Senior Compliance Automation Engineer
True Anomaly
<div class="content-intro"><p class="ms-outlook-mobile-reference-message">Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it.</p> <p class="ms-outlook-mobile-reference-message"><u>OUR MISSION</u></p> <p class="ms-outlook-mobile-reference-message">True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors — enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground.</p> <p class="ms-outlook-mobile-reference-message"><u>OUR VALUES</u></p> <ul> <li class="ms-outlook-mobile-reference-message"><strong>Be the offset.</strong><span class="Apple-converted-space">&nbsp;</span>We create asymmetric advantages with creativity and ingenuity.</li> <li class="ms-outlook-mobile-reference-message"><strong>What would it take?</strong>&nbsp;We challenge assumptions to deliver ambitious results.</li> <li class="ms-outlook-mobile-reference-message"><strong>It’s the people.</strong>&nbsp;Our team is our competitive advantage and we are better together.</li> </ul></div><p><strong>Your Mission</strong></p> <p>We are seeking a Senior Compliance Automation Engineer to join our Governance, Risk, and Compliance (GRC) team and design and build True Anomaly's compliance automation platform from the ground up. This is a greenfield engineering role, not a configuration or administration position. You will not be deploying off-the-shelf GRC tools and calling it done. Instead, you will architect and engineer a purpose-built, continuous compliance monitoring platform capable of spanning a hybrid environment of on-premises classified systems and multi-cloud infrastructure (AWS GovCloud, Azure Government).</p> <p>This role sits at the intersection of software engineering, DevSecOps, and compliance, and demands someone who can write production-quality code, design robust API and webhook integration frameworks, and translate NIST SP 800-53 Rev. 5 and NIST SP 800-171 Rev. 3 control requirements into automated, evidence-generating technical workflows. You will own the architecture, build the pipelines, and integrate data from across the enterprise to produce a real-time, auditable, and scalable compliance posture built on infrastructure you design, not a vendor's dashboard.</p> <p>This position requires the ability to obtain and maintain a security clearance.</p> <p>&nbsp;</p> <p><strong>Responsibilities</strong></p> <p><strong>Compliance Automation Platform Engineering</strong></p> <ul> <li>Architect and build a greenfield Continuous Compliance Monitoring (CCM) platform from first principles, designed to aggregate, correlate, and report on security control status across hybrid on-premises and cloud environments in near real time.</li> <li>Design and implement a modular, API-first platform architecture with well-documented internal APIs and extensible data models that support rapid onboarding of new control families, systems, and data sources.</li> <li>Develop webhook-driven integration pipelines that ingest telemetry and compliance signals from diverse source systems, including cloud-native security services, SIEM platforms, vulnerability scanners, configuration management tools, and identity providers, without reliance on manual data collection or polling.</li> <li>Build control validation microservices that programmatically test the implementation state of NIST SP 800-53 and 800-