification is preferred. Do you have ServiceNow CSA or CAD?
- Do you have hands on experience building, or evaluating AI-powered coding tools and software engineering agents, such as Claude Code, Devin, OpenCode, or comparable platforms?
Education:
- Bachelor’s (Required)
Experience:
- security compliance, audit readiness, technology risk: 5 years (Required)
- GRC, or security controls: 5 years (Required)
- Audit evidence management and control documentation: 3 years (Preferred)
- gap identification, and remediation tracking.: 3 years (Preferred)
Language:
- English (Required)
Benefits & conditions
$60 - $120 an hour - Temporary, Contract
About the company
Progile Solutions is seeking a Platform Security & Compliance Lead (CMMC / Audit Enablement) for an exclusive client engagement supporting a global consulting leader and a Fortune 100 enterprise AI Platform-as-a-Service provider.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
The Prompt Engineer ✍️
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Is Software Engineering Over-Saturated?
Now is the time for industrialized software development