Job Details:
Job Title: Source Control and Governance Engineer
Location: 100% Remote
Duration: 6+ Months Contract
Background
CoreWeave runs an AI compute and bare metal infrastructure platform. The Source Control and Governance team builds the tooling and automation that keeps that platform compliant, secure, and audit-ready across SOC 2, SOX, and ISO 27001.
Most of that work lands on GitHub. The team owns org-wide policy, branch and repository rulesets, code ownership rules, the GitHub Apps that hold automation access, the access review process, and an internal portal where the results of all of it are visible.
This engagement brings in a senior engineer to own a defined slice of that tooling. The work is greenfield automation, not audit support or control attestation. The contractor writes code; CoreWeave staff own the controls, the auditor relationship, and any decision that binds the company.
Scope of work
The contractor will deliver, in priority order set by the team lead:
• Compliance pipelines. Build automated checks that run on infrastructure
o changes and compute provisioning, wired into existing CI/CD. Checks must fail closed, log their decision, and be reviewable in version control.
• Policy as code. Implement governance rules using OPA/Rego, Conftest, or
o Every rule ships with tests, a written statement of what it enforces, and a documented exception path.
• Evidence automation. Replace named manual evidence tasks with pipelines
o that produce timestamped, immutable artifacts on a fixed schedule. Each automation includes a runbook and an owner handoff.
• GitHub platform automation. Build against the GitHub REST, GraphQL, and
o Enterprise APIs to manage and audit rulesets, code ownership rules, repository and team access, and GitHub App installations. Handle pagination, rate limits, and App installation tokens correctly.
• Access review tooling. Build and run the recurring certification process:
o pull current access, generate reviewer worklists, capture decisions, and produce the revocation list and the evidence artifact at the end.
• Audit log analysis. Work with GitHub audit log data in S3 through Athena
o to build baselines and detections for policy overrides, unreviewed merges, and credential events. Includes the table and partition setup, not just the
• Internal portal. Contribute to the internal web application that surfaces
o posture, access, and review state. This is a real frontend and backing service, not a BI dashboard. Read-only against source systems.
• Infrastructure as code. Manage GitHub org and repository configuration in
o Every change is reviewed and applied through the existing pipeline, never clicked in the UI.
• Go services and tooling. Write and maintain the Go services, collectors,
o and command line tools the items above depend on, to the team's existing code standards and test coverage bar.
Anything outside this list is out of scope unless added by written change order.
Deliverables and acceptance
Deliverable Accepted when
Pipeline checks in CI/CD Merged, running on real traffic for 10 business days, documented failure modes
Policy-as-code rule set Rules version-controlled, test coverage on each rule, peer reviewed and merged
Evidence collection jobs Producing artifacts on schedule, runbook written, named CoreWeave owner signed off
GitHub platform automation Running against the live org, rate-limit and pagination behavior verified, no manual steps left
Access review tooling One full review cycle completed end to end using it, evidence artifact produced
Audit log baselines and detections Queries and tables checked in, results reproducible, false-positive rate reviewed with the team
Portal features Deployed to the internal environment, data sources documented, reviewed against the team's UI standards
Terraform changes Planned and applied through the existing pipeline, no drift against live state
Go services and tooling Merged, unit tested, builds and deploys through the team's existing pipeline
Handover package Architecture notes, runbooks, and open-issue list in the team repo
All code lands in CoreWeave repositories under CoreWeave ownership. Work is accepted by the Source Control and Governance team lead. Nothing is considered delivered until it is merged and running in the target environment.
Required skills
• 7+ years building production software.
• Production Go development. Writing, testing, and shipping Go services and
o command line tools, including concurrency, memory behavior, and performance work at scale.
• Python for scripting and data collection work alongside the Go codebase.
• Designed and built CI/CD pipelines in GitHub Actions, GitLab CI, Jenkins, or
o Buildkite, with a clear view of pipeline architecture and design patterns.
• Hands-on with the GitHub platform at org scale. Rulesets, code ownership,
o teams and permissions, and the REST and GraphQL APIs, including App
• Terraform for managing real infrastructure, including reading a plan and
o knowing when not to apply it.
• Comfortable with Linux systems and networking fundamentals.
• Self-directed. Takes a workstream, runs it, and reports status without being
Useful but not required
• Policy-as-code tools: OPA/Rego, Sentinel, Checkov, InSpec.
• Working knowledge of SOC 2, SOX, ISO 27001, or NIST CSF. Auditor experience is
o not needed. Knowing what a control is and why it exists is.
• Cloud infrastructure, bare metal, or compute platform background.
• Web application work in TypeScript or similar, enough to contribute to an
o internal portal rather than only backend services.
• Querying large log datasets in S3 with Athena, Presto, or equivalent, including
o partitioning and cost awareness.
• Secrets and credential management: rotation, short-lived tokens, and
o just-in-time access patterns.