Lead GRC Security Engineer (BBBH2325000) Orange, California
Salary: USD165000 - USD240000 per annum
Title: Security Engineering Lead (GRC)
Location: Onsite in Orange County, CA (or fully remote)
Pay: $165,000 - $240,000/year, depends on experience level
Type: Full time, Direct Hire
About the Team:
Lorien has an exciting opportunity for a Governance, Risk, and Compliance Engineering Lead to join our Defense Technology customer on a direct hire basis. We're looking for someone with 6+ years of hands-on experience in security engineering or GRC who thrives working independently, is energized by open-ended technical challenges, and is excited to shape the technical roadmap for this function as they build out the team behind it.
Responsibilities:
- Set the technical roadmap for the function and coach an expanding engineering team
- Establish the technical foundation of the GRC program, engineering the pipeline and tooling that convert internal systems into continuous, audit-ready compliance evidence, eliminating the last-minute crunch that typically happens when audits arrive
- Convert regulatory frameworks (CMMC, NIST 800-171, FedRAMP/IL5) into automated technical validations with clear pass/fail outcomes
- Develop the pipeline that gathers evidence across internal systems and aligns it to a standardized control model
- Create the authoritative system of record for controls, mappings, and evidence, while leading the build-versus-buy decision-making process
- Identify control drift and elevate findings to the relevant system owners, providing clear paths for remediation or formal risk acceptance
- Design reusable collectors and schemas as standard reference architectures, so onboarding each new control becomes a matter of assembly rather than starting from scratch
Qualifications:
- Solid coding skills in at least one general-purpose programming language (such as Go, Python, or Rust)
- Background working with security data lakes, log aggregation systems, or building queryable data marts
- Direct, hands-on experience putting compliance frameworks into practice (CMMC, NIST 800-171, 800-53, FedRAMP, SOC 2)
- Comfortable operating independently, taking ownership of undefined problems, and building consensus across partner teams
- Familiarity with continuous control monitoring tools or GRC platforms (Vanta, Drata, Hyperproof, OneTrust), or experience building custom equivalents in-house
- Production-level experience with infrastructure-as-code tooling (e.g., Terraform, AWS CDK)
- 6+ years working in security engineering, GRC, or an adjacent role, with real experience building automation or data pipelines
- Working knowledge of STIG/ConMon scanning, CSPM tooling, or Kubernetes hardening practices
- Experience architecting data collection and integration across cloud and SaaS environments (APIs, log/event pipelines, data lakes)
- Demonstrated history of guiding technical direction and mentoring engineering talent
- Background operating in fast-moving, high-growth defense technology settings
- Must qualify to obtain and hold a U.S. Secret-level security clearance