SECURITY & COMPLIANCE ENGINEER (SCE)
Company: Zermount, Inc.
Location: United States (Remote)
Type: Full-time
Remote: Yes
Posted: 2026-04-20
About this role
ZERMOUNT POSITION DESCRIPTION (PD) SECURITYCOMPLIANCE ENGINEERING (SCE)
POSITION OVERVIEW
Zermount Inc. is seeking System Compliance Engineering (SCE) to support system risk analysis and ensure that federal information systems comply with Information Assurance and cybersecurity standards. The SCE ensures that federal information systems are secure in operation, not merely compliant with documentation. This role directly contributes to mission assurance by identifying, validating, and mitigating real-world cybersecurity risks across enterprise environments.
The SCE operates at the intersection of compliance, engineering, and mission operations, transforming federal mandates (e.g., NIST RMF, FISMA, EO 14028, OMB directives) into measurable, technically enforced security outcomes. Rather than relying solely on static assessments, the role requires continuous evaluation of the system's security posture by directly analyzing configurations, logs, architectures, and control implementations.
This position is designed for individuals with foundational technical expertise across multiple domains, including cloud platforms, network architecture, operating systems, identity systems, and databases. You must be able to independently assess systems, identify exploitable conditions, and validate whether implemented controls effectively reduce risk in real-world scenarios.
The role is a core component of Zermount's Modern GRC mindset, emphasizing:
- Continuous monitoring of system compliance responsibilities
- Real-time risk identification and prioritization
- Direct integration with system teams to drive remediation
- Elimination of "check-the-box" compliance practices
You will be responsible for producing decision-quality outputs that enable system owners, ISSOs, and leadership to make informed, risk-based decisions. This includes identifying control failures, recommending technically sound remediation strategies, and validating that corrective actions are effectiv...