IonQ Logo

IonQ

Senior Governance, Risk, and Compliance Engineer

Posted 22 Days Ago
Remote or Hybrid
Hiring Remotely in US
110K-144K Annually
Senior level
Remote or Hybrid
Hiring Remotely in US
110K-144K Annually
Senior level
The Senior GRC Engineer will lead cybersecurity compliance, drive CMMC posture, conduct audits, and develop compliance strategies within IonQ's security team.
The summary above was generated by AI

About IonQ: 

IonQ, Inc. [NYSE: IONQ] is the world’s leading quantum platform and merchant supplier - delivering integrated quantum solutions across computing, networking, sensing, and security. IonQ’s newest generation of quantum computers, the IonQ Tempo, is the latest in a line of cutting-edge systems that have been helping customers and partners including Amazon Web Services, and AstraZeneca achieve 20x performance results and accelerate innovation in drug discovery, materials science, financial modeling, logistics, cybersecurity, and defense. In 2025, the company achieved 99.99% two-qubit gate fidelity, setting a world record in quantum computing performance.
Headquartered in College Park, Maryland, IonQ has operations in California, Colorado, Massachusetts, Tennessee, Washington, Italy, South Korea, Sweden, Switzerland, Canada, and the United Kingdom. Our quantum computing services are available through all major cloud providers, while we also meet the needs of networking and sensing customers across land, sea, air, and space. IonQ is making quantum platforms more accessible and impactful than ever before.  

Location: This position can work onsite or hybrid from one of our offices or fully remote in the US.
Travel: Up to 10%
Job ID:
1614

The Role: 

We are looking for a Senior Governance, Risk, and Compliance (GRC) Engineer to join our Security team. As a Senior GRC Engineer, you’ll be part of a cross-functional team whose mission is to lead IonQ on its journey to build the world’s best quantum computers to solve the world’s most complex problems.

Quantum computing and national security are inseparable. IonQ operates at the intersection of cutting-edge research and the defense industrial base, making rigorous cybersecurity compliance a core business imperative. In this role, you will own and drive IonQ’s Cybersecurity Maturity Model Certification (CMMC) posture across the organization, from architecting compliant environments and leading C3PAO assessments to developing compliance strategy and advising internal teams at every level. The ideal candidate is a self-directed senior practitioner who can architect solutions, lead programs, and serve as the go-to internal expert across engineering, legal, and operations.

In your first 90 days you will conduct a comprehensive gap assessment of our current CMMC posture, map CUI data flows across all environments, and develop a prioritized roadmap for building or maturing our SSP and associated artifacts.

Responsibilities:

  • Architect and own end-to-end CMMC implementation and audit readiness, including scoping strategy, control mapping, SSP and POA&M development, evidence collection, and remediation tracking across the organization.
  • Interpret and apply DFARS clause requirements, including DFARS 252.204-7012, 252.204-7019, and 252.204-7020, translating contractual obligations into operational controls and owning accurate SPRS submissions.
  • Lead recurring internal audits of NIST 800-171 security controls and drive end-to-end preparation for C3PAO assessments, including evidence packages, assessment logistics, and assessor coordination.
  • Architect CUI environments to meet CMMC boundary requirements, including network segmentation, access control, media protection, and FIPS-validated encryption; lead evaluation of cloud environments against CMMC scoping guidance.
  • Drive implementation of technical controls across NIST 800-171 practice families, including MFA, audit logging, configuration management, incident response, and vulnerability management, engaging directly with engineering teams.
  • Serve as the primary CMMC subject matter expert at IonQ, developing compliance roadmaps, facilitating readiness workshops, and providing authoritative guidance on DFARS flow-down requirements for subcontractors.
  • Partner with legal and contracts teams to review FAR/DFARS clauses in new and existing contracts, flagging CUI obligations and CMMC level requirements, and lead coordination with regulatory teams on ITAR and EAR obligations as they intersect with CUI handling.
  • Develop and operate a formal risk management program covering IT systems and infrastructure, maintain a risk register, and provide regular executive-level reporting on posture, open risks, and remediation progress.
  • Own and mature the organization’s GRC platform to support evidence management, POA&M tracking, and risk register maintenance, and build compliance dashboards for leadership visibility.

Requirements:

  • 5–8 years of professional experience in cybersecurity compliance, GRC, or security engineering, with demonstrated hands-on ownership of NIST SP 800-171 and CMMC compliance programs.
  • Proven track record developing SSPs, POA&Ms, and C3PAO assessment artifacts, and independently scoping CUI environments across realistic system boundaries.
  • Deep working knowledge of DFARS cybersecurity clauses (7012, 7019, 7020), CMMC 2.0 framework structure across all three levels, and the difference in assessment methodology between self-assessment and C3PAO.
  • A technical background in systems administration, cloud security, or security engineering sufficient to credibly lead control implementation discussions with IT and engineering teams, including network architecture, IAM, key management, logging, and endpoint management.
  • Experience leading cross-functional compliance initiatives and translating technical requirements for non-technical stakeholders including legal, finance, and executive leadership.
  • Bachelor’s degree in Computer Science, Information Security, or equivalent practical experience.

Preferred Qualifications: 

  • Familiarity with ITAR and EAR and how export control obligations intersect with CUI handling in a defense-adjacent research environment.
  • Hands-on experience with GRC platforms (e.g., Hyperproof, Drata, Anecdotes AI) and security tooling such as CSPM or vulnerability scanners.
  • Prior experience in a defense contractor, national laboratory, government, or high-security research environment.
  • CMMC certifications (CCP, CCA, or LCPA) are a strong plus, as are CISSP, CISM, CISA, or CRISC.

The approximate base salary range for this position is $110,336 - $144,459. The total compensation package includes base, bonus, equity, and a range of benefit options found on our career site.

Compensation will vary based on individual factors such as education, qualifications, and experience of the final candidate(s), specific office location, and calibration against relevant market data and internal team equity.  Posted base salary figures are subject to change as new market data becomes available. Our benefits include comprehensive medical, dental, and vision plans, matching 401K, unlimited PTO and paid holidays, parental/adoption leave, legal insurance, and a home technology stipend.  Details of participation in these benefit plans will be provided when a candidate receives an offer of employment. 

At IonQ, we believe in fair treatment, access, opportunity, and advancement for all while striving to identify and eliminate barriers. We empower employees to thrive by fostering a culture of autonomy, productivity, and respect. We are dedicated to creating an environment where individuals can feel welcomed, respected, supported, and valued.
 
We are committed to equity and justice. We welcome different voices and viewpoints and do not discriminate on the basis of race, religion, ancestry, physical and/or mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, transgender status, age, sexual orientation, military or veteran status, or any other basis protected by law. We are proud to be an Equal Employment Opportunity employer.

US Technical Jobs. The position you are applying for will require access to technology that is subject to U.S. export control and government contract restrictions.  Employment with IonQ is contingent on either verifying “U.S. Person” (e.g., U.S. citizen, U.S. national, U.S. permanent resident, or lawfully admitted into the U.S. as a refugee or granted asylum) status for export controls and government contracts work, obtaining any necessary license, and/or confirming the availability of a license exception under U.S. export controls.  Please note that in the absence of confirming you are a U.S. Person for export control and government contracts work purposes, IonQ may choose not to apply for a license or decline to use a license exception (if available) for you to access export-controlled technology that may require authorization, and similarly, you may not qualify for government contracts work that requires U.S. Persons, and IonQ may decline to proceed with your application on those bases alone.  Accordingly, we will have some additional questions regarding your immigration status that will be used for export control and compliance purposes, and the answers will be reviewed by compliance personnel to ensure compliance with federal law.  

US Non-Technical Jobs. Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum. Accordingly, we will have some additional questions regarding your immigration status that will be used for export control and compliance purposes, and the answers will be reviewed by compliance personnel to ensure compliance with federal law.

If you are interested in being a part of our team and mission, we encourage you to apply! 


Similar Jobs

An Hour Ago
Remote or Hybrid
USA
75K-125K Annually
Senior level
75K-125K Annually
Senior level
Machine Learning • Payments • Security • Software • Financial Services
Lead business analysis for Digital Identity projects: gather and document system requirements, define capabilities, create system flows, manage backlogs, roadmap and releases, mentor junior analysts, coordinate stakeholders, and drive process improvement within Agile frameworks.
Top Skills: ConfluenceDynatraceJIRAKanbanMS OfficePostmanSafeScrumServicenowSoapui
3 Hours Ago
Remote or Hybrid
Senior level
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Lead and coach regional sales leaders and direct reps to drive new business and revenue growth. Own territory and quota planning, forecasting, pipeline management, C-level engagement, partner collaboration, and cross-functional alignment. Recruit and develop talent, support field teams to close deals, and retain/expand customer accounts while executing strategic sales initiatives to meet quarterly and annual targets.
Top Skills: AICRMServicenow
3 Hours Ago
Remote or Hybrid
148K-230K Annually
Expert/Leader
148K-230K Annually
Expert/Leader
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Lead technical architecture and platform strategy for ServiceNow implementations across federal customers. Advise executives and engineering teams on instance strategy, integrations, governance, cloud application design, and technical debt reduction. Scope engagements, support sales, contribute leading practices, mentor others, and ensure long-term platform health and adoption.
Top Skills: AIAPIsCloudIntegrationsServicenow

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account