Governor's Office of Information Technology
Colorado

Senior Compliance Engineer (Remote From Anywhere In CO)

Remote$110,000 - $125,000/yrPosted 2 days ago

We tailor your resume to this role and apply for you in seconds.

Apply to Senior Compliance Engineer (Remote From Anywhere In CO) at Governor's Office of Information Technology

Job details

Location
Colorado
Work type
Remote
Compensation
$110,000 - $125,000/yr
Posted
2 days ago
Apply on
governmentjobs.com

About this role

About the Department



Together, we innovate for a stronger Colorado

The work of employees at the Governor's Office of Information Technology (OIT) is challenging and diverse because the needs of agencies, customers and Coloradans constantly evolve. But our focus never changes: improve the lives of all Coloradans through innovation and collaboration. We're building one of the nation's leading government IT organizations by reimagining how we support agencies, building first-of-their-kind applications, and creating an inclusive, collaborative culture, together. Join us in the important work of providing equitable access to services.


Watch this video to learn more about how we're Serving People. Serving Colorado.

Position Duties


TERM LIMITED POSITION: This position is term limited with an anticipated end date of approximately one year from the date of hire. This position is eligible for State employee benefits and may be extended as the situation warrants. This video explains the many benefits of working at the State of Colorado on a term limited basis. 


IMPORTANT NOTE: Please review your application to ensure completion. For the most equitable applicant experience, OIT’s hiring team considers only the contents of your application to review your qualifications. Please do not include any attachments (such as resume or cover letter) with your application as these items are not used by OIT’s hiring team. 

Are you a security-minded strategist ready to protect the heart of Colorado’s digital infrastructure? The Governor's Office of Information Technology is seeking a Senior Compliance Engineer to anchor our Information Security Office. In this high-impact role, you will be the guardian of the state's data assets, leading the development and execution of our compliance program against rigorous standards like the NIST Cybersecurity Framework, HIPAA, CJIS, and IRS Publication 1075. You won’t just write policies—you’ll translate complex technical realities into clear, actionable strategies that empower leadership and stakeholders to make informed, risk-aware decisions. By bridging the gap between technical operations and regulatory requirements, you will ensure our state’s public services remain resilient, secure, and worthy of our citizens' trust.


Essential Functions:

  • Policy & standard development (Govern — GV.PO) - Write, maintain, and version-control security policies, standards, and secure configuration baselines aligned to NIST 800-53 control families, incorporating requirements from IRS Publication 1075 (federal tax information safeguards), HIPAA Security Rule, and the FBI CJIS Security Policy where applicable. Where feasible, codify standards as Policy as Code so requirements are machine-enforceable rather than documentation-only. Outcome: a current, approved policy library that maps directly to control families, satisfies overlapping regulatory obligations without gaps, and is enforceable through automated guardrails.

  • Control mapping & framework alignment (Identify — ID.RA / Govern — GV.OC) - Map internal technical and administrative controls to NIST CSF categories and NIST 800-53 controls, cross-walking to IRS Pub 1075, HIPAA, and CJIS requirements to identify overlaps and unique obligations across regulatory regimes. Outcome: a unified control matrix showing full framework coverage with clear ownership, avoiding duplicate or conflicting control implementations.

  • Compliance monitoring & evidence collection (Detect — DE.CM) - Design and operate continuous monitoring processes to assess control effectiveness and automate evidence collection to support NIST, IRS Safeguards, HIPAA, and CJIS audit requirements, leveraging Policy as Code scans and Infrastructure as Code drift detection to continuously validate control state. Outcome: audit-ready evidence available on demand across all applicable regulatory regimes, with control drift caught automatically rather than at audit time.


  • Technical control implementation guidance (Protect — PR.PS / PR.AA) - Translate NIST, IRS Pub 1075, HIPAA, and CJIS control requirements into technical specifications engineering and IT teams can implement (e.g., FTI data handling and encryption per IRS Pub 1075, PHI access controls per HIPAA, criminal justice data handling and advanced authentication per CJIS). Partner with engineering to embed these requirements directly into Infrastructure as Code templates (e.g., Terraform, CloudFormation modules) so compliant configurations are the default at deployment time. Outcome: controls that satisfy the most stringent applicable requirement, are functionally effective in production, and are consistently applied through reusable, version-controlled infrastructure templates.


  • Procedure & runbook documentation (Govern — GV.PO / Protect — PR.PS) - Author standard operating procedures and control-testing runbooks that support repeatable compliance activities, including regime-specific procedures (e.g., FTI incident reporting per IRS Pub 1075, breach notification per HIPAA, CJIS personnel security screening), and document how Policy as Code rules and Infrastructure as Code modules map back to the controls they satisfy. Outcome: processes that don't rely on institutional knowledge held by one person, and can be handed off, independently audited, or traced from control to enforced code.


  • Regulatory & framework change management (Govern — GV.OC) - Monitor updates to NIST publications, IRS Publication 1075, HIPAA regulations, and the CJIS Security Policy, updating internal policies, standards, and corresponding Policy as Code rules and IaC baseline templates accordingly. Outcome: the policy library and its codified enforcement mechanisms stay current with minimal lag after any framework or regulatory change takes effect.


  • Cross-functional compliance training (Govern — GV.RR) - Develop and deliver training and reference documentation to help engineering, IT, and program staff understand and apply NIST, IRS Pub 1075, HIPAA, and CJIS requirements relevant to their roles, including how to work within Policy as Code guardrails and approved IaC modules rather than around them. Outcome: fewer compliance violations caused by lack of awareness, and higher developer adoption of compliant-by-default infrastructure patterns.


  • Metrics & compliance reporting (Govern — GV.OV) - Define and track compliance KPIs mapped to control maturity across NIST, IRS Safeguards, HIPAA, and CJIS (e.g., % of controls assessed, time-to-remediate findings, policy review currency, audit finding closure rates by regime, % of infrastructure provisioned through compliant IaC templates, Policy as Code rule pass/fail rates). Outcome: leadership has a clear, quantifiable view of compliance posture, trends, and the degree to which compliance is automated versus manually enforced.




Additional Functions: 

Self-Direction & Autonomy

  • Operates independently with minimal supervision; exercises sound judgment in ambiguous or evolving situations

  • Prioritizes and manages a complex workload across competing deadlines without day-to-day direction

  • Recognizes when to escalate versus when to resolve independently


Continuous Improvement Ownership

  • Proactively identifies gaps or inefficiencies in the compliance program and drives improvements without being asked

  • Stays current on evolving threats, regulatory changes, and framework updates (e.g., NIST CSF, CJIS, IRS revisions) and incorporates them into practice

  • Seeks feedback on their own work product and iterates on methodologies, templates, and reporting over time


Mentorship & Influence

  • Mentors others  

  • Influences stakeholders and leadership without formal authority — builds credibility through sound analysis rather than positional power

  • Acts as a subject-matter resource other teams turn to for compliance-related questions


Accountability & Ownership

  • Takes ownership of outcomes, not just tasks — follows through on remediation and reporting until issues are genuinely resolved

  • Documents decisions and rationale clearly enough to withstand audit or leadership scrutiny


Judgment Under Ambiguity

  • Comfortable making recommendations with incomplete information

  • Balances competing priorities (security, budget, mission delivery, public accountability) rather than defaulting to a single lens


Communication & Composure

  • Communicates effectively under pressure, including during incidents or audit findings

  • Adapts communication style for technical staff, program managers, and non-technical executives or elected oversight bodies


Professional Development

  • Maintains and pursues relevant certifications (CISSP, CRISC, CISA, CGRC, GRCP) as a mark of ongoing self-investment

  • Participates in professional communities to bring outside perspective back into the agency



Why Join Us:

Join a supportive, growth-oriented team committed to diversity, equity, and inclusion. Help us protect our infrastructure, safeguard our reputation, and shape the future of our organization.


Minimum Qualifications



A wide salary range is posted for this position and any job offer is based upon a salary analysis to comply with the Colorado Equal Pay for Equal Work Act. The salary analysis considers relevant experience, education, certifications, and state seniority as compared to others doing substantially similar work. While most salary offers are made within the posted range, occasionally an offer is made below or above the posted range based upon this salary analysis.

This is a skills-based job announcement. The required minimum qualifications and/or education (if substituting for the proven experience, knowledge, and skills), are as follows:

To better understand your qualifications and increase your opportunity to move forward in the selection process, please indicate in your work history for each job the outcomes you have achieved that you believe are most relevant to this job.



Minimum Qualifications:


At Least five (5) years of experience in a technology engineering role such as application developer or system administrator. At least three (3) years of experience supporting audit or compliance programs  (e.g., NIST 800-53 CJIS, IRS, HIPAA, SSA, SOC 2, or similar).



Substitutions:


  • Additional appropriate education will substitute for the required experience on a year-for-year basis, but cannot completely substitute for these qualifications. 

  • Training or Certification related to the work assigned to the position will be assigned credit towards substitution for experience and/or education, but cannot completely substitute for these qualifications. 

  • If the minimum qualifications include a degree requirement, additional appropriate paid or unpaid experience will substitute for the required education on a year-for-year basis.



Preferred Qualifications:


  • 1 year of experience implementing automated compliance guardrails using Policy as Code (e.g., OPA/Rego, Sentinel, Checkov, or cloud-native policy services) within CI/CD pipelines or infrastructure provisioning workflows.

  • Professional security certification.

  • Exposure to Governance, Risk and Compliance (GRC) tooling, such as ServiceNow GRC, Archer, or similar platforms.

  • Project management experience.



Conditions of Employment:

OIT employees must comply with any screening procedures in place at state agency locations where they might perform work. 

A pre-employment background check will be conducted as part of the selection process. Post-employment background checks will be required for specific agencies as business needs dictate, which may include a polygraph exam, fingerprint-based criminal history search, reference checks, and a drug test.

This position may require travel within the specified geographic area, and to locations across the state as needed. 

This position may require on-call duties as needed by the position. 


Other Qualifications



If this posting indicates “remote from anywhere in CO” in the title, periodic reporting to the primary state work location designated for the position is required. All remote work must be performed in Colorado. 


While candidates from out of state will be considered for this role, the candidate selected for the position must relocate and reside in Colorado on the first day of their new position.  A reasonable timeframe for relocation will be established on an individual basis, while considering business needs, and determining a start date.

We know it's important to support each other, and that means having a healthy balance of work and personal time. Visit our benefits to learn more about some of our great offerings that allow us all to have fulfilling lives. 


Visit our How to Apply webpage to learn more about our application process and what to expect after you apply.

The State of Colorado strives to create a Colorado for All by building and maintaining workplaces that value and respect all Coloradans through a commitment to equal opportunity and hiring based on merit and fitness.  The State is resolute in non-discriminatory practices in everything we do, including hiring, employment, and advancement opportunities.


The Governor's Office of Information Technology is committed to the full inclusion of all qualified individuals. As part of this commitment, our agency will assist individuals who have a disability with any reasonable accommodation requests related to employment, including completing the application process, interviewing, completing any pre-employment testing, participating in the employee selection process, and/or to perform essential job functions where the requested accommodation does not impose an undue hardship. If you have a disability and require reasonable accommodation to ensure you have a positive experience applying or interviewing for this position, please direct your inquiries to our ADA Coordinator at [email protected] or call (303) 764-7900.


This posting may be used to fill multiple vacancies based upon business need. 

The Governor's Office of Information Technology does NOT offer sponsored Visas for employment purposes.

Benefits

Please note that each agency's contact information is different; therefore, we encourage all applicants to view the full, official job announcement which includes contact information and class title. Select the job you wish to view, then click on the "Print" icon.

Supplemental Questions

01
TERM LIMITED POSITION:
This position is term limited with an anticipated end date of one year from the time of hire. The position may be extended if additional funds permit it. This position is eligible for State employee benefits. Do you wish to proceed with the selection process?
  • Yes
  • No
02
Describe the top 3 outcomes you have achieved that you believe are relevant to this role.
03
The role requires acting as a technical liaison between compliance teams and technical stakeholders. Explain your approach to fostering collaboration and effectively communicating highly technical security concepts to non-technical audiences, particularly in the context of audit control implementation or new technology integrations.
04
Describe your experience translating complex security requirements (e.g., those from IRS Publication 1075, CMS MARS-E, or similar) into actionable technical controls and implementation guidance for technical teams. Provide a specific example of a challenge you faced and how you addressed it.
05
Describe your experience in designing, implementing, and operationalizing security tooling and controls across diverse technical environments (on-premise, cloud, and hybrid). Provide an example of how you've identified opportunities for improvement or integrated new technologies to strengthen an agency's security posture.
06
What experience do you have drafting policies and standard operating procedures about risk management and audits?
07
Please describe how you learned of this job opening.
08
The Governor's Office of Information Technology (OIT) complies with Colorado's Equal Pay for Equal Work Act. While a wide salary range is posted, specific criteria (experience, education, state seniority, etc.) will be used to determine any salary offer. While most salary offers are made within the posted range, occasionally an offer is made below or above the posted range based upon this salary analysis. It is this salary analysis, rather than any negotiation process, that determines any salary offer. Please acknowledge your understanding of this process and the posted salary range for this position.
  • Yes, I understand the above statement.
09
All remote work must be performed from within the State of Colorado. If you live out of state and are selected for this position you must relocate to Colorado before commencing employment. There is no form of relocation assistance, financial or otherwise, available for any position. Do you wish to proceed with your submission?
  • Yes, I understand the above statement.
10
Do you currently reside in the state of Colorado?
  • Yes
  • No
11
If any of the State of Colorado positions listed in your employment history were performed as a contract employee, you MUST list the position/s, State Agency, and the name of the contracting company by whom you were paid during the contract position. If this does not apply, please type "N/A".
12
Do you currently require employer sponsorship for a Visa, employer-provided documentation to maintain your Visa, or employer participation in a program for the purposes of immigration status?
  • Yes
  • No
13
In the future, will you require employer sponsorship for a Visa, employer-provided documentation to maintain your Visa, or employer participation in a program for the purposes of immigration status?
  • Yes
  • No

Required Question

Agency Information

EmployerState of ColoradoAddress See the full announcement by clicking
the "Printer" icon located above the job title
Location varies by announcement, Colorado, -- Website https://careers.colorado.gov/
Ready to apply?
We tailor your resume to this role and apply for you.

About Governor's Office of Information Technology

Governor's Office of Information Technology
Colorado