{"schemaVersion":"jobsearcher.job.v1","id":"efcdf831629e2e57046f483a","url":"https://jobsearcher.com/jobs/efcdf831629e2e57046f483a","canonicalUrl":"https://jobsearcher.com/jobs/efcdf831629e2e57046f483a","title":"Senior Full-Stack Security/GRC Platform Engineer","description":"Job Family:\nCyber Engineering (CYS)\n\nTravel Required:\nUp to 10%\n\nClearance Required:\nNone\nWhat You Will Do:\nWe are hiring a senior engineer to maintain and extend a large full-stack Governance, Risk, and Compliance platform. The product is not a simple scanner wrapper. The current codebase includes a substantial FastAPI backend, a React/TypeScript frontend, a PostgreSQL data model, an async worker system, scanner integrations, an AI provider abstraction, a compliance framework catalog, audit/reporting workflows, and local/cloud deployment infrastructure.\nThe ideal candidate can work confidently across backend services, frontend workflows, database migrations, security controls, AI-assisted analysis, scanner ingestion, and production operations.\nMaintain and extend a FastAPI backend with hundreds of registered API routes.\nBuild and refine React/TypeScript product workflows across a large frontend surface.\nDesign and maintain SQLAlchemy models, Alembic migrations, PostgreSQL queries, and data integrity rules.\nSupport scanner integrations, finding normalization, deduplication, evidence workflows, and compliance mapping.\nMaintain AI-assisted features through a centralized provider abstraction rather than direct calls to providers.\nWork across GRC workflows including findings, evidence, SSPs, POA&Ms, RMF, FedRAMP/FISMA, SCRM, ZTA, ISCM, risk acceptance, and reporting.\nKeep local development and test environments healthy using Docker Compose, Redis, PostgreSQL, worker queues, Ollama, observability services, and frontend tooling.\nMaintain quality gates including linting, type checking, OpenAPI drift checks, migration safety, SDK drift, architecture boundaries, and test suites.\nDebug issues across frontend state, API contracts, database state, workers, scanner output, generated SDKs, and deployment configuration.\nTreat documentation as helpful but secondary to the codebase; validate assumptions against source, tests, migrations, and running behavior.\nWhat You Will Need:\nMinimum of SIX (6) years’ experience with Python backend development.\nStrong FastAPI, Pydantic, SQLAlchemy, Alembic, async Python, and pytest experience.\nStrong React, TypeScript, Vite, React Router, React Query, and component architecture experience.\nPostgreSQL experience, including schema design, migrations, indexes, JSON/JSONB, and relational integrity.\nExperience maintaining large API surfaces and generated frontend API clients.\nExperience with background jobs or async workers using Redis-backed queues.\nStrong security engineering fundamentals: authentication, authorization, RBAC, audit logs, secret handling, dependency risk, and input validation.\nAbility to diagnose source-of-truth issues when documentation, generated code, database schema, and runtime behavior disagree.\nSecurity/GRC Domain Skills To Include\nVulnerability findings and remediation workflows.\nEvidence collection and evidence sufficiency.\nSSPs, POA&Ms, control mappings, audit packages, and risk acceptance.\nNIST 800-53, RMF, FedRAMP/FISMA, CMMC, SCRM, ZTA, ISCM, and related compliance concepts.\nScanner output from tools such as cloud security scanners, vulnerability scanners, SAST/IaC tools, secret scanners, identity/M365 scanners, and web security scanners.\nProvenance, auditability, and defensibility requirements for regulated workflows.\nAI/LLM Product Skills To Include\nExperience building AI-assisted product features, preferably in security, compliance, document review, or workflow automation.\nUnderstanding of RAG, embeddings, document extraction, prompt/context design, and evidence citation.\nAbility to enforce scoped context, provenance, guardrails, and human-review boundaries.\nComfort maintaining provider abstractions across local and cloud AI providers.\nInfrastructure And Operations Skills To Include\nDocker Compose for local development.\nAWS-style production operations: containers, managed databases, caches, object storage, CDN, IAM, logs, and deployment pipelines.\nTerraform or similar infrastructure-as-code experience.\nCI/CD debugging and release discipline.\nObservability, logs, health checks, and operational runbooks.\n\nWhat Would Be Nice To Have:\nPrior experience with GRC, audit automation, security consulting tools, vulnerability management, FedRAMP/FISMA, or SSP/POA&M workflows.\nExperience with generated OpenAPI SDKs.\nExperience producing PDF, Excel, DOCX, PowerPoint, or audit package exports.\nExperience with immutable audit logs, provenance chains, multi-tenant permissions, or evidence workflows.\nThe annual salary range for this position is $86,500.00-$129,900.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.\n\nWhat We Offer:\nGuidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.\nBenefits include:\nMedical, Rx, Dental & Vision Insurance\nPersonal and Family Sick Time & Company Paid Holidays\nParental Leave\n401(k) Retirement Plan\nGroup Term Life and Travel Assistance\nVoluntary Life and AD&D Insurance\nHealth Savings Account, Health Care & Dependent Care Flexible Spending Accounts\nTransit and Parking Commuter Benefits\nShort-Term & Long-Term Disability\nTuition Reimbursement, Personal Development, Certifications & Learning Opportunities\nEmployee Referral Program\nCorporate Sponsored Events & Community Outreach\nCare.com annual membership\nEmployee Assistance Program\nSupplemental Benefits via Corestream (Critical Care, Hospital Indemnity, Accident Insurance, Legal Assistance and ID theft protection, etc.)\nPosition may be eligible for a discretionary variable incentive bonus\nAbout Guidehouse\nGuidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.\nGuidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.\nIf you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.\nAll communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.\nIf any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.\nGuidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.","company":"Guidehouse","rawCompany":"guidehouse","city":"Washington","state":"DC","isRemote":false,"isActive":false,"createdAt":"2026-08-04T18:07:07.256Z","occupations":[{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Senior Full-Stack Security/GRC Platform Engineer","description":"Job Family:\nCyber Engineering (CYS)\n\nTravel Required:\nUp to 10%\n\nClearance Required:\nNone\nWhat You Will Do:\nWe are hiring a senior engineer to maintain and extend a large full-stack Governance, Risk, and Compliance platform. The product is not a simple scanner wrapper. The current codebase includes a substantial FastAPI backend, a React/TypeScript frontend, a PostgreSQL data model, an async worker system, scanner integrations, an AI provider abstraction, a compliance framework catalog, audit/reporting workflows, and local/cloud deployment infrastructure.\nThe ideal candidate can work confidently across backend services, frontend workflows, database migrations, security controls, AI-assisted analysis, scanner ingestion, and production operations.\nMaintain and extend a FastAPI backend with hundreds of registered API routes.\nBuild and refine React/TypeScript product workflows across a large frontend surface.\nDesign and maintain SQLAlchemy models, Alembic migrations, PostgreSQL queries, and data integrity rules.\nSupport scanner integrations, finding normalization, deduplication, evidence workflows, and compliance mapping.\nMaintain AI-assisted features through a centralized provider abstraction rather than direct calls to providers.\nWork across GRC workflows including findings, evidence, SSPs, POA&Ms, RMF, FedRAMP/FISMA, SCRM, ZTA, ISCM, risk acceptance, and reporting.\nKeep local development and test environments healthy using Docker Compose, Redis, PostgreSQL, worker queues, Ollama, observability services, and frontend tooling.\nMaintain quality gates including linting, type checking, OpenAPI drift checks, migration safety, SDK drift, architecture boundaries, and test suites.\nDebug issues across frontend state, API contracts, database state, workers, scanner output, generated SDKs, and deployment configuration.\nTreat documentation as helpful but secondary to the codebase; validate assumptions against source, tests, migrations, and running behavior.\nWhat You Will Need:\nMinimum of SIX (6) years’ experience with Python backend development.\nStrong FastAPI, Pydantic, SQLAlchemy, Alembic, async Python, and pytest experience.\nStrong React, TypeScript, Vite, React Router, React Query, and component architecture experience.\nPostgreSQL experience, including schema design, migrations, indexes, JSON/JSONB, and relational integrity.\nExperience maintaining large API surfaces and generated frontend API clients.\nExperience with background jobs or async workers using Redis-backed queues.\nStrong security engineering fundamentals: authentication, authorization, RBAC, audit logs, secret handling, dependency risk, and input validation.\nAbility to diagnose source-of-truth issues when documentation, generated code, database schema, and runtime behavior disagree.\nSecurity/GRC Domain Skills To Include\nVulnerability findings and remediation workflows.\nEvidence collection and evidence sufficiency.\nSSPs, POA&Ms, control mappings, audit packages, and risk acceptance.\nNIST 800-53, RMF, FedRAMP/FISMA, CMMC, SCRM, ZTA, ISCM, and related compliance concepts.\nScanner output from tools such as cloud security scanners, vulnerability scanners, SAST/IaC tools, secret scanners, identity/M365 scanners, and web security scanners.\nProvenance, auditability, and defensibility requirements for regulated workflows.\nAI/LLM Product Skills To Include\nExperience building AI-assisted product features, preferably in security, compliance, document review, or workflow automation.\nUnderstanding of RAG, embeddings, document extraction, prompt/context design, and evidence citation.\nAbility to enforce scoped context, provenance, guardrails, and human-review boundaries.\nComfort maintaining provider abstractions across local and cloud AI providers.\nInfrastructure And Operations Skills To Include\nDocker Compose for local development.\nAWS-style production operations: containers, managed databases, caches, object storage, CDN, IAM, logs, and deployment pipelines.\nTerraform or similar infrastructure-as-code experience.\nCI/CD debugging and release discipline.\nObservability, logs, health checks, and operational runbooks.\n\nWhat Would Be Nice To Have:\nPrior experience with GRC, audit automation, security consulting tools, vulnerability management, FedRAMP/FISMA, or SSP/POA&M workflows.\nExperience with generated OpenAPI SDKs.\nExperience producing PDF, Excel, DOCX, PowerPoint, or audit package exports.\nExperience with immutable audit logs, provenance chains, multi-tenant permissions, or evidence workflows.\nThe annual salary range for this position is $86,500.00-$129,900.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.\n\nWhat We Offer:\nGuidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.\nBenefits include:\nMedical, Rx, Dental & Vision Insurance\nPersonal and Family Sick Time & Company Paid Holidays\nParental Leave\n401(k) Retirement Plan\nGroup Term Life and Travel Assistance\nVoluntary Life and AD&D Insurance\nHealth Savings Account, Health Care & Dependent Care Flexible Spending Accounts\nTransit and Parking Commuter Benefits\nShort-Term & Long-Term Disability\nTuition Reimbursement, Personal Development, Certifications & Learning Opportunities\nEmployee Referral Program\nCorporate Sponsored Events & Community Outreach\nCare.com annual membership\nEmployee Assistance Program\nSupplemental Benefits via Corestream (Critical Care, Hospital Indemnity, Accident Insurance, Legal Assistance and ID theft protection, etc.)\nPosition may be eligible for a discretionary variable incentive bonus\nAbout Guidehouse\nGuidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.\nGuidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.\nIf you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.\nAll communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.\nIf any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.\nGuidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.","datePosted":"2026-08-04T18:07:07.256Z","dateModified":"2026-08-04T18:07:07.256Z","hiringOrganization":{"@type":"Organization","name":"Guidehouse","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"efcdf831629e2e57046f483a"},"url":"https://jobsearcher.com/jobs/efcdf831629e2e57046f483a"}}