Lead Security Engineer, GRC
Anduril IndustriesAbout the role
<div class="content-intro"><p>Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.</p></div><h2><strong>ABOUT THE TEAM</strong></h2> <p>Anduril's Security Engineering team is looking for a Governance, Risk, and Compliance Engineering Lead to build the engineering core of our GRC program: the pipeline and tooling that turn Anduril's systems into continuous, defensible evidence of compliance, replacing the manual scramble that happens at audit time. You'll set technical direction for the function and grow the team building it.<br><br><strong>WHAT YOU'LL DO</strong></p> <ul> <li>Build the pipeline that collects evidence from Anduril's systems and maps it to a normalized control model</li> <li>Construct reusable collectors and schemas as reference architectures so each new control is assembly, not reinvention</li> <li>Stand up the system of record for controls, mappings, and evidence, and drive the build-vs-buy analysis</li> <li>Surface control drift and route findings to system owners with clear remediation and risk-acceptance paths</li> <li>Translate frameworks (CMMC, NIST 800-171, FedRAMP/IL5) into automatable technical checks and pass/fail signals</li> <li>Set technical direction and mentor a growing engineering team</li> </ul> <h4><strong>REQUIRED QUALIFICATIONS</strong></h4> <ul> <li>6+ years in security engineering, GRC, or a related role, including hands-on building of automation or data pipelines</li> <li>Strong programming ability in a general-purpose language (Go, Python, Rust, etc.)</li> <li>Hands-on experience operationalizing compliance frameworks (CMMC, NIST 800-171, 800-53, FedRAMP, SOC 2)</li> <li>Experience designing data collection and integration across cloud and SaaS systems (APIs, log/event pipelines, data lakes)</li> <li>Experience with infrastructure as code (e.g., Terraform, AWS CDK) in a production capacity</li> <li>Track record of setting technical direction and mentoring engineers</li> <li>Ability to work autonomously, take ownership of ambiguous problems, and driv
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s