Aalyria Logo

Aalyria

Security and Compliance Lead

Posted 3 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
180K-215K Annually
Senior level
Remote
Hiring Remotely in United States
180K-215K Annually
Senior level
Lead compliance initiatives for federal frameworks while enhancing security architecture, implementing controls, and managing compliance documentation and assessments.
The summary above was generated by AI
About Aalyria:

Aalyria is a leading technology company that supplies laser communications technology and temporospatial software-defined networking platforms to the aerospace industry. With technology acquired from Google, Aalyria is at the forefront of innovation in satellite and airborne mesh networks, as well as cislunar and deep-space communications. We are revolutionizing the orchestration and management of planetary mesh networks using any radio or optical spectrum, any orbit, and any hardware across land, sea, air, and space.

Role Overview:

We are looking for an experienced Security & Compliance Lead to join our team. The ideal candidate for this role has deep expertise in federal compliance frameworks including CMMC, FedRAMP, ITAR, and DFARS, combined with hands-on technical security implementation experience. We need someone who can navigate compliance frameworks and roll up their sleeves to implement controls, harden systems, and solve technical problems. We require an individual capable of navigating compliance frameworks, implementing controls, hardening systems, and resolving technical challenges.


You will be the primary owner of our government compliance programs while also contributing directly to security architecture, tooling, and engineering efforts. You will work closely with the Director of Security & IT, our engineering teams, and external partners to ensure we meet contractual and regulatory obligations. Come join a team building secure systems that support mission-critical communications for defense and federal customers.

Key Responsibilities:
  • Own CMMC L2 certification and FedRAMP High authorization efforts end-to-end, including gap analysis, remediation tracking, evidence collection, and assessment coordination
  • Maintain compliance with DFARS cybersecurity clauses (7012, 7019, 7020), ITAR, EAR and other federal requirements; manage SPRS score and supplier requirements
  • Develop and maintain System Security Plans, POA&Ms, policies, procedures, and supporting artifacts across all compliance frameworks
  • Serve as primary point of contact for C3PAO/3PAO assessors, government customers, prime contractors, and agency authorizing officials
  • Manage continuous monitoring activities including vulnerability scanning, access reviews, evidence collection, and monthly/annual reporting
  • Monitor regulatory changes across CMMC, FedRAMP, NIST 800-171/800-53, DFARS, and ITAR; assess impact and drive necessary updates
  • Implement security controls hands-on, including identity and access management, logging, encryption, and endpoint security
  • Harden cloud infrastructure in GCP, AWS, implementing security configurations and access controls aligned with compliance requirements
  • Build automation and tooling for evidence collection and compliance reporting; integrate security into CI/CD pipelines
  • Define, document, and enforce CUI boundaries and enclave architecture
  • Translate compliance requirements into actionable technical guidance for engineering teams
  • Support customer security assessments, due diligence requests, and contract security requirements
Required Qualifications:
  • 7+ years of experience in security roles with demonstrated compliance and technical responsibilities
  • Deep knowledge of federal compliance frameworks: NIST 800-171, NIST 800-53 Rev 5, CMMC 2.0, FedRAMP, and ITAR compliance and cybersecurity requirements
  • Experience preparing for and supporting third-party assessments (C3PAO, 3PAO, FedRAMP JAB/Agency, or equivalent)
  • Hands-on technical skills: ability to write scripts, Terraform, and troubleshoot access issues
  • Cloud security experience securing cloud environments (GCP preferred; AWS GovCloud)
  • Experience with enterprise IAM platforms (Okta, Azure AD, or similar)
  • Excellent documentation skills with ability to write policies that satisfy auditors and implementation guides that engineers can use
  • Strong communication skills with comfort presenting to auditors, executives, government customers, and authorizing officials
  • Combined experience in both compliance/GRC and hands-on technical security implementation
  • Experience leading or supporting third-party security assessments (C3PAO, 3PAO, FedRAMP JAB/Agency, or similar)
  • Ability to interpret NIST 800-53 controls and implement them in cloud environments
  • Working knowledge of CMMC, FedRAMP, and DFARS frameworks, including overlapping control requirements
  • Demonstrated ability to operate effectively in fast-paced environments with competing priorities
  • Experience building or significantly maturing a compliance program
  • U.S. Citizenship required
Preferred Qualifications:
  • FedRAMP authorization experience, ideally from initial readiness through ATO
  • CMMC C3PAO assessment experience
  • DoD or federal contractor background with understanding of regulatory environment and contract requirements
  • GCP experience including Security Command Center, Cloud Audit Logs, IAM, VPC Service Controls, and Assured Workloads
  • Infrastructure-as-code experience with Terraform, Ansible, or similar tools
  • GRC tooling experience (Vanta, Drata,or similar)
  • Security certifications such as CISSP, CISM, CGRC, CAP, or Security+
  • Familiarity with scripting languages (Python, Go, Bash)
  • Active Secret or Top Secret clearance, or ability to obtain
What We Offer:
  • Innovative Environment: Work at a cutting-edge company shaping the future of aerospace communications.
  • Impactful Work: Directly contribute to critical national security programs and initiatives.
  • Growth Opportunities: Expand your career with opportunities for professional development and advancement.
  • Inclusive Culture: Be part of a collaborative, supportive, and inclusive workplace where your contributions matter.
  • Flexibility: Flexible working arrangements including hybrid remote/in-office schedules.
  • Compensation and Equity: Competitive salary, comprehensive benefits (401(k), dental, vision, health, life insurance), paid time off, and equity options.
ITAR/EAR Requirements:

This position involves access to export-controlled information. To comply with U.S. government export regulations, applicants must meet one of the following criteria:


(A) Qualify as a U.S. person, which includes:

  • U.S. citizen or national
  • U.S. lawful permanent resident (green card holder)
  • Refugee under 8 U.S.C. 1157
  • Asylee under 8 U.S.C. 1158

(B) Be eligible to access export-controlled information without requiring an export authorization.


(C) Be eligible and reasonably likely to obtain the necessary export authorization from the appropriate U.S. government agency.


The company reserves the right to decline pursuing an export licensing process for legitimate business-related reasons.

Equal Opportunity Employer Statement:

Aalyria is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate based on race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, age, disability status, genetic information, protected veteran status, or any other characteristic protected by law. Qualified applicants from all backgrounds are encouraged to apply.


#LI-Remote

Top Skills

AWS
Azure Ad
Bash
Cmmc
Dfars
Fedramp
GCP
Go
Itar
Nist 800-171
Nist 800-53
Okta
Python
Terraform

Similar Jobs

23 Days Ago
Remote or Hybrid
United States
180K-299K Annually
Expert/Leader
180K-299K Annually
Expert/Leader
Automotive • Cloud • Greentech • Information Technology • Other • Software • Cybersecurity
Lead Cloud Security and Compliance practice at RapidScale, focusing on AI-driven security strategies, team management, client engagements, and developing innovative security offerings.
Top Skills: AIAWSAzureCybersecurityGoogle
An Hour Ago
Remote or Hybrid
United States
123K-169K Annually
Senior level
123K-169K Annually
Senior level
Digital Media • Fintech • Information Technology • Mobile • Payments • Software • Financial Services
The Senior Solutions Consultant will demonstrate digital banking solutions to clients, establish relationships throughout the sales cycle, and collaborate with sales teams.
Top Skills: Digital Banking SolutionsMobile DevicesProjection/Mirroring SoftwareTabletsTechnical ArchitectureWireless Connectors
An Hour Ago
Remote or Hybrid
United States
45K-45K Annually
Junior
45K-45K Annually
Junior
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
The role involves providing exceptional customer service for Group Variable Universal Life insurance policies, responding to inquiries, and educating customers on policy features.
Top Skills: Computer Systems

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account