Anduril Industries logo
Anduril Industries

Lead Security Engineer, GRC

USAPosted 1 month ago

Apply opens Anduril Industries's site. When you're back, we'll ask whether you applied.

Job type
Full-time
Work mode
Not listed
Level
Lead
Department
Information Technology
Experience
6+ years experience
Posted
Aug 26, 2026

About the role

About the Team

Anduril's Security Engineering team is looking for a Governance, Risk, and Compliance Engineering Lead to build the engineering core of our GRC program: the pipeline and tooling that turn Anduril's systems into continuous, defensible evidence of compliance, replacing the manual scramble that happens at audit time. You'll set technical direction for the function and grow the team building it.

What You'll Do

  • Build the pipeline that collects evidence from Anduril's systems and maps it to a normalized control model
  • Construct reusable collectors and schemas as reference architectures so each new control is assembly, not reinvention
  • Stand up the system of record for controls, mappings, and evidence, and drive the build-vs-buy analysis
  • Surface control drift and route findings to system owners with clear remediation and risk-acceptance paths
  • Translate frameworks (CMMC, NIST 800-171, FedRAMP/IL5) into automatable technical checks and pass/fail signals
  • Set technical direction and mentor a growing engineering team

Required Qualifications

  • 6+ years in security engineering, GRC, or a related role, including hands-on building of automation or data pipelines
  • Strong programming ability in a general-purpose language (Go, Python, Rust, etc.)
  • Hands-on experience operationalizing compliance frameworks (CMMC, NIST 800-171, 800-53, FedRAMP, SOC 2)
  • Experience designing data collection and integration across cloud and SaaS systems (APIs, log/event pipelines, data lakes)
  • Experience with infrastructure as code (e.g., Terraform, AWS CDK) in a production capacity
  • Track record of setting technical direction and mentoring engineers
  • Ability to work autonomously, take ownership of ambiguous problems, and drive alignment across partner teams
  • Eligible to obtain and maintain a U.S. Secret clearance

Preferred Qualifications

  • Experience with continuous control monitoring or GRC platforms (Vanta, Drata, Hyperproof, OneTrust), or building bespoke equivalents
  • Experience with security data lakes, log aggregation, or building data marts for querying
  • Familiarity with STIG/ConMon scanning, CSPM, or Kubernetes hardening
  • Experience in fast-paced, high-growth defense technology environments