Skip to Content

GRC DevOps Engineer

Remote

About the Role

YGI Solutions runs two complementary GRC tracks. Our consultants assess a client's control environment and produce the documentation that carries it through audit. This role is the engineering counterpart: you build the infrastructure, automation and monitoring that make those controls real in production, and you make the evidence fall out of the system as a byproduct of running it.

Most of our work is FedRAMP and CMMC, with additional engagements across other frameworks. You will move between client environments, so the ability to come up to speed quickly on an unfamiliar architecture matters as much as depth in any one platform.

Key Responsibilities

  • Implement and maintain technical controls in client cloud environments, mapped to NIST SP 800-53 and NIST SP 800-171 control families
  • Build infrastructure as code and CI/CD pipelines that enforce control requirements at deploy time rather than catching drift after the fact
  • Apply and maintain hardening baselines such as CIS Benchmarks and DISA STIGs, and track approved deviations
  • Automate evidence collection and control reporting into GRC platforms or client-specified systems
  • Stand up and tune continuous monitoring: log aggregation and retention, SIEM detections, vulnerability scanning, alerting, and FedRAMP ConMon deliverables including monthly scans, POA&M feeds and inventory
  • Implement identity and access controls: SSO, MFA, privileged access management, least privilege reviews, and joiner, mover and leaver automation
  • Support authorization boundary definition and data flow documentation with the consulting team, and keep diagrams and asset inventories accurate as environments change
  • Remediate findings from assessments, scans and penetration tests, recording the work as auditable change
  • Write and maintain the technical sections of compliance artifacts: control implementation statements, configuration standards and operational runbooks
  • Contribute to reusable internal baselines, modules and reference architectures so each engagement starts further along than the last

Requirements

  • Three to five years in DevOps, cloud, platform or security engineering, including at least one regulated or externally audited environment
  • Hands-on experience with at least one major cloud platform, including its government regions or an equivalent restricted environment
  • Working knowledge of NIST SP 800-53 and/or NIST SP 800-171 control families, and what satisfying them looks like technically rather than on paper
  • Infrastructure as code and CI/CD in practice, not in theory: Terraform, GitHub Actions or close equivalents
  • Linux and/or Windows Server administration, networking fundamentals, and modern identity systems such as Microsoft Entra ID or Okta
  • Scripting for automation and evidence collection in Python, PowerShell or Bash
  • The ability to write clearly for auditors as well as for engineers. Control implementation statements are part of the role, not an afterthought
  • U.S. person status, required for federal and defense industrial base work

Preferred Qualifications

  • Direct FedRAMP or CMMC delivery experience: ConMon operations, 3PAO or C3PAO assessment support, SSP authoring
  • Container and orchestration work inside a compliance-scoped boundary
  • GRC platform administration and API integration, for example Vanta, Drata, Hyperproof or ServiceNow GRC
  • Depth in security tooling such as Wiz, Prisma Cloud, Tenable, Qualys, Microsoft Defender, Microsoft Sentinel or Splunk
  • Consulting or multi-client delivery experience, and comfort working directly with client engineering teams
  • Certifications such as AWS Certified Security Specialty, AZ-104, SC-200, CompTIA Security+, CISSP, or CMMC CCP or CCA
  • Familiarity with the defense industrial base, DFARS 252.204-7012 and CUI handling requirements
  • An active security clearance, or eligibility to obtain one

What Makes This Role Different

Compliance engineering is usually somebody's second job, bolted onto a platform team that has other priorities. Here it is the work. You will not be asked to screenshot a console at quarter end, because if you are doing this well the evidence generates itself. You will also see across many client architectures rather than one, which compresses years of exposure into months. 

Customer Relationships
Technical Expertise