Hiring.Camp

Senior Compliance Engineer (Remote From Anywhere In CO)

State of Colorado

·

Yesterday

Salary
$110k – $125k/yr
Location
Statewide, CO, CO, US
Department
Engineering
Seniority
Senior
Experience
1+ years
Visa
Not sponsored
Source
GovernmentJobs

Description



Together, we innovate for a stronger Colorado

The work of employees at the Governor's Office of Information Technology (OIT) is challenging and diverse because the needs of agencies, customers and Coloradans constantly evolve. But our focus never changes: improve the lives of all Coloradans through innovation and collaboration. We're building one of the nation's leading government IT organizations by reimagining how we support agencies, building first-of-their-kind applications, and creating an inclusive, collaborative culture, together. Join us in the important work of providing equitable access to services.


Watch this video to learn more about how we're Serving People. Serving Colorado.


TERM LIMITED POSITION: This position is term limited with an anticipated end date of approximately one year from the date of hire. This position is eligible for State employee benefits and may be extended as the situation warrants. This video explains the many benefits of working at the State of Colorado on a term limited basis. 


IMPORTANT NOTE: Please review your application to ensure completion. For the most equitable applicant experience, OIT’s hiring team considers only the contents of your application to review your qualifications. Please do not include any attachments (such as resume or cover letter) with your application as these items are not used by OIT’s hiring team. 

Are you a security-minded strategist ready to protect the heart of Colorado’s digital infrastructure? The Governor's Office of Information Technology is seeking a Senior Compliance Engineer to anchor our Information Security Office. In this high-impact role, you will be the guardian of the state's data assets, leading the development and execution of our compliance program against rigorous standards like the NIST Cybersecurity Framework, HIPAA, CJIS, and IRS Publication 1075. You won’t just write policies—you’ll translate complex technical realities into clear, actionable strategies that empower leadership and stakeholders to make informed, risk-aware decisions. By bridging the gap between technical operations and regulatory requirements, you will ensure our state’s public services remain resilient, secure, and worthy of our citizens' trust.


Essential Functions:

  • Policy & standard development (Govern — GV.PO) - Write, maintain, and version-control security policies, standards, and secure configuration baselines aligned to NIST 800-53 control families, incorporating requirements from IRS Publication 1075 (federal tax information safeguards), HIPAA Security Rule, and the FBI CJIS Security Policy where applicable. Where feasible, codify standards as Policy as Code so requirements are machine-enforceable rather than documentation-only. Outcome: a current, approved policy library that maps directly to control families, satisfies overlapping regulatory obligations without gaps, and is enforceable through automated guardrails.

  • Control mapping & framework alignment (Identify — ID.RA / Govern — GV.OC) - Map internal technical and administrative controls to NIST CSF categories and NIST 800-53 controls, cross-walking to IRS Pub 1075, HIPAA, and CJIS requirements to identify overlaps and unique obligations across regulatory regimes. Outcome: a unified control matrix showing full framework coverage with clear ownership, avoiding duplicate or conflicting control implementations.

  • Compliance monitoring & evidence collection (Detect — DE.CM) - Design and operate continuous monitoring processes to assess control effectiveness and automate evidence collection to support NIST, IRS Safeguards, HIPAA, and CJIS audit requirements, leveraging Policy as Code scans and Infrastructure as Code drift detection to continuously validate control state. Outcome: audit-ready evidence available on demand across all applicable regulatory regimes, with control drift caught automatically rather than at audit time.


  • Technical control implementation guidance (Protect — PR.PS / PR.AA) - Translate NIST, IRS Pub 1075, HIPAA, and CJIS control requirements into technical specifications engineering and IT teams can implement (e.g., FTI data handling and encryption per IRS Pub 1075, PHI access controls per HIPAA, criminal justice data handling and advanced authentication per CJIS). Partner with engineering to embed these requirements directly into Infrastructure as Code templates (e.g., Terraform, CloudFormation modules) so compliant configurations are the default at deployment time. Outcome: controls that satisfy the most stringent applicable requirement, are functionally effective in production, and are consistently applied through reusable, version-controlled infrastructure templates.


  • Procedure & runbook documentation (Govern — GV.PO / Protect — PR.PS) - Author standard operating procedures and control-testing runbooks that support repeatable compliance activities, including regime-specific procedures (e.g., FTI incident reporting per IRS Pub 1075, breach notification per HIPAA, CJIS personnel security screening), and document how Policy as Code rules and Infrastructure as Code modules map back to the controls they satisfy. Outcome: processes that don't rely on institutional knowledge held by one person, and can be handed off, independently audited, or traced from control to enforced code.


  • Regulatory & framework change management (Govern — GV.OC) - Monitor updates to NIST publications, IRS Publication 1075, HIPAA regulations, and the CJIS Security Policy, updating internal policies, standards, and corresponding Policy as Code rules and IaC baseline templates accordingly. Outcome: the policy library and its codified enforcement mechanisms stay current with minimal lag after any framework or regulatory change takes effect.


  • Cross-functional compliance training (Govern — GV.RR) - Develop and deliver training and reference documentation to help engineering, IT, and program staff understand and apply NIST, IRS Pub 1075, HIPAA, and CJIS requirements relevant to their roles, including how to work within Policy as Code guardrails and approved IaC modules rather than around them. Outcome: fewer compliance violations caused by lack of awareness, and higher developer adoption of compliant-by-default infrastructure patterns.


  • Metrics & compliance reporting (Govern — GV.OV) - Define and track compliance KPIs mapped to control maturity across NIST, IRS Safeguards, HIPAA, and CJIS (e.g., % of controls assessed, time-to-remediate findings, policy review currency, audit finding closure rates by regime, % of infrastructure provisioned through compliant IaC templates, Policy as Code rule pass/fail rates). Outcome: leadership has a clear, quantifiable view of compliance posture, trends, and the degree to which compliance is automated versus manually enforced.




Additional Functions: 

Self-Direction & Autonomy

  • Operates independently with minimal supervision; exercises sound judgment in ambiguous or evolving situations

  • Prioritizes and manages a complex workload across competing deadlines without day-to-day direction

  • Recognizes when to escalate versus when to resolve independently


Continuous Improvement Ownership

  • Proactively identifies gaps or inefficiencies in the compliance program and drives improvements without being asked

  • Stays current on evolving threats, regulatory changes, and framework updates (e.g., NIST CSF, CJIS, IRS revisions) and incorporates them into practice

  • Seeks feedback on their own work product and iterates on methodologies, templates, and reporting over time


Mentorship & Influence

  • Mentors others  

  • Influences stakeholders and leadership without formal authority — builds credibility through sound analysis rather than positional power

  • Acts as a subject-matter resource other teams turn to for compliance-related questions


Accountability & Ownership

  • Takes ownership of outcomes, not just tasks — follows through on remediation and reporting until issues are genuinely resolved

  • Documents decisions and rationale clearly enough to withstand audit or leadership scrutiny


Judgment Under Ambiguity

  • Comfortable making recommendations with incomplete information

  • Balances competing priorities (security, budget, mission delivery, public accountability) rather than defaulting to a single lens


Communication & Composure

  • Communicates effectively under pressure, including during incidents or audit findings

  • Adapts communication style for technical staff, program managers, and non-technical executives or elected oversight bodies


Professional Development

  • Maintains and pursues relevant certifications (CISSP, CRISC, CISA, CGRC, GRCP) as a mark of ongoing self-investment

  • Participates in professional communities to bring outside perspective back into the agency



Why Join Us:

Join a supportive, growth-oriented team committed to diversity, equity, and inclusion. Help us protect our infrastructure, safeguard our reputation, and shape the future of our organization.




A wide salary range is posted for this position and any job offer is based upon a salary analysis to comply with the Colorado Equal Pay for Equal Work Act. The salary analysis considers relevant experience, education, certifications, and state seniority as compared to others doing substantially similar work. While most salary offers are made within the posted range, occasionally an offer is made below or above the posted range based upon this salary analysis.

This is a skills-based job announcement. The required minimum qualifications and/or education (if substituting for the proven experience, knowledge, and skills), are as follows:

To better understand your qualifications and increase your opportunity to move forward in the selection process, please indicate in your work history for each job the outcomes you have achieved that you believe are most relevant to this job.



Minimum Qualifications:


At Least five (5) years of experience in a technology engineering role such as application developer or system administrator. At least three (3) years of experience supporting audit or compliance programs  (e.g., NIST 800-53 CJIS, IRS, HIPAA, SSA, SOC 2, or similar).



Substitutions:


  • Additional appropriate education will substitute for the required experience on a year-for-year basis, but cannot completely substitute for these qualifications. 

  • Training or Certification related to the work assigned to the position will be assigned credit towards substitution for experience and/or education, but cannot completely substitute for these qualifications. 

  • If the minimum qualifications include a degree requirement, additional appropriate paid or unpaid experience will substitute for the required education on a year-for-year basis.



Preferred Qualifications:


  • 1 year of experience implementing automated compliance guardrails using Policy as Code (e.g., OPA/Rego, Sentinel, Checkov, or cloud-native policy services) within CI/CD pipelines or infrastructure provisioning workflows.

  • Professional security certification.

  • Exposure to Governance, Risk and Compliance (GRC) tooling, such as ServiceNow GRC, Archer, or similar platforms.

  • Project management experience.



Conditions of Employment:

OIT employees must comply with any screening procedures in place at state agency locations where they might perform work. 

A pre-employment background check will be conducted as part of the selection process. Post-employment background checks will be required for specific agencies as business needs dictate, which may include a polygraph exam, fingerprint-based criminal history search, reference checks, and a drug test.

This position may require travel within the specified geographic area, and to locations across the state as needed. 

This position may require on-call duties as needed by the position. 




If this posting indicates “remote from anywhere in CO” in the title, periodic reporting to the primary state work location designated for the position is required. All remote work must be performed in Colorado. 


While candidates from out of state will be considered for this role, the candidate selected for the position must relocate and reside in Colorado on the first day of their new position.  A reasonable timeframe for relocation will be established on an individual basis, while considering business needs, and determining a start date.

We know it's important to support each other, and that means having a healthy balance of work and personal time. Visit our benefits to learn more about some of our great offerings that allow us all to have fulfilling lives. 


Visit our How to Apply webpage to learn more about our application process and what to expect after you apply.

The State of Colorado strives to create a Colorado for All by building and maintaining workplaces that value and respect all Coloradans through a commitment to equal opportunity and hiring based on merit and fitness.  The State is resolute in non-discriminatory practices in everything we do, including hiring, employment, and advancement opportunities.


The Governor's Office of Information Technology is committed to the full inclusion of all qualified individuals. As part of this commitment, our agency will assist individuals who have a disability with any reasonable accommodation requests related to employment, including completing the application process, interviewing, completing any pre-employment testing, participating in the employee selection process, and/or to perform essential job functions where the requested accommodation does not impose an undue hardship. If you have a disability and require reasonable accommodation to ensure you have a positive experience applying or interviewing for this position, please direct your inquiries to our ADA Coordinator at [email protected] or call (303) 764-7900.


This posting may be used to fill multiple vacancies based upon business need. 

The Governor's Office of Information Technology does NOT offer sponsored Visas for employment purposes.

Skills

TerraformCI/CDServiceNowCybersecuritySOCComplianceProject ManagementChange ManagementSOC 2HIPAACISSP

Similar Jobs

30

Sr. Engineer, Compliance

Renesas Electronics · Bengaluru, KA, India

2 weeks ago

Sr Compliance Engineer

Jj · CH008 Cilag AG, Schaffhausen, Switzerland · Onsite

3 weeks ago

Senior Compliance Engineer

Sonatus · Seoul, South Korea

3 weeks ago

Senior Compliance Engineer

Lumilens · Bengaluru, India · Onsite

2 months ago

Senior Compliance Engineer

Accuray · 1240 Deming, United States of America

3 months ago

Sr. Compliance Engineer

Trueanomalyinc · Denver, CO or Long Beach, CA or Washington, DC +3

4 months ago

Senior Compliance Engineer

Andurilindustries · Costa Mesa, California, United States +1

5 months ago

Senior Compliance Engineer

Interclypse Inc. · San Antonio, TX

1+ year ago

Senior Compliance Engineer

Interclypse Inc. · Annapolis Junction, MD

1+ year ago

Senior AI Business Automation Engineer (Dot Compliance) - Technology IT

Signant Health · Noida, Uttar Pradesh, India +2

3 days ago

Sr Engineer-Compliance, Electrical Engineering

Consolidated Edison · Spring Valley, NY, United States, US

3 days ago

Sr. Materials Comp Engineer, Amazon Robotics Materials Compliance

Amazon

3 days ago

Senior Consultant, Air Quality Compliance Engineer or Scientist - Irvine, California

Erm · Irvine, California, United States of America +3

3 days ago

Senior Protocol Compliance Engineer - Automotive Ethernet

Infineon · Shanghai, Shanghai,CN, CN

4 days ago

Gas Compliance Engineer (Entry, Staff, Senior, or Principal)

Xcelenergy · Lipan Distribution Center, United States of America

4 days ago

Senior Product Validation Engineer (Compliance Engineer for Ethernet Switch)

Jabil · TWN - Sanchong, Taiwan

4 days ago

Sr. HW Regulatory Compliance Engineer

Amazon

1 week ago

Senior Compliance Engineer, AWS Product Compliance Engineering

Amazon

1 week ago

Sr. HW Regulatory Compliance Engineer, Hardware

Amazon

1 week ago

Senior Software Developer Engineer, AWS Compliance & Security Assurance

Amazon · Remote

1 week ago

Senior/Staff Engineer, FE Global Warehouse – Business Process Excellence & Compliance Lead

Micron Technology · Taichung City,TW, TW +1

1 week ago

Senior/Staff Engineer, FE Global Warehouse – Business Process Excellence & Compliance Lead

Micron · Taichung - Fab 16, Taiwan +1

1 week ago

Senior Quality, Compliance, and Regulatory Engineer

Cagents · Boston, Massachusetts · Hybrid

1 week ago

Sr. Maintenance Compliance Engineer

Pfizer · USA - MI - Rochester, United States of America

2 weeks ago

Sr. Maintenance Compliance Engineer

Pfizer · USA - MI - Rochester, United States of America

2 weeks ago

Senior International Trade Compliance Engineer

Andurilindustries · Costa Mesa, California, United States +1

2 weeks ago

Senior International Trade Compliance Engineer

Andurilindustries · Washington, District of Columbia, United States

2 weeks ago

Senior Engineer - Alternative Class Compliance Programs

TC Energy · Houston Office TC Energy Center, United States of America +1

2 weeks ago

Senior Security & Compliance Engineer

XYZ Reality · London Office · Hybrid

2 weeks ago

Senior Backend Engineer, Compliance Engineering

reddit · Remote - United States · Remote

3 weeks ago