Lead GRC Security Engineer

Lorien

United States

Remote

USD 165,000 - 240,000

Full time

38 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Lorien in Orange, CA is hiring a Governance, Risk, and Compliance Engineering Lead to drive the GRC program and build a scalable automation framework. You will set roadmaps, guide an expanding team, and translate frameworks into automated validations across cloud and on-prem systems.

Ideal candidates have 6+ years in security engineering or GRC, strong coding skills, and experience with Terraform/AWS CDK and key GRC platforms. Onsite in Orange County or fully remote option available.

Qualifications

  • 6+ years of hands-on experience in security engineering or GRC
  • Solid coding skills in at least one general-purpose programming language (Go, Python, or Rust)
  • Background working with security data lakes, log aggregation systems, or building queryable data marts
  • Direct, hands-on experience putting compliance frameworks into practice (CMMC, NIST 800-171, 800-53, FedRAMP, SOC 2)
  • Comfortable operating independently, taking ownership of undefined problems, and building consensus across partner teams
  • Familiarity with continuous control monitoring tools or GRC platforms (Vanta, Drata, Hyperproof, OneTrust)
  • Production-level experience with infrastructure-as-code tooling (Terraform, AWS CDK)
  • 6+ years in security engineering, GRC, or adjacent role with automation experience
  • Knowledge of STIG/ConMon scanning, CSPM tooling, or Kubernetes hardening
  • Experience architecting data collection across cloud/SaaS (APIs, log/event pipelines, data lakes)
  • Demonstrated history of guiding technical direction and mentoring engineering talent
  • Experience in fast-moving defense technology environments
  • Must qualify to obtain and hold a U.S. Secret-level security clearance

Responsibilities

  • Set the technical roadmap for the function and coach an expanding engineering team
  • Establish the technical foundation of the GRC program, engineering the pipeline and tooling for audit-ready evidence
  • Convert regulatory frameworks (CMMC, NIST 800-171, FedRAMP/IL5) into automated validations
  • Develop the pipeline that gathers evidence across internal systems and aligns it to a standardized control model
  • Create the authoritative system of record for controls, mappings, and evidence, guiding build-versus-buy decisions
  • Identify control drift and escalate findings with remediation paths
  • Design reusable collectors and schemas to simplify onboarding of new controls

Skills

Go
Python
Rust
Security data lakes
Data pipelines
Mentoring
APIs
Kubernetes hardening

Tools

Vanta
Drata
Hyperproof
OneTrust
Terraform
AWS CDK

Job description

Lead GRC Security Engineer (BBBH2325000) Orange, California

Salary: USD165000 - USD240000 per annum

Title: Security Engineering Lead (GRC)
Location: Onsite in Orange County, CA (or fully remote)
Pay: $165,000 - $240,000/year, depends on experience level
Type: Full time, Direct Hire

About the Team:
Lorien has an exciting opportunity for a Governance, Risk, and Compliance Engineering Lead to join our Defense Technology customer on a direct hire basis. We're looking for someone with 6+ years of hands-on experience in security engineering or GRC who thrives working independently, is energized by open-ended technical challenges, and is excited to shape the technical roadmap for this function as they build out the team behind it.

Responsibilities:
  • Set the technical roadmap for the function and coach an expanding engineering team
  • Establish the technical foundation of the GRC program, engineering the pipeline and tooling that convert internal systems into continuous, audit-ready compliance evidence, eliminating the last-minute crunch that typically happens when audits arrive
  • Convert regulatory frameworks (CMMC, NIST 800-171, FedRAMP/IL5) into automated technical validations with clear pass/fail outcomes
  • Develop the pipeline that gathers evidence across internal systems and aligns it to a standardized control model
  • Create the authoritative system of record for controls, mappings, and evidence, while leading the build-versus-buy decision-making process
  • Identify control drift and elevate findings to the relevant system owners, providing clear paths for remediation or formal risk acceptance
  • Design reusable collectors and schemas as standard reference architectures, so onboarding each new control becomes a matter of assembly rather than starting from scratch
Qualifications:
  • Solid coding skills in at least one general-purpose programming language (such as Go, Python, or Rust)
  • Background working with security data lakes, log aggregation systems, or building queryable data marts
  • Direct, hands-on experience putting compliance frameworks into practice (CMMC, NIST 800-171, 800-53, FedRAMP, SOC 2)
  • Comfortable operating independently, taking ownership of undefined problems, and building consensus across partner teams
  • Familiarity with continuous control monitoring tools or GRC platforms (Vanta, Drata, Hyperproof, OneTrust), or experience building custom equivalents in-house
  • Production-level experience with infrastructure-as-code tooling (e.g., Terraform, AWS CDK)
  • 6+ years working in security engineering, GRC, or an adjacent role, with real experience building automation or data pipelines
  • Working knowledge of STIG/ConMon scanning, CSPM tooling, or Kubernetes hardening practices
  • Experience architecting data collection and integration across cloud and SaaS environments (APIs, log/event pipelines, data lakes)
  • Demonstrated history of guiding technical direction and mentoring engineering talent
  • Background operating in fast-moving, high-growth defense technology settings
  • Must qualify to obtain and hold a U.S. Secret-level security clearance
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC Engineering Lead - Remote/OC
Security GRC Engineering Lead - Remote/OC

Lorien • United States

Remote
USD 165,000 - 240,000
Lead Security Engineer, GRC
Lead Security Engineer, GRC

Anduril • Washington

On-site
USD 166,000 - 253,000
Senior Cyber Security & GRC Engineer
Senior Cyber Security & GRC Engineer

Emergent Staffing • Hartford (CT)

On-site
USD 130,000 - 180,000
Sr. Security Assurance Engineer
Sr. Security Assurance Engineer

6sense • United States

On-site
USD 140,000 - 200,000
GRC Specialist (US Citizen)
GRC Specialist (US Citizen)

Oligo Cyber Security Ltd. • Illinois

On-site
USD 120,000 - 180,000
GRC Analyst II
GRC Analyst II

Frontgrade Technologies • Colorado Springs (CO)

On-site
USD 70,000 - 90,000
Immediate Medical, Dental, and Vision
401K Match with 100% immediate vesting
Tuition Reimbursement/Student Loan Repayment
+2
GRC Security compliance leader
GRC Security compliance leader

Avantdigitalnow • San Francisco (CA)

On-site
USD 120,000 - 150,000
GRC Analyst
GRC Analyst

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 81,000 - 99,000
Sr Security Engineer L5 (IT GRC)
Sr Security Engineer L5 (IT GRC)

Frontdoor, Inc. • Idaho

On-site
USD 124,000 - 150,000
Health insurance
401(k) matching
Stock purchase plan
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000