> Markdown version of [/jobs/ext/2530516-lead-security-engineer-grc](https://www.wearedevelopers.com/jobs/ext/2530516-lead-security-engineer-grc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Engineer, GRC - **Company:** Amazon.com, Inc. - **Location:** Seattle, WA, United States - **Experience:** Expert - **Salary:** $87,100.0 - $114,400.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Software as a Service, Data Mart, Python (Programming Language), Open Source Technology, Phishing, AWS Cdk, SC Clearance, Data Lakes, Kubernetes, RSA Archer Platform, Terraform, Data Pipelines - **Published:** August 3, 2026 - **Apply:** https://www.careerjet.com/job/usf995177e87b20d2aeedbd865f1fbcb9f/eaa ## About the Role * 6+ years in security engineering, GRC, or a related role, including hands-on building of automation or data pipelines * Strong programming ability in a general-purpose language (Go, Python, Rust, etc.) * Hands-on experience operationalizing compliance frameworks (CMMC, NIST 800-171, 800-53, FedRAMP, SOC 2) * Experience designing data collection and integration across cloud and SaaS systems (APIs, log/event pipelines, data lakes) * Experience with infrastructure as code (e.g., Terraform, AWS CDK) in a production capacity * Track record of setting technical direction and mentoring engineers * Ability to work autonomously, take ownership of ambiguous problems, and drive alignment across partner teams * Eligible to obtain and maintain a U.S. Secret clearance, * Experience with continuous control monitoring or GRC platforms (Vanta, Drata, Hyperproof, OneTrust), or building bespoke equivalents * Experience with security data lakes, log aggregation, or building data marts for querying * Familiarity with STIG/ConMon scanning, CSPM, or Kubernetes hardening * Experience in fast-paced, high-growth defense technology environments ## Description Anduril's Security Engineering team is looking for a Governance, Risk, and Compliance Engineering Lead to build the engineering core of our GRC program: the pipeline and tooling that turn Anduril's systems into continuous, defensible evidence of compliance, replacing the manual scramble that happens at audit time. You'll set technical direction for the function and grow the team building it. WHAT YOU'LL DO * Build the pipeline that collects evidence from Anduril's systems and maps it to a normalized control model * Construct reusable collectors and schemas as reference architectures so each new control is assembly, not reinvention * Stand up the system of record for controls, mappings, and evidence, and drive the build-vs-buy analysis * Surface control drift and route findings to system owners with clear remediation and risk-acceptance paths * Translate frameworks (CMMC, NIST 800-171, FedRAMP/IL5) into automatable technical checks and pass/fail signals * Set technical direction and mentor a growing engineering team, At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you're supported in health, recovery, and whatever comes next. For more information, . Protecting Yourself from Recruitment Scams Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We've observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information. To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind: No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates. * Please always verify communications: * Direct from Anduril: If you receive an email from one of our recruiters, it will only come from an @anduril.com address. * Via Agency Partner: If contacted by a recruiting agency for an Anduril role, their email will clearly identify their agency. If you suspect any suspicious activity, please verify the agency's authenticity by reaching out to . Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not engage. Always confirm the sender's email domain is @anduril.com before providing any personal information or clicking on links. What to Do If You Suspect Fraud: Should you encounter any questionable or fraudulent outreach claiming to be from Anduril, please report it immediately to . Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts. Data Privacy To view Anduril's candidate data privacy policy, please visit . By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Building Reliable Serverless Applications with AWS CDK and Testing](https://www.wearedevelopers.com/videos/812-building-reliable-serverless-applications-with-aws-cdk-and-testing) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [The power of Cloud Development Kit (CDK): How to get the most out of it](https://www.wearedevelopers.com/videos/740-the-power-of-cloud-development-kit-cdk-how-to-get-the-most-out-of-it) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)