Wiz Logo

Wiz

Senior Compliance Operations Engineer - Public Sector

Posted 17 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
151K-208K Annually
Senior level
Remote
Hiring Remotely in USA
151K-208K Annually
Senior level
The Senior Compliance Operations Engineer will operationalize and improve FedRAMP High and DoD IL5 compliant cloud environments, automate compliance controls, and support continuous monitoring and audits.
The summary above was generated by AI

Come join the company that is reinventing cloud security and empowering businesses to thrive in the cloud. As the fastest-growing startup ever, Wiz is on a mission to help organizations secure cloud environments that will accelerate their businesses. Trusted by security teams all over the world, we have a proven track record of success and a culture that values world-class talent.  

Our Wizards from over 20 countries work together to protect the infrastructure of our hundreds of customers, including over 50% of the Fortune 100, who trust us to scan and secure over 230 billion files daily. We’re the leading player in a massive and growing market, but it’s still early enough for you to make a significant impact. At Wiz, you’ll have the freedom to think creatively, dream big, and use your full range of skills to contribute to our record growth. Come join our team and help us create secure cloud environments that allow the best companies to move faster. 

SUMMARY

The Corporate & Public Sector Strategy Team aims to accelerate Wiz’s growth by developing a comprehensive strategy, in tight partnership with all other organizations, to drive customer value and adoption. As we continue to grow at an incredible speed, we work to ensure each sales team member is set up for success at every phase. We take both a bird’s eye view and dive into the weeds to solve problems as a team to drive employee success and revenue. 

We are seeking an experienced Senior Compliance Operations Engineer that will contribute to the operationalization, sustainment, and continuous improvement of our FedRAMP High and DoD IL5 compliant cloud environments. This senior individual contributor role bridges compliance requirements with real-world engineering practices, ensuring our cloud services meet stringent federal and defense standards while maintaining high availability, security, and audit-readiness.

You will serve as a key technical SME on NIST SP 800-53 controls (tailored for FedRAMP High and DoD SRG IL5 overlays), translate regulatory mandates into automated controls and monitoring, lead continuous monitoring activities, oversee remediation efforts, and play a major role in assessments/audits. This position requires deep hands-on experience implementing and operating compliance in FedRAMP High + DoD IL5 cloud systems (AWS GovCloud, Azure Government, or equivalent).

You will be asked to quickly learn the challenges of the business and find ways to simplify processes within our compliance operations to increase productivity and efficiency. More importantly, the role requires a personality that promotes collaboration and unity.  

WHAT YOU’LL DO

  • Document security controls and architectures that satisfy FedRAMP High baseline requirements and DoD Cloud Computing Security Requirements Guide (SRG) overlays for Impact Level 5 (including handling of high-sensitivity CUI and unclassified National Security Systems).
  • Oversee continuous monitoring (ConMon) programs including vulnerability scanning, configuration monitoring, log aggregation/analysis, boundary protection validation, and monthly/ongoing reporting to meet FedRAMP and DoD expectations.
  • Translate NIST 800-53 Rev. 5 controls and DoD-specific enhancements into operational requirements; partner with engineering, DevOps, and product teams to embed compliance into their processes.
  • Lead preparation, evidence collection, and remediation for FedRAMP reassessments, 3PAO audits, DoD Provisional Authorizations, Significant Change Requests (SCRs), and contribute to Plan of Action & Milestones (POA&M) management.
  • Automate compliance validation for control implementation verification and drift detection.
  • Conduct technical risk assessments, root-cause analysis on compliance findings, and provide guidance for implementation of compensating controls or hardening measures in cloud environments.
  • Support incident response and boundary protection activities in IL5 environments, ensuring alignment with DoD policies for mission-critical workloads.
  • Maintain and update compliance documentation including System Security Plans (SSP), control implementation descriptions, architectural diagrams, and boundary definitions.
  • Collaborate cross-functionally with legal, product, engineering, and federal customer teams to scope new features/services while preserving authorization boundaries.
  • Mentor others on FedRAMP/DoD compliance best practices and contribute to internal training programs.
  • Align and coordinate complex, cross-functional federal programs/projects which include FedRAMP and/or DoD authorizations and/or the operational process requirements needed to meet ongoing operational requirements.

WHAT YOU’LL BRING

  • 7+ years of hands-on experience in cloud security engineering, compliance operations, or GRC roles, with at least 4+ years directly supporting FedRAMP Moderate/High and DoD IL4/IL5 authorizations.
  • In-depth expertise in NIST SP 800-53 Rev. 5, FedRAMP baselines (especially High), DoD Cloud SRG, and associated control overlays for IL5.
  • Proven track record implementing and operating continuous monitoring in production FedRAMP and DoD IL4/IL5 environments, including vulnerability management, configuration compliance, and audit evidence generation.
  • Experience with DoD-specific tools/processes (e.g., eMASS, ACAS, HBSS, STIGs).
  • Experience with DoD BCAP architecture and configuration.
  • Strong experience with cloud platforms in government spaces (AWS GovCloud, Azure Government, Google Cloud for Government, or equivalent) and associated security services.
  • Proficiency in automation/scripting (Python, Bash, PowerShell) and Infrastructure as Code (Terraform, Ansible, Puppet/Chef preferred).
  • Familiarity with tools for compliance automation and scanning (e.g., Chef InSpec, OpenSCAP, Qualys, Tenable, AWS-native tools, Azure Security Center).
  • U.S. Citizenship required (due to handling of CUI and potential access to controlled environments).
  • Knowledge of additional frameworks that overlap with FedRAMP/DoD (e.g., CMMC, NIST 800-171/172, FISMA).

Preferred Qualifications

  • Ability to obtain and maintain a U.S. Secret or higher security clearance (active clearance strongly preferred).
  • Active security certifications such as CISSP, CCSP, CISM, AWS/GCP/Azure Security Specialty, or DoD 8570/8140 IAT Level III / IAM Level III.

Candidates must meet EAR part 772 and ITAR 120.15 definition of a U.S. person (Any individual who is granted U.S. citizenship; or any individual who is granted U.S. permanent residence (green card holder); or any individual who is granted status as a “protected person”) and that they reside in the contiguous United States.

Benefits 

Wiz offers a competitive package of benefits and programs to support you and your family. Below provides a description of our current benefits for employees in the US. Specific benefits may vary by location. 

Health & Welfare Benefits 

  • Medical, dental and vision insurance 
  • Home Office Setup reimbursement 
  • Flexible Spending Accounts 
  • Monthly Connectivity reimbursement 
  • Employee Assistance Program (EAP) 

Financial Benefits 

  • Short- and Long-term Disability Insurance 
  • Life & Accident Insurance 
  • 401(k) Retirement Savings Plan (with employer match) 

Time Off 

  • Flexible paid time off + 11 paid holidays 
  • Paid leave programs, including parental, pregnancy health, medical and bereavement leave 

Compensation 

Starting compensation will be determined based on various factors, including but not limited to, the candidate's job-related experience, skills and geographic location. Your Talent Partner can share more about the specific salary range during the hiring process. 

This role is eligible to participate in Wiz’s equity plan and may also include incentive compensation. 

The annual base salary range for this full-time position is listed below. 

US Base Pay Range
$151,000$208,000 USD

Applicants must have the legal right to work in the country where the position is based, without the need for visa sponsorship. This role does not offer visa sponsorship.

Wiz is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. 

By submitting your application, you acknowledge that Wiz will process your personal data in accordance with Wiz's Privacy Policy.

Top Skills

Ansible
Aws Govcloud
Aws-Native Tools
Azure Government
Azure Security Center
Bash
Chef
Chef Inspec
Dod Il5
Fedramp High
Nist Sp 800-53
Openscap
Powershell
Python
Qualys
Tenable
Terraform
HQ

Wiz New York, New York, USA Office

New York, NY, United States

Similar Jobs

An Hour Ago
Remote
United States of America
Internship
Internship
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
Contribute to Product Security by building automation to triage and remediate CodeQL alerts, design AI-assisted workflows to prioritize findings, tune static analysis rules, and integrate CodeQL checks into CI/CD pipelines while collaborating with security and engineering teams.
Top Skills: Python,Javascript,Java,Codeql,Ci/Cd,Github Advanced Security,Snyk,Wiz,Sast,Sca,Devsecops,Ai Agents,Static Analysis
An Hour Ago
Remote
United States of America
145K-193K Annually
Expert/Leader
145K-193K Annually
Expert/Leader
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
Lead and manage a regional KYC team handling B2B onboarding, enhanced due diligence, and periodic reviews. Ensure SLA adherence, high-quality risk memos, AI-driven workflow improvements, audit readiness, and strong cross-functional partnerships with product, engineering, QA, and commercial teams while monitoring regulatory developments.
Top Skills: Google Workspace,Slack,Macos,Ai-Enabled Tools,Ai-Assisted Research Or Workflow Tools
An Hour Ago
Remote
United States of America
140K-185K Annually
Senior level
140K-185K Annually
Senior level
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
Lead second-line, risk-based compliance testing and monitoring across AML, BSA, Sanctions, and enterprise programs. Plan, execute, and document testing, identify findings, support root cause analysis and remediation, validate control effectiveness across jurisdictions, and improve testing methodologies and reporting while partnering with stakeholders.
Top Skills: ChainalysisChatgptEllipticGeminiGoogle SuitemacOSSlackTrm Labs

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account