Sr. GRC Engineer

BLUE ORIGIN•Seattle, WA
•$156,802 - $219,522

About The Position

At Blue Origin, we envision millions of people living and working in space for the benefit of Earth. We’re working to develop reusable, safe, and low-cost space vehicles and systems within a culture of safety, collaboration, and inclusion. Join our team of problem solvers as we add new chapters to the history of spaceflight! This role is part of Enterprise Technology (ET), where we’re developing the digital infrastructure needed to build the road to space, with an emphasis on digital capabilities required to advance Blue Origin’s mission. Enterprise Technology is the center of excellence for digital technology at Blue Origin, providing oversight and governance to align technology and business strategies. The Blue Origin Cybersecurity GRC team is reducing the cost of security compliance through automation and engineering. This is primarily an engineering role: you will design, build, and operate the automation that makes compliance measurable, repeatable, and efficient, applying software and infrastructure engineering practices to the governance, risk, and compliance domains. It is well suited to software, SRE, platform, or DevOps engineers seeking to apply their automation expertise to security operations. Passion for our mission and vision is required!

Requirements

  • 7+ years building and operating production software or infrastructure automation (software, SRE, DevOps, platform, or security engineering).
  • Proficiency in a general-purpose programming language (Python strongly preferred; Go, JavaScript/TypeScript, or similar welcome), with maintainable, tested, version-controlled code.
  • Experience integrating disparate systems via REST APIs and automating data/evidence collection across multiple cloud and SaaS platforms.
  • Hands-on experience with CI/CD pipelines (e.g., GitLab CI) and infrastructure-as-code (Terraform, Bicep, or similar).
  • Experience with configuration management and configuration monitoring - config-as-code and continuous validation of system state against baselines, including drift detection.
  • Ability to translate ambiguous, multi-stakeholder requirements into reliable automation.
  • Aptitude and appetite to learn security compliance frameworks (NIST, ISO, CMMC); extensive prior GRC experience is not required.
  • Bachelor's degree or certification in a technical field, or equivalent experience.

Nice To Haves

  • Familiarity with GRC/compliance frameworks: NIST 800-53/800-171, ISO 27001, ISO 28000, SOC, CMMC, and privacy frameworks.
  • Compliance-as-Code / OSCAL / policy-as-code (OPA/Rego, InSpec) experience.
  • Configuration compliance and desired-state tooling (SCAP, CIS Benchmarks, Ansible, Salt, Chef/Puppet, or PowerShell DSC).
  • Continuous vulnerability monitoring - automating collection and correlation of findings from vulnerability management platforms (enterprise scanning is owned by a partner team).
  • SIEM / observability integration.
  • AI security experience.
  • Aerospace, manufacturing, or OT/safety-critical environment experience.

Responsibilities

  • Automating the collection of compliance artifacts and evidence across multiple cloud, SaaS, and internal platforms by integrating their APIs and normalizing the data.
  • Building and operating CI/CD pipelines and Compliance-as-Code so compliance content is version-controlled, tested, and validated automatically.
  • Automating configuration management and configuration monitoring - continuously validating system and platform configurations against approved baselines, detecting drift, and capturing results as evidence.
  • Supporting continuous monitoring by integrating and correlating security telemetry and findings from partner-team platforms (including vulnerability management and SIEM/observability) into control-status reporting.
  • Building GRC dashboards that integrate observability solutions to enable data-driven decisions.
  • Developing outcome-driven metrics and KPIs to measure control effectiveness.
  • Identifying manually intensive processes and engineering them away.
  • Supporting risk assessments and maintaining policies aligned with security frameworks.

Benefits

  • Medical
  • dental
  • vision
  • basic and supplemental life insurance
  • paid parental leave
  • short and long-term disability
  • 401(k) with a company match of up to 5%
  • Education Support Program
  • Stock Options for all regular employees (working at least 20 hours/week)
  • Paid Time Off: Up to four (4) weeks per year based on weekly scheduled hours
  • up to 14 company-paid holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service