Home About Ibex Job Seekers Blog Contact FAQ Build Your Team
← Back to all open roles

GRC DevOps Engineer

Remote Philippines Contract 1099

Location: Remote
Employment Type: Contract

We are hiring a on behalf of a client that supports organizations with security, compliance, and regulatory requirements.

This role combines DevOps, cloud infrastructure, security engineering, and compliance. The successful candidate will build and maintain the technical infrastructure, automation, and monitoring required to implement security controls in production environments and generate reliable compliance evidence through normal system operations.

Most engagements involve FedRAMP, CMMC, NIST SP 800-53, and NIST SP 800-171, with additional security and compliance frameworks depending on the client.

Because this position may support multiple client environments, the ability to quickly understand unfamiliar architectures and adapt to different technologies is essential.

Key Responsibilities

  • Implement and maintain technical security controls in client cloud environments, mapped to NIST SP 800-53 and NIST SP 800-171 control families.
  • Build and maintain Infrastructure as Code (IaC) and CI/CD pipelines that incorporate security and compliance requirements into the deployment process.
  • Apply and maintain security hardening standards such as CIS Benchmarks and DISA STIGs, including tracking and documenting approved deviations.
  • Automate evidence collection and compliance reporting through GRC platforms or client-specific systems.
  • Implement and maintain continuous monitoring capabilities, including:
    • Log aggregation and retention
    • SIEM detections
    • Vulnerability scanning
    • Security alerting
    • FedRAMP Continuous Monitoring activities
    • Monthly vulnerability scans
    • POA&M updates
    • Asset and system inventory
  • Implement and maintain identity and access management controls, including:
    • SSO
    • MFA
    • Privileged access management
    • Least-privilege reviews
    • Joiner, mover, and leaver automation
  • Support security authorization boundary definition and data flow documentation in coordination with GRC/compliance teams.
  • Maintain accurate system diagrams, asset inventories, and configuration documentation as environments evolve.
  • Remediate findings identified through security assessments, vulnerability scans, penetration tests, and compliance reviews.
  • Document remediation and configuration changes in an auditable manner.
  • Develop and maintain technical sections of compliance documentation, including control implementation statements, configuration standards, and operational runbooks.
  • Contribute to reusable security baselines, infrastructure modules, automation, and reference architectures that can be leveraged across future engagements.
  • Collaborate directly with client engineering, security, and compliance teams to implement practical security solutions.

Requirements

  • 3–5 years of experience in DevOps, cloud engineering, platform engineering, security engineering, or a closely related field.
  • Experience working in at least one regulated, security-sensitive, or externally audited environment.
  • Hands-on experience with at least one major cloud platform, including experience with government, restricted, or compliance-focused cloud environments where applicable.
  • Working knowledge of NIST SP 800-53 and/or NIST SP 800-171, with the ability to understand how controls are technically implemented in production environments.
  • Practical experience with Infrastructure as Code and CI/CD, including Terraform, GitHub Actions, or comparable technologies.
  • Strong experience with Linux and/or Windows Server administration.
  • Solid networking fundamentals and experience with modern identity platforms such as Microsoft Entra ID or Okta.
  • Scripting and automation experience using Python, PowerShell, Bash, or similar languages.
  • Ability to communicate effectively with both engineers and auditors.
  • Strong technical writing skills, including the ability to document control implementations, configurations, procedures, and operational processes.

Preferred Qualifications

  • Direct experience supporting FedRAMP or CMMC engagements, including:
    • Continuous Monitoring (ConMon)
    • 3PAO or C3PAO assessment support
    • SSP development
  • Experience with containers and orchestration technologies within compliance-scoped environments.
  • Experience administering or integrating GRC platforms through APIs, such as Vanta, Drata, Hyperproof, or ServiceNow GRC.
  • Experience with security and cloud security platforms such as:
    • Wiz
    • Prisma Cloud
    • Tenable
    • Qualys
    • Microsoft Defender
    • Microsoft Sentinel
    • Splunk
  • Consulting or multi-client delivery experience.
  • Experience working directly with client engineering and security teams.
  • Relevant certifications such as:
    • AWS Certified Security – Specialty
    • Microsoft Azure certifications such as AZ-104
    • Microsoft SC-200
    • CompTIA Security+
    • CISSP
    • CMMC CCP or CCA
  • Familiarity with the Defense Industrial Base (DIB), DFARS 252.204-7012, and CUI handling requirements.
Apply for this role

Build Your Team

Select roles to configure your deployment

Starter Pods (One-Click Setup)

$
Roles above your budget are locked

Request your proposal

Tell us where to send it — we'll follow up with tailored pricing and next steps.

Request received

Want to move faster? Book time with us now and we'll walk through your proposal live.

Prefer to wait? No problem — we'll email your proposal within one business day.

Your Team

Your team is empty.