Senior Compliance Engineer, AI Governance

True Anomaly - Denver Metropolitan Area

Hiring: Senior Compliance Engineer, AI Governance Company: True Anomaly Location: Denver Metropolitan Area Job Posted Time: 2026-09-03 10:29:05 Employment Type: Hybrid Target Skills & Keywords : AWS, Agile, Azure, C, CI/CD, Embedded Systems, LLM, LangChain, MLOps, SaaS, Scrum, Systems Design About the job Experience: •7+ years of experience in IT security compliance, GRC, or a closely related discipline, with direct ownership of compliance program activities. Required Skills: •Lead and support compliance assessment readiness across key organizational frameworks including NIST SP 800-171 Rev. 2 and 3, CMMC Level 3, NIST SP 800-53 Rev. 5, and the NIST Cybersecurity Framework (CSF). •Provide direction on cybersecurity readiness to address EAR and ITAR-related controls and requirements. •Drive CMMC readiness activities across the organization, including scoping, gap analysis, control implementation validation, evidence collection, and pre-assessment preparation. •Review, maintain, and mature System Security Plans (SSPs) to accurately reflect organizational control implementations, system boundaries, and operational practices — including AI/ML system boundaries and data flows. •Manage Plans of Actions and Milestones (POA&Ms), tracking open findings to resolution, communicating status to GRC leadership, and coordinating remediation efforts across responsible teams. •Conduct internal compliance audits and control effectiveness reviews to ensure ongoing adherence to applicable frameworks and to surface emerging gaps before external assessments. •Maintain audit-ready evidence repositories and documentation packages, ensuring traceability between controls, evidence, and framework requirements. •AI Governance, Risk & Compliance (AI-GRC) Qualifications: •Demonstrated expertise in NIST SP 800-171, CMMC (Level 2 or 3), and NIST SP 800-53, with hands-on experience conducting gap assessments, implementing controls, and preparing organizations for external audits. •Extensive, hands-on experience with AI/LLM systems, including practical knowledge of platforms such as OpenAI (GPT-4/o-series), Anthropic Claude, Meta Llama, Microsoft Azure OpenAI Service, and/or comparable commercial and open-source LLM ecosystems. •Demonstrated ability to design, implement, and operationalize compliance controls within LLM pipelines, including guardrail layers, content filtering, audit logging hooks, and data classification enforcement. •Solid functional working knowledge of AI security risks, including prompt injection, jailbreaking, data exfiltration via LLM outputs, model inversion, and supply chain risks associated with third-party AI APIs. •Operational familiarity with NIST AI Risk Management Framework (AI RMF) and its application to enterprise and defense AI deployments. •In-depth knowledge of SSP development and maintenance, POA&M management, and audit evidence lifecycle practices in an organizational (non-product) compliance context. •Proven experience developing and operationalizing information security policies, standards, and procedures across a multi-disciplinary organization. •Strong communication skills with the ability to explain compliance requirements — including AI risk concepts — clearly to both technical practitioners and non-technical business stakeholders. •Highly organized, with demonstrated ability to manage multiple concurrent compliance workstreams and deadlines in a fast-paced environment. •Active or ability to obtain SECRET or TS/SCI security clearance. Compensation: •$140,000 - $195,000 / year •Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!