True Anomaly
Compliance Engineer III
About this role
True Anomaly seeks an experienced Compliance Engineer to design and operationalize secure cloud architectures in AWS and Azure Government environments while building compliance as a product. This hands-on role combines security engineering, STIG development, and GRC enablement with a focus on marketing compliance frameworks to engineering and business teams across the enterprise.
What you'll do
- Design, implement, and maintain secure systems in AWS and Azure Government aligned with DoD RMF (IL5/IL6) and CMMC frameworks
- Develop and maintain custom STIGs for cloud infrastructure, SaaS applications, and customer-deployed solutions
- Drive vulnerability remediation workflows, patch management, and automated response processes with DevOps teams
- Create and deliver compliance training programs, videos, and hands-on demonstrations across the enterprise
- Support audits and assessments as technical point of contact with evidence collection and system walkthroughs
- Productize GRC services by packaging controls, training, and compliance into clear offerings with messaging and adoption metrics
What they're looking for
- STIG development and vulnerability remediation
- AWS and Azure Government cloud platforms
- DoD RMF, CMMC, and compliance audit frameworks
- DevSecOps and SecOps practices
- Security tools (Nessus, JIRA, Docebo)
- Technical writing and content creation
- Video production and demo development
- Security questionnaire and RFP response support
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
True Anomaly
True Anomaly develops advanced spacecraft and aerospace defense systems for mission-critical space applications. The company is hiring mechanical, thermal, systems, and test engineers to design, test, integrate, and verify complex space vehicle systems.
- Website
- trueanomaly.com
Likely interview questions
- Describe your experience developing and maintaining STIGs—how have you tailored them for specific cloud platforms or applications?
- Tell us about a time you remediated a significant vulnerability across multiple systems—how did you coordinate with DevOps teams?