Ionq
Ionq7h ago
New

Senior Governance, Risk, and Compliance Engineer

United StatesUnited StatesRemotesenior
OtherCompliance Engineer
0 views0 saves0 applied

Quick Summary

Key Responsibilities

Architect and own end-to-end CMMC implementation and audit readiness, including scoping strategy, control mapping, SSP and POA&M development, evidence collection,

Technical Tools
OtherCompliance Engineer

IonQ, Inc. [NYSE: IONQ] is the world’s leading quantum platform and merchant supplier - delivering integrated quantum solutions across computing, networking, sensing, and security. IonQ’s newest generation of quantum computers, the IonQ Tempo, is the latest in a line of cutting-edge systems that have been helping customers and partners including Amazon Web Services, and AstraZeneca achieve 20x performance results and accelerate innovation in drug discovery, materials science, financial modeling, logistics, cybersecurity, and defense. In 2025, the company achieved 99.99% two-qubit gate fidelity, setting a world record in quantum computing performance.

Headquartered in College Park, Maryland, IonQ has operations in California, Colorado, Massachusetts, Tennessee, Washington, Italy, South Korea, Sweden, Switzerland, Canada, and the United Kingdom. Our quantum computing services are available through all major cloud providers, while we also meet the needs of networking and sensing customers across land, sea, air, and space. IonQ is making quantum platforms more accessible and impactful than ever before.  

We are looking for a Senior Governance, Risk, and Compliance (GRC) Engineer to join our Security team. As a Senior GRC Engineer, you’ll be part of a cross-functional team whose mission is to lead IonQ on its journey to build the world’s best quantum computers to solve the world’s most complex problems.

Quantum computing and national security are inseparable. IonQ operates at the intersection of cutting-edge research and the defense industrial base, making rigorous cybersecurity compliance a core business imperative. In this role, you will own and drive IonQ’s Cybersecurity Maturity Model Certification (CMMC) posture across the organization, from architecting compliant environments and leading C3PAO assessments to developing compliance strategy and advising internal teams at every level. The ideal candidate is a self-directed senior practitioner who can architect solutions, lead programs, and serve as the go-to internal expert across engineering, legal, and operations.

In your first 90 days you will conduct a comprehensive gap assessment of our current CMMC posture, map CUI data flows across all environments, and develop a prioritized roadmap for building or maturing our SSP and associated artifacts.

Responsibilities

~2 min read
  • Architect and own end-to-end CMMC implementation and audit readiness, including scoping strategy, control mapping, SSP and POA&M development, evidence collection, and remediation tracking across the organization.
  • Interpret and apply DFARS clause requirements, including DFARS 252.204-7012, 252.204-7019, and 252.204-7020, translating contractual obligations into operational controls and owning accurate SPRS submissions.
  • Lead recurring internal audits of NIST 800-171 security controls and drive end-to-end preparation for C3PAO assessments, including evidence packages, assessment logistics, and assessor coordination.
  • Architect CUI environments to meet CMMC boundary requirements, including network segmentation, access control, media protection, and FIPS-validated encryption; lead evaluation of cloud environments against CMMC scoping guidance.
  • Drive implementation of technical controls across NIST 800-171 practice families, including MFA, audit logging, configuration management, incident response, and vulnerability management, engaging directly with engineering teams.
  • Serve as the primary CMMC subject matter expert at IonQ, developing compliance roadmaps, facilitating readiness workshops, and providing authoritative guidance on DFARS flow-down requirements for subcontractors.
  • Partner with legal and contracts teams to review FAR/DFARS clauses in new and existing contracts, flagging CUI obligations and CMMC level requirements, and lead coordination with regulatory teams on ITAR and EAR obligations as they intersect with CUI handling.
  • Develop and operate a formal risk management program covering IT systems and infrastructure, maintain a risk register, and provide regular executive-level reporting on posture, open risks, and remediation progress.
  • Own and mature the organization’s GRC platform to support evidence management, POA&M tracking, and risk register maintenance, and build compliance dashboards for leadership visibility.

Requirements

~2 min read
  • 5–8 years of professional experience in cybersecurity compliance, GRC, or security engineering, with demonstrated hands-on ownership of NIST SP 800-171 and CMMC compliance programs.
  • Proven track record developing SSPs, POA&Ms, and C3PAO assessment artifacts, and independently scoping CUI environments across realistic system boundaries.
  • Deep working knowledge of DFARS cybersecurity clauses (7012, 7019, 7020), CMMC 2.0 framework structure across all three levels, and the difference in assessment methodology between self-assessment and C3PAO.
  • A technical background in systems administration, cloud security, or security engineering sufficient to credibly lead control implementation discussions with IT and engineering teams, including network architecture, IAM, key management, logging, and endpoint management.
  • Experience leading cross-functional compliance initiatives and translating technical requirements for non-technical stakeholders including legal, finance, and executive leadership.
  • Bachelor’s degree in Computer Science, Information Security, or equivalent practical experience.
  • Familiarity with ITAR and EAR and how export control obligations intersect with CUI handling in a defense-adjacent research environment.
  • Hands-on experience with GRC platforms (e.g., Hyperproof, Drata, Anecdotes AI) and security tooling such as CSPM or vulnerability scanners.
  • Prior experience in a defense contractor, national laboratory, government, or high-security research environment.
  • CMMC certifications (CCP, CCA, or LCPA) are a strong plus, as are CISSP, CISM, CISA, or CRISC.

If you are interested in being a part of our team and mission, we encourage you to apply! 


 

Location & Eligibility

Where is the job
United States
Remote within one country
Who can apply
US

Listing Details

Posted
May 22, 2026
First seen
May 22, 2026
Last seen
May 23, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
76%
Scored at
May 22, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Ionq
Ionq
greenhouse
Employees
350
Founded
2015
Domain
ionq.com
View company profile
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

IonqSenior Governance, Risk, and Compliance Engineer