Compliance Engineer - US Public Sector
at Wiz, Inc.
- Work model
- Remote
- Location
- Remote - USA
- Posted
- 5d ago
at Wiz, Inc.
<div class="content-intro"><p>Come join the organization that is redefining security for the AI era. As one of the<a href="https://www.wiz.io/blog/100m-arr-in-18-months-wiz-becomes-the-fastest-growing-software-company-ever"> fastest-growing startups ever,</a> we enable teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. Trusted by security teams all over the world, we have a proven<a href="https://www.g2.com/products/wiz-wiz/reviews"> track record of success</a> and a culture that values world-class talent. Not to mention, we're now<a href="https://cloud.google.com/blog/products/identity-security/google-completes-acquisition-of-wiz"> powered by Google</a>, meaning we offer our customers an AI-powered platform that harnesses Google’s Threat Intelligence and Security Operations to better detect, prevent, and respond to threats across all environments, allowing for further innovation.</p> <p>Our Wizards from all over the globe work together to protect the infrastructure of our customers, including over 65% of the Fortune 100, who trust us to scan and secure over 230 billion files daily. We’re honored to be a leading player in a massive and growing market, and we continue to look for exceptional Wizards who are eager to make a significant impact on our team. At Wiz, you’ll have the freedom to think creatively, dream big, and use your full range of skills to contribute to our momentous growth. Come join our team and help us create secure cloud environments that allow even the best companies to move faster, all while having some fun!</p></div><p><strong><span data-markdown-start-index="1433">Minimum qualifications</span></strong></p> <ul> <li> <p><span data-markdown-start-index="271">6+ years of experience in security engineering, DevOps, and systems engineering, with a proven ability developing processes and writing code to solve security/compliance problems.</span></p> </li> <li> <p><span data-markdown-start-index="452">4+ years of expertise in NIST SP 800-53, FedRAMP High baselines, and DoW SRG overlays, with a proven ability to assess risk, reduce risk, and build engineering solutions that enable compliance.</span></p> </li> <li> <p><span data-markdown-start-index="647">Deep understanding of the differences between FR 20x and CR26 ruleset for Rev5 authorizations and the impacts these rule changes have on Cloud Service Providers (CSPs).</span></p> </li> <li> <p><span data-markdown-start-index="817">Experience working in a cloud-native environment with DevSecOps technologies, specifically including CI/CD, Containers, and Kubernetes.</span></p> </li> <li> <p><span data-markdown-start-index="954">Strong proficiency in scripting and Infrastructure as Code (IaC), with specific requirements for Shell Scripting, Python, Terraform or OpenTofu, and Preferred AI Harness (Claude Code, OpenAI Codex).</span></p> </li> <li> <p><span data-markdown-start-index="1154">Experience with cloud platforms in government spaces.</span></p> </li> </ul> <p><strong><span data-markdown-start-index="1893">Preferred qualifications</span></strong></p> <ul> <li> <p><span data-markdown-start-index="1239">Experience with AWS GovCloud.</span></p> </li> <li> <p><span data-markdown-start-index="1270">Experience in Azure Government, Google Cloud for Government (Assured Workloads), or equivalent and associated security services.</span></p> </li> <li> <p><span data-markdown-start-index="1400">Experience with DevSecOps technologies including Microservices, GitOps, and Observability / Logging / SIEM / Platforms.</span></p> </li> <li> <p><span data-markdown-start-index="1521">Experience with Packer, other Configuration as Code tools, and Policy as Code tools.</span></p> </li> <li> <p><span data-markdown-start-index="1607">Experience automating compliance validation using cloud-native tools.</span></p> </li> </ul> <p><strong><span data-markdown-start-index="511">About the job</span></strong></p> <p><span data-markdown-start-index="1694">The Public Sector Compliance Operations Team aims to accelerate Wiz’s growth by developing a comprehensive strategy, in tight partnership with all other organizations, to drive customer value and adoption. As we continue to grow at an incredible speed, we work to ensure each sales team member is set up for success at every phase. We take both a bird’s eye view and dive into the weeds to solve problems as a team to drive employee success and revenue.</span></p> <p><span data-markdown-start-index="2149">We are seeking an experienced Compliance Engineer to serve as the strategic technical lead for Wiz’s FedRAMP CR26 initiative. You will define the long-term technical roadmap by architecting comprehensive compliance-as-code solutions, utilizing both Wiz's native features and custom-developed automations outside the platform to efficiently address CR26 Class D rule changes. This individual contributor role bridges complex regulatory requirements with scalable engineering practices, ensuring our cloud services meet stringent federal and defense standards while maintaining high availability, security, and audit-readiness.</span></p> <p><span data-markdown-start-index="2769">You will be asked to quickly learn the challenges of the business and find ways to simplify processes within our compliance operations to increase productivity and efficiency. More importantly, the role requires a personality that promotes collaboration and unity.</span></p> <p><strong><span data-markdown-start-index="2378">Responsibilities</span></strong></p> <ul> <li> <p><span data-markdown-start-index="3058">Lead the technical roadmap for FedRAMP Continuous Monitoring, moving from manual reporting to an automated, real-time telemetry model.</span></p> </li> <li> <p><span data-markdown-start-index="3194">Architect compliance outcomes by translating NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering and product solutions.</span></p> </li> <li> <p><span data-mar