{"id":1235017,"url":"https://alion.io/job/monee-it-compliance-automation-engineer","title":"IT Compliance Automation Engineer","company":{"id":2725464,"name":"Monee","domain":"monee.com","url":"https://alion.io/company/monee","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Career site","truth_index":null},"role":"DevOps","role_family":"DevOps","seniority":"junior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Singapore"],"countries":["SG"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":null,"experience_years_min":2,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"Ansible","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"Docker","optional":false},{"name":"IAM","optional":false},{"name":"ISO 27001","optional":false},{"name":"LLM","optional":false},{"name":"Model Context Protocol","optional":false},{"name":"n8n","optional":false},{"name":"Node JS","optional":false},{"name":"Python","optional":false},{"name":"Rest API","optional":false},{"name":"ServiceNow","optional":false},{"name":"SIEM","optional":false},{"name":"Swagger","optional":false},{"name":"Terraform","optional":false},{"name":"JavaScript","optional":true}],"status":"live","first_seen_at":"2026-09-25T16:14:42Z","employer_posted_date":"2026-09-25","last_verified_at":"2026-09-25T23:50:42Z","board_verified":false,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"Design and implement workflow-based control automation for Regulatory Standards (e.g., ISO, PCI) and SOX 404 ITGCs, using:Explicit start-action-evidence-end flows.\nTriggers from tickets, change-management systems, HR events, or IAM changes.\nDelivered via tools such as n8n, Camunda, Azure Logic Apps, or custom MCP-style servers.\n\nBuild and operate MCP-style or MCP-compatible servers that expose:Tools: RESTful endpoints for “trigger evidence collection”, “run access review”, “validate change ticket”, etc..\nResources: Standardized data sources (logs, IAM, ticket data) formatted for AI agents or workflow engines.\nAuth patterns: API keys, bearer tokens, OAuth2, or OIDC-style flows that can be consumed by agents or external tools.\n\nEngineer API-first automation:Write scripts and connectors (Python, Node.js, Bash, etc.) that call, compose, and orchestrate APIs from:IAM, IdP, PAM, HRIS, ticketing, cloud IAM, and logging platforms, etc.\nGRC platforms (e.g., ServiceNow, 6clicks, or similar) via REST APIs.\n\nImplement:Authentication and authorization (API keys, Bearer, OAuth2, JWT, Basic, MTLS).\nPagination, retry with backoff, rate-limiting, and safe error handling.\nIdempotency and safe state transitions for audit-critical operations.\n\nTranslate ISO 27001 controls and SOX 404 ITGCs into automated workflows:Example pattern:Trigger: new user join or role change in IAM.\nAction: call APIs to validate entitlements, cross-check against SoD, and emit evidence to a GRC tool.\nOutcome: workflow-generated record for ISO 27001 access control and SOX logical-access control.\n\nMaintain one source of truth for control logic (code / config) and use workflow IDs as control-evidence bindings.\n\nDesign AI-agent-ready interfaces:Expose structured, MCP-style endpoints or OpenAPI specs so that LLM agents or workflow tools can call concrete tools (e.g., “get latest access review for System X”, “run change-ticket-completeness check”).\nHandle dynamic policy enforcement: short-lived tokens, context-aware access, and audit logging for each AI or agent call.\n\nIntegrate with data platforms and SIEM/logging:Use logs, change tickets, and identity events as workflow inputs.\nBuild automated tests for control effectiveness (e.g., “if a production change is not approved, fire an alert and record as control failure”) linked to ISO / SOX control IDs.\n\nMaintain audit-ready workflow artifacts:Log all workflow steps, including timestamps, input, user/agent context, and outputs.\nEnsure workflow outputs are machinable (JSON, structured logs) and can be replayed or reasoned over by auditors or AI agents.\n\nBachelor's degree or above in computer science, computer engineering or related disciplines.\nStrong understanding of authorization and authentication:API keys, Bearer tokens, OAuth2 (client, JWT, PKCE), Basic Auth, MTLS, and OIDC-style flows.\nHands-on experience implementing these in Python, Node.js, or Go (or similar).\n\nDeep practical experience with:RESTful APIs: understanding of HTTP methods, status codes, pagination, rate-limiting, and idempotency.\nAPI clients: writing or using libraries that handle auth, retries, and error handling for large datasets.\n\nExperience building or integrating with:Workflow / orchestration tools (n8n, Airflow, Logic Apps, Camunda, etc.) or MCP-style servers / Model Context Protocol-compatible tooling.\nGRC platforms via APIs (e.g., ServiceNow, 6clicks, or similar).\n\nAt least 2 years of working experience with:ISO 27001 (especially Annex A controls related to access management, change control, and operations).\nSOX 404 ITGCs (logical access, change management, computer operations, data integrity).\n\nFamiliarity with:\nOpenAPI / Swagger to MCP-style tool generation (e.g., converting production APIs into MCP servers or AI-agent tools).\nExperience with MCP servers or similar control-plane architectures that expose tools, resources, and prompts for AI agents.\nBackground in security automation, CI/CD, or DevSecOps (number of tools: n8n, Terraform, Ansible, Docker, logging pipelines).\nPrior involvement in SOX 404 audits and ISO 27001 certification projects, with a focus on how to automate evidence collection rather than manual spreadsheets.","description_format":"text","description_chars":4183,"description_truncated":false,"requirements":{"experience_years_min":2,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":[],"lifecycle":[{"event":"open","at":"2026-09-25T16:14:42Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":15,"reasons":["conf:29","velocity","win:early","comp:junior"],"computed_at":"2026-09-27T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/monee-it-compliance-automation-engineer","json_url":"https://alion.io/job/monee-it-compliance-automation-engineer.json","meta":{"generated_at":"2026-09-28T03:10:34Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2000,"day_limit":5000,"remaining_today":3000,"minute_limit":60,"resets_at":"2026-09-29T00:00:00Z"}}}