Senior Compliance Engineer (Remote From Anywhere In CO)

State of Colorado
  • CO
  • Remote
  • $110,000–$125,000 Per Year
2 days ago

Job Description

Senior Compliance Engineer (Remote From Anywhere In CO)

Salary

$110,000.00 - $125,000.00 Annually

Location

Statewide, CO

Job Type

Full Time

Job Number

EGB93815

Department

Governors Office of Information Technology

Opening Date

09/04/2026

Closing Date

9/16/2026 11:59 PM Mountain

FLSA

Determined by Position

Primary Physical Work Address

(Remote From Anywhere In CO)

FLSA Status

Exempt; position is not eligible for overtime compensation.

Department Contact Information

oit_hr@state.co.us

Type of Announcement

This announcement is not governed by the selection processes of the classified personnel system. Applications will be considered from residents and non-residents of Colorado.

How To Apply

Please submit an online application for this position at https://www.governmentjobs.com/careers/colorado. Reach out to the Department Contact to apply using a paper application, including any supplemental questions. Failure to submit a complete and timely application may result in the rejection of your application. Applicants are responsible for ensuring that application materials are received by the appropriate Human Resources office before the closing date and time listed.

  • Description
  • Benefits
  • Questions

Department Information

Together, we innovate for a stronger Colorado

The work of employees at the Governors Office of Information Technology (OIT) is challenging and diverse because the needs of agencies, customers and Coloradans constantly evolve. But our focus never changes: improve the lives of all Coloradans through innovation and collaboration. Were building one of the nations leading government IT organizations by reimagining how we support agencies, building first-of-their-kind applications, and creating an inclusive, collaborative culture, together. Join us in the important work of providing equitable access to services.

Watch this video to learn more about how were Serving People. Serving Colorado.

Description of Job

TERM LIMITED POSITION: This position is term limited with an anticipated end date of approximately one year from the date of hire. This position is eligible for State employee benefits and may be extended as the situation warrants. This video explains the many benefits of working at the State of Colorado on a term limited basis.

IMPORTANT NOTE: Please review your application to ensure completion. For the most equitable applicant experience, OIT's hiring team considers only the contents of your application to review your qualifications. Please do not include any attachments (such as resume or cover letter) with your application as these items are not used by OIT's hiring team.

Are you a security-minded strategist ready to protect the heart of Colorado's digital infrastructure? The Governors Office of Information Technology is seeking a Senior Compliance Engineer to anchor our Information Security Office. In this high-impact role, you will be the guardian of the states data assets, leading the development and execution of our compliance program against rigorous standards like the NIST Cybersecurity Framework, HIPAA, CJIS, and IRS Publication 1075. You won't just write policies-you'll translate complex technical realities into clear, actionable strategies that empower leadership and stakeholders to make informed, risk-aware decisions. By bridging the gap between technical operations and regulatory requirements, you will ensure our state's public services remain resilient, secure, and worthy of our citizens trust.

Essential Functions:

  • Policy & standard development (Govern - GV.PO) - Write, maintain, and version-control security policies, standards, and secure configuration baselines aligned to NIST 800-53 control families, incorporating requirements from IRS Publication 1075 (federal tax information safeguards), HIPAA Security Rule, and the FBI CJIS Security Policy where applicable. Where feasible, codify standards as Policy as Code so requirements are machine-enforceable rather than documentation-only. Outcome: a current, approved policy library that maps directly to control families, satisfies overlapping regulatory obligations without gaps, and is enforceable through automated guardrails.

  • Control mapping & framework alignment (Identify - ID.RA / Govern - GV.OC) - Map internal technical and administrative controls to NIST CSF categories and NIST 800-53 controls, cross-walking to IRS Pub 1075, HIPAA, and CJIS requirements to identify overlaps and unique obligations across regulatory regimes. Outcome: a unified control matrix showing full framework coverage with clear ownership, avoiding duplicate or conflicting control implementations.

  • Compliance monitoring & evidence collection (Detect - DE.CM) - Design and operate continuous monitoring processes to assess control effectiveness and automate evidence collection to support NIST, IRS Safeguards, HIPAA, and CJIS audit requirements, leveraging Policy as Code scans and Infrastructure as Code drift detection to continuously validate control state. Outcome: audit-ready evidence available on demand across all applicable regulatory regimes, with control drift caught automatically rather than at audit time.

  • Technical control implementation guidance (Protect - PR.PS / PR.AA) - Translate NIST, IRS Pub 1075, HIPAA, and CJIS control requirements into technical specifications engineering and IT teams can implement (e.g., FTI data handling and encryption per IRS Pub 1075, PHI access controls per HIPAA, criminal justice data handling and advanced authentication per CJIS). Partner with engineering to embed these requirements directly into Infrastructure as Code templates (e.g., Terraform, CloudFormation modules) so compliant configurations are the default at deployment time. Outcome: controls that satisfy the most stringent applicable requirement, are functionally effective in production, and are consistently applied through reusable, version-controlled infrastructure templates.

  • Procedure & runbook documentation (Govern - GV.PO / Protect - PR.PS) - Author standard operating procedures and control-testing runbooks that support repeatable compliance activities, including regime-specific procedures (e.g., FTI incident reporting per IRS Pub 1075, breach notification per HIPAA, CJIS personnel security screening), and document how Policy as Code rules and Infrastructure as Code modules map back to the controls they satisfy. Outcome: processes that dont rely on institutional knowledge held by one person, and can be handed off, independently audited, or traced from control to enforced code.

  • Regulatory & framework change management (Govern - GV.OC) - Monitor updates to NIST publications, IRS Publication 1075, HIPAA regulations, and the CJIS Security Policy, updating internal policies, standards, and corresponding Policy as Code rules and IaC baseline templates accordingly. Outcome: the policy library and its codified enforcement mechanisms stay current with minimal lag after any framework or regulatory change takes effect.

  • Cross-functional compliance training (Govern - GV.RR) - Develop and deliver training and reference documentation to help engineering, IT, and program staff understand and apply NIST, IRS Pub 1075, HIPAA, and CJIS requirements relevant to their roles, including how to work within Policy as Code guardrails and approved IaC modules rather than around them. Outcome: fewer compliance violations caused by lack of awareness, and higher developer adoption of compliant-by-default infrastructure patterns.

  • Metrics & compliance reporting (Govern - GV.OV) - Define and track compliance KPIs mapped to control maturity across NIST, IRS Safeguards, HIPAA, and CJIS (e.g., % of controls assessed, time-to-remediate findings, policy review currency, audit finding closure rates by regime, % of infrastructure provisioned through compliant IaC templates, Policy as Code rule pass/fail rates). Outcome: leadership has a clear, quantifiable view of compliance posture, trends, and the degree to which compliance is automated versus manually enforced.

Additional Functions:

Self-Direction & Autonomy

  • Operates independently with minimal supervision; exercises sound judgment in ambiguous or evolving situations

  • Prioritizes and manages a complex workload across competing deadlines without day-to-day direction

  • Recognizes when to escalate versus when to resolve independently

Continuous Improvement Ownership

  • Proactively identifies gaps or inefficiencies in the compliance program and drives improvements without being asked

  • Stays current on evolving threats, regulatory changes, and framework updates (e.g., NIST CSF, CJIS, IRS revisions) and incorporates them into practice

  • Seeks feedback on their own work product and iterates on methodologies, templates, and reporting over time

Mentorship & Influence

  • Mentors others

  • Influences stakeholders and leadership without formal authority - builds credibility through sound analysis rather than positional power

  • Acts as a subject-matter resource other teams turn to for compliance-related questions

Accountability & Ownership

  • Takes ownership of outcomes, not just tasks - follows through on remediation and reporting until issues are genuinely resolved

  • Documents decisions and rationale clearly enough to withstand audit or leadership scrutiny

Judgment Under Ambiguity

  • Comfortable making recommendations with incomplete information

  • Balances competing priorities (security, budget, mission delivery, public accountability) rather than defaulting to a single lens

Communication & Composure

  • Communicates effectively under pressure, including during incidents or audit findings

  • Adapts communication style for technical staff, program managers, and non-technical executives or elected oversight bodies

Professional Development

  • Maintains and pursues relevant certifications (CISSP, CRISC, CISA, CGRC, GRCP) as a mark of ongoing self-investment

  • Participates in professional communities to bring outside perspective back into the agency

Why Join Us:

Join a supportive, growth-oriented team committed to diversity, equity, and inclusion. Help us protect our infrastructure, safeguard our reputation, and shape the future of our organization.

Minimum Qualifications, Substitutions, Conditions of Employment & Appeal Rights

A wide salary range is posted for this position and any job offer is based upon a salary analysis to comply with the Colorado Equal Pay for Equal Work Act. The salary analysis considers relevant experience, education, certifications, and state seniority as compared to others doing substantially similar work. While most salary offers are made within the posted range, occasionally an offer is made below or above the posted range based upon this salary analysis.

This is a skills-based job announcement. The required minimum qualifications and/or education (if substituting for the proven experience, knowledge, and skills), are as follows:

To better understand your qualifications and increase your opportunity to move forward in the selection process, please indicate in your work history for each job the outcomes you have achieved that you believe are most relevant to this job.

Minimum Qualifications:

At Least five (5) years of experience in a technology engineering role such as application developer or system administrator. At least three (3) years of experience supporting audit or compliance programs (e.g., NIST 800-53 CJIS, IRS, HIPAA, SSA, SOC 2, or similar).

Substitutions:

  • Additional appropriate education will substitute for the required experience on a year-for-year basis, but cannot completely substitute for these qualifications.

  • Training or Certification related to the work assigned to the position will be assigned credit towards substitution for experience and/or education, but cannot completely substitute for these qualifications.

  • If the minimum qualifications include a degree requirement, additional appropriate paid or unpaid experience will substitute for the required education on a year-for-year basis.

Preferred Qualifications:

  • 1 year of experience implementing automated compliance guardrails using Policy as Code (e.g., OPA/Rego, Sentinel, Checkov, or cloud-native policy services) within CI/CD pipelines or infrastructure provisioning workflows.

  • Professional security certification.

  • Exposure to Governance, Risk and Compliance (GRC) tooling, such as ServiceNow GRC, Archer, or similar platforms.

  • Project management experience.

Conditions of Employment:

OIT employees must comply with any screening procedures in place at state agency locations where they might perform work.

A pre-employment background check will be conducted as part of the selection process. Post-employment background checks will be required for specific agencies as business needs dictate, which may include a polygraph exam, fingerprint-based criminal history search, reference checks, and a drug test.

This position may require travel within the specified geographic area, and to locations across the state as needed.

This position may require on-call duties as needed by the position.

Supplemental Information

If this posting indicates "remote from anywhere in CO" in the title, periodic reporting to the primary state work location designated for the position is required. All remote work must be performed in Colorado.

While candidates from out of state will be considered for this role, the candidate selected for the position must relocate and reside in Colorado on the first day of their new position. A reasonable timeframe for relocation will be established on an individual basis, while considering business needs, and determining a start date.

We know its important to support each other, and that means having a healthy balance of work and personal time. Visit our benefits to learn more about some of our great offerings that allow us all to have fulfilling lives.

Visit our How to Apply webpage to learn more about our application process and what to expect after you apply.

The State of Colorado strives to create a Colorado for All by building and maintaining workplaces that value and respect all Coloradans through a commitment to equal opportunity and hiring based on merit and fitness. The State is resolute in non-discriminatory practices in everything we do, including hiring, employment, and advancement opportunities.

The Governors Office of Information Technology is committed to the full inclusion of all qualified individuals. As part of this commitment, our agency will assist individuals who have a disability with any reasonable accommodation requests related to employment, including completing the application process, interviewing, completing any pre-employment testing, participating in the employee selection process, and/or to perform essential job functions where the requested accommodation does not impose an undue hardship. If you have a disability and require reasonable accommodation to ensure you have a positive experience applying or interviewing for this position, please direct your inquiries to our ADA Coordinator at OIT_HR@state.co.us or call (303) 764-7900.

This posting may be used to fill multiple vacancies based upon business need.

The Governors Office of Information Technology does NOT offer sponsored Visas for employment purposes.

Please note that each agencys contact information is different; therefore, we encourage all applicants to view the full, official job announcement which includes contact information and class title. Select the job you wish to view, then click on the "Print" icon.

01

TERM LIMITED POSITION:

This position is term limited with an anticipated end date of one year from the time of hire. The position may be extended if additional funds permit it. This position is eligible for State employee benefits. Do you wish to proceed with the selection process?

  • Yes
  • No

02

Describe the top 3 outcomes you have achieved that you believe are relevant to this role.

03

The role requires acting as a technical liaison between compliance teams and technical stakeholders. Explain your approach to fostering collaboration and effectively communicating highly technical security concepts to non-technical audiences, particularly in the context of audit control implementation or new technology integrations.

04

Describe your experience translating complex security requirements (e.g., those from IRS Publication 1075, CMS MARS-E, or similar) into actionable technical controls and implementation guidance for technical teams. Provide a specific example of a challenge you faced and how you addressed it.

05

Describe your experience in designing, implementing, and operationalizing security tooling and controls across diverse technical environments (on-premise, cloud, and hybrid). Provide an example of how youve identified opportunities for improvement or integrated new technologies to strengthen an agencys security posture.

06

What experience do you have drafting policies and standard operating procedures about risk management and audits?

07

Please describe how you learned of this job opening.

08

The Governors Office of Information Technology (OIT) complies with Colorados Equal Pay for Equal Work Act. While a wide salary range is posted, specific criteria (experience, education, state seniority, etc.) will be used to determine any salary offer. While most salary offers are made within the posted range, occasionally an offer is made below or above the posted range based upon this salary analysis. It is this salary analysis, rather than any negotiation process, that determines any salary offer. Please acknowledge your understanding of this process and the posted salary range for this position.

  • Yes, I understand the above statement.

09

All remote work must be performed from within the State of Colorado. If you live out of state and are selected for this position you must relocate to Colorado before commencing employment. There is no form of relocation assistance, financial or otherwise, available for any position. Do you wish to proceed with your submission?

  • Yes, I understand the above statement.

10

Do you currently reside in the state of Colorado?

  • Yes
  • No

11

If any of the State of Colorado positions listed in your employment history were performed as a contract employee, you MUST list the position/s, State Agency, and the name of the contracting company by whom you were paid during the contract position. If this does not apply, please type "N/A".

12

Do you currently require employer sponsorship for a Visa, employer-provided documentation to maintain your Visa, or employer participation in a program for the purposes of immigration status?

  • Yes
  • No

13

In the future, will you require employer sponsorship for a Visa, employer-provided documentation to maintain your Visa, or employer participation in a program for the purposes of immigration status?

  • Yes
  • No

Required Question

Employer State of Colorado

Address See the full announcement by clicking

the "Printer" icon located above the job title

Location varies by announcement, Colorado, --

Website https://careers.colorado.gov/

Numbers & Facts

LocationCO (
Remote
)
Salary$110,000–$125,000 Per Year

Skills

  • Access Controlunmatched
  • Authenticationunmatched
  • Background Investigationunmatched
  • Budgetingunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Change Managementunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • Content Management Systems (CMS)unmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Improvementunmatched
  • Continuous Integrationunmatched
  • Criminal Justiceunmatched
  • Cross-Functionalunmatched
  • Cryptographyunmatched
  • Diversityunmatched
  • Diversity Recruitingunmatched
  • Documentationunmatched
  • Employee Benefitsunmatched
  • Establish Prioritiesunmatched
  • Fitnessunmatched
  • Government Organizationsunmatched
  • HIPAA (Health Insurance Portability and Accountability Act)unmatched
  • Hybrid Cloudunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internet Securityunmatched
  • Leadershipunmatched
  • Machine Toolunmatched
  • Maintain Complianceunmatched
  • Mentoringunmatched
  • Metricsunmatched
  • Performance Metricsunmatched
  • Policy Developmentunmatched
  • Problem Solving Skillsunmatched
  • Process Improvementunmatched
  • Project/Program Managementunmatched
  • Public/Media/Press/Analyst Relationsunmatched
  • Publicationsunmatched
  • Reference Verificationunmatched
  • Regulationsunmatched
  • Regulatory Requirementsunmatched
  • Riskunmatched
  • Security Policyunmatched
  • ServiceNowunmatched
  • Software Developmentunmatched
  • Systems Administration/Managementunmatched
  • Team Playerunmatched
  • Technical Leadershipunmatched
  • Technical Operationsunmatched
  • Time Managementunmatched
  • Training/Teachingunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Willing to Travelunmatched
  • Work From Homeunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder