Federal Compliance Lead

WindBorne Systems

Completely RemoteFull TimeInformation Technology
Posted 3 days ago

Job description

About the Company

WindBorne Systems is supercharging weather forecasts with a unique proprietary data source: a global constellation of next-generation smart weather balloons targeting the most critical atmospheric data. The founding team of Stanford engineers is backed by top-tier investors, including Khosla Ventures and Footwork VC.

Responsibilities

  • Build the government compliance function from scratch and own it end-to-end
  • Lead the company through CMMC Level 2 certification, FedRAMP, IL5, and IL6
  • Translate complex federal regulatory frameworks into practical decisions regarding technical architecture, documentation, and process
  • Coordinate compliance implementation across engineering, operations, and business development teams

Requirements

  • 3+ years experience with compliance audits (FedRAMP, PCI, SOC2, HIPAA, etc.)
  • Prior US Government compliance and audit experience (FedRAMP, FISMA, NIST 800-53, NIST 800-171, US Government ATOs)
  • Experience defining CUI boundaries and scoping assessment environments
  • Experience writing or contributing to a System Security Plan
  • Proficiency with GRC platforms (Drata, Vanta, eMASS, or similar)
  • Experience implementing security controls in cloud infrastructure (AWS, Azure)
  • Deep understanding of cloud infrastructure and ephemeral technologies like containers
  • Proficiency with security concepts and continuous monitoring tooling
  • Strong project management skills
  • Ability to obtain a US security clearance

Benefits

  • 401(k)
  • Dental insurance
  • Health insurance
  • Vision insurance
  • Unlimited PTO
  • Stock Option Plan
  • Office food and beverages

Skills & tools

FedRAMPCMMCNIST

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 013+ years compliance audit experience
  2. 02US Government compliance experience
  3. 03Experience with CUI boundaries
  4. 04System Security Plan experience
  5. 05GRC platform proficiency
  6. 06Cloud infrastructure security experience
  7. 07Ability to obtain US security clearance
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches