Senior Governance, Risk, and Compliance Engineer

Job not on LinkedIn

🕒 May 22

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of IonQ

IonQ

201 - 500 employees

Founded 2015

🤖 Artificial Intelligence

🔌 API

🏢 Enterprise

Artificial Intelligence • API • Enterprise

IonQ is a company specializing in quantum computing, providing a quantum cloud platform that allows users to access and utilize quantum processors. They offer extensive documentation and resources for developers to learn and implement quantum computing solutions using their SDKs and APIs, integrating with platforms like Qiskit, Cirq, and TensorFlow. IonQ also offers integrations with cloud services such as Amazon Braket, enabling hybrid cloud quantum computing. Their platform includes tools for managing jobs, organizations, and projects, as well as simulators that support noise models and up to 29 qubits. IonQ is dedicated to advancing quantum computing technology and provides community support through channels like Slack.

📋 Description

• Architect and own end-to-end CMMC implementation and audit readiness, including scoping strategy, control mapping, SSP and POA&M development, evidence collection, and remediation tracking across the organization. • Interpret and apply DFARS clause requirements, including DFARS 252.204-7012, 252.204-7019, and 252.204-7020, translating contractual obligations into operational controls and owning accurate SPRS submissions. • Lead recurring internal audits of NIST 800-171 security controls and drive end-to-end preparation for C3PAO assessments, including evidence packages, assessment logistics, and assessor coordination. • Architect CUI environments to meet CMMC boundary requirements, including network segmentation, access control, media protection, and FIPS-validated encryption; lead evaluation of cloud environments against CMMC scoping guidance. • Drive implementation of technical controls across NIST 800-171 practice families, including MFA, audit logging, configuration management, incident response, and vulnerability management, engaging directly with engineering teams. • Serve as the primary CMMC subject matter expert at IonQ, developing compliance roadmaps, facilitating readiness workshops, and providing authoritative guidance on DFARS flow-down requirements for subcontractors. • Partner with legal and contracts teams to review FAR/DFARS clauses in new and existing contracts, flagging CUI obligations and CMMC level requirements, and lead coordination with regulatory teams on ITAR and EAR obligations as they intersect with CUI handling. • Develop and operate a formal risk management program covering IT systems and infrastructure, maintain a risk register, and provide regular executive-level reporting on posture, open risks, and remediation progress. • Own and mature the organization’s GRC platform to support evidence management, POA&M tracking, and risk register maintenance, and build compliance dashboards for leadership visibility.

🎯 Requirements

• 5–8 years of professional experience in cybersecurity compliance, GRC, or security engineering, with demonstrated hands-on ownership of NIST SP 800-171 and CMMC compliance programs. • Proven track record developing SSPs, POA&Ms, and C3PAO assessment artifacts, and independently scoping CUI environments across realistic system boundaries. • Deep working knowledge of DFARS cybersecurity clauses (7012, 7019, 7020), CMMC 2.0 framework structure across all three levels, and the difference in assessment methodology between self-assessment and C3PAO. • A technical background in systems administration, cloud security, or security engineering sufficient to credibly lead control implementation discussions with IT and engineering teams, including network architecture, IAM, key management, logging, and endpoint management. • Experience leading cross-functional compliance initiatives and translating technical requirements for non-technical stakeholders including legal, finance, and executive leadership. • Bachelor’s degree in Computer Science, Information Security, or equivalent practical experience.

🏖️ Benefits

• Comprehensive medical, dental, and vision plans • Matching 401K • Unlimited PTO and paid holidays • Parental/adoption leave • Legal insurance • Home technology stipend

Apply Now

Similar Jobs

🕒 May 22

Saks

1001 - 5000

🛒 Retail

👗 Fashion

🛍️ eCommerce

Import Coordinator overseeing customs compliance and import documentation for Saks Global. Collaborating with internal and external stakeholders to streamline import processes and improve efficiency.

🕒 May 22

iRhythm Technologies, Inc.

1001 - 5000

⚕️ Healthcare Insurance

🧬 Biotechnology

Compliance & Ethics Specialist developing insights and training materials for patient care at iRhythm. Analyzing data and collaborating across functions to support strategic initiatives.

🕒 May 22

InvestCloud, Inc.

1001 - 5000

💳 Fintech

☁️ SaaS

🤝 B2B

Senior Compliance Analyst at InvestCloud managing security and compliance controls. Collaborating with technical teams to ensure adherence to regulations and standards.

🕒 May 22

NextGen Healthcare

1001 - 5000

⚕️ Healthcare Insurance

☁️ SaaS

📡 Telecommunications

Senior Engineer overseeing audit and compliance programs at NextGen Healthcare, ensuring alignment with regulatory and security requirements. Leading audit lifecycle and optimizing GRC solutions for efficient compliance operations.

🕒 May 22

Twilio

5001 - 10000

Strategy & Operations role focusing on telecommunications compliance at Twilio. Leading strategic execution and governance for global communications platform compliance initiatives.