Source Control and Governance Engineer - 100% Remote - 6+ Months Contract

Remote • Posted 1 hour ago • Updated 1 hour ago
Contract Independent
Contract W2
6 Months
No Travel Required
Remote
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Source Control
  • Governance
  • Production Go
  • Go
  • GitHub
  • API
  • CI/CD
  • Terraform
  • IaC
  • Python
  • scripting
  • automation
  • REST
  • GraphQL
  • APIs
  • Linux

Summary

Job Details:
Job Title:             Source Control and Governance Engineer
Location:             100% Remote
Duration:            6+ Months Contract

Background
CoreWeave runs an AI compute and bare metal infrastructure platform. The Source Control and Governance team builds the tooling and automation that keeps that platform compliant, secure, and audit-ready across SOC 2, SOX, and ISO 27001.
Most of that work lands on GitHub. The team owns org-wide policy, branch and repository rulesets, code ownership rules, the GitHub Apps that hold automation access, the access review process, and an internal portal where the results of all of it are visible.
This engagement brings in a senior engineer to own a defined slice of that tooling. The work is greenfield automation, not audit support or control attestation. The contractor writes code; CoreWeave staff own the controls, the auditor relationship, and any decision that binds the company.

Scope of work
The contractor will deliver, in priority order set by the team lead:
•    Compliance pipelines. Build automated checks that run on infrastructure
o    changes and compute provisioning, wired into existing CI/CD. Checks must fail closed, log their decision, and be reviewable in version control.
•    Policy as code. Implement governance rules using OPA/Rego, Conftest, or
o    Every rule ships with tests, a written statement of what it enforces, and a documented exception path.
•    Evidence automation. Replace named manual evidence tasks with pipelines
o    that produce timestamped, immutable artifacts on a fixed schedule. Each automation includes a runbook and an owner handoff.
•    GitHub platform automation. Build against the GitHub REST, GraphQL, and
o    Enterprise APIs to manage and audit rulesets, code ownership rules, repository and team access, and GitHub App installations. Handle pagination, rate limits, and App installation tokens correctly.
•    Access review tooling. Build and run the recurring certification process:
o    pull current access, generate reviewer worklists, capture decisions, and produce the revocation list and the evidence artifact at the end.
•    Audit log analysis. Work with GitHub audit log data in S3 through Athena
o    to build baselines and detections for policy overrides, unreviewed merges, and credential events. Includes the table and partition setup, not just the
•    Internal portal. Contribute to the internal web application that surfaces
o    posture, access, and review state. This is a real frontend and backing service, not a BI dashboard. Read-only against source systems.
•    Infrastructure as code. Manage GitHub org and repository configuration in
o    Every change is reviewed and applied through the existing pipeline, never clicked in the UI.
•    Go services and tooling. Write and maintain the Go services, collectors,
o    and command line tools the items above depend on, to the team's existing code standards and test coverage bar.
Anything outside this list is out of scope unless added by written change order.

Deliverables and acceptance
Deliverable    Accepted when
Pipeline checks in CI/CD    Merged, running on real traffic for 10 business days, documented failure modes
Policy-as-code rule set    Rules version-controlled, test coverage on each rule, peer reviewed and merged
Evidence collection jobs    Producing artifacts on schedule, runbook written, named CoreWeave owner signed off
GitHub platform automation    Running against the live org, rate-limit and pagination behavior verified, no manual steps left
Access review tooling    One full review cycle completed end to end using it, evidence artifact produced
Audit log baselines and detections    Queries and tables checked in, results reproducible, false-positive rate reviewed with the team
Portal features    Deployed to the internal environment, data sources documented, reviewed against the team's UI standards
Terraform changes    Planned and applied through the existing pipeline, no drift against live state
Go services and tooling    Merged, unit tested, builds and deploys through the team's existing pipeline
Handover package    Architecture notes, runbooks, and open-issue list in the team repo
All code lands in CoreWeave repositories under CoreWeave ownership. Work is accepted by the Source Control and Governance team lead. Nothing is considered delivered until it is merged and running in the target environment.

Required skills
•    7+ years building production software.
•    Production Go development. Writing, testing, and shipping Go services and
o    command line tools, including concurrency, memory behavior, and performance work at scale.
•    Python for scripting and data collection work alongside the Go codebase.
•    Designed and built CI/CD pipelines in GitHub Actions, GitLab CI, Jenkins, or
o    Buildkite, with a clear view of pipeline architecture and design patterns.
•    Hands-on with the GitHub platform at org scale. Rulesets, code ownership,
o    teams and permissions, and the REST and GraphQL APIs, including App
•    Terraform for managing real infrastructure, including reading a plan and
o    knowing when not to apply it.
•    Comfortable with Linux systems and networking fundamentals.
•    Self-directed. Takes a workstream, runs it, and reports status without being

Useful but not required
•    Policy-as-code tools: OPA/Rego, Sentinel, Checkov, InSpec.
•    Working knowledge of SOC 2, SOX, ISO 27001, or NIST CSF. Auditor experience is
o    not needed. Knowing what a control is and why it exists is.
•    Cloud infrastructure, bare metal, or compute platform background.
•    Web application work in TypeScript or similar, enough to contribute to an
o    internal portal rather than only backend services.
•    Querying large log datasets in S3 with Athena, Presto, or equivalent, including
o    partitioning and cost awareness.
•    Secrets and credential management: rotation, short-lived tokens, and
o    just-in-time access patterns.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: RTX1d209c
  • Position Id: 9097684
  • Posted 1 hour ago
Contact the job poster
BS

Balaji Singh

Recruiter @ Dexperts Inc
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote or New York, New York

•

Today

Full-time

Remote

•

Today

Full-time

Remote

•

11d ago

Easy Apply

Contract

Depends on Experience

Remote

•

Today

Full-time

USD 205,000.00 - 231,000.00 per year

Search all similar jobs