Haystack
← Back to Jobs
Remote
Engineering
DE

Source Control and Governance Engineer - 100% Remote - 6+ Months Contract

Dexperts IncUnited States🇺🇸United StatesPosted Sep 28, 2026

Why This Role Stands Out

This remote contract role offers a fantastic opportunity to build greenfield automation and contribute to the security and compliance of a cutting-edge AI compute platform. You'll thrive here if you're a mid-senior engineer skilled in policy-as-code and API development, eager to expand your expertise in a dynamic, fast-paced environment. Apply now to shape critical tooling and gain invaluable experience.

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
Yesterday

Job Description

Job Details:
Job Title:             Source Control and Governance Engineer
Location:             100% Remote
Duration:            6+ Months Contract

Background
CoreWeave runs an AI compute and bare metal infrastructure platform. The Source Control and Governance team builds the tooling and automation that keeps that platform compliant, secure, and audit-ready across SOC 2, SOX, and ISO 27001.
Most of that work lands on GitHub. The team owns org-wide policy, branch and repository rulesets, code ownership rules, the GitHub Apps that hold automation access, the access review process, and an internal portal where the results of all of it are visible.
This engagement brings in a senior engineer to own a defined slice of that tooling. The work is greenfield automation, not audit support or control attestation. The contractor writes code; CoreWeave staff own the controls, the auditor relationship, and any decision that binds the company.

Scope of work
The contractor will deliver, in priority order set by the team lead:
•    Compliance pipelines. Build automated checks that run on infrastructure
o    changes and compute provisioning, wired into existing CI/CD. Checks must fail closed, log their decision, and be reviewable in version control.
•    Policy as code. Implement governance rules using OPA/Rego, Conftest, or
o    Every rule ships with tests, a written statement of what it enforces, and a documented exception path.
•    Evidence automation. Replace named manual evidence tasks with pipelines
o    that produce timestamped, immutable artifacts on a fixed schedule. Each automation includes a runbook and an owner handoff.
•    GitHub platform automation. Build against the GitHub REST, GraphQL, and
o    Enterprise APIs to manage and audit rulesets, code ownership rules, repository and team access, and GitHub App installations. Handle pagination, rate limits, and App installation tokens correctly.
•    Access review tooling. Build and run the recurring certification process:
o    pull current access, generate reviewer worklists, capture decisions, and produce the revocation list and the evidence artifact at the end.
•    Audit log analysis. Work with GitHub audit log data in S3 through Athena
o    to build baselines and detections for policy overrides, unreviewed merges, and credential events. Includes the table and partition setup, not just the
•    Internal portal. Contribute to the internal web application that surfaces
o    posture, access, and review state. This is a real frontend and backing service, not a BI dashboard. Read-only against source systems.
•    Infrastructure as code. Manage GitHub org and repository configuration in
o    Every change is reviewed and applied through the existing pipeline, never clicked in the UI.
•    Go services and tooling. Write and maintain the Go services, collectors,
o    and command line tools the items above depend on, to the team's existing code standards and test coverage bar.
Anything outside this list is out of scope unless added by written change order.

Deliverables and acceptance
Deliverable    Accepted when
Pipeline checks in CI/CD    Merged, running on real traffic for 10 business days, documented failure modes
Policy-as-code rule set    Rules version-controlled, test coverage on each rule, peer reviewed and merged
Evidence collection jobs    Producing artifacts on schedule, runbook written, named CoreWeave owner signed off
GitHub platform automation    Running against the live org, rate-limit and pagination behavior verified, no manual steps left
Access review tooling    One full review cycle completed end to end using it, evidence artifact produced
Audit log baselines and detections    Queries and tables checked in, results reproducible, false-positive rate reviewed with the team
Portal features    Deployed to the internal environment, data sources documented, reviewed against the team's UI standards
Terraform changes    Planned and applied through the existing pipeline, no drift against live state
Go services and tooling    Merged, unit tested, builds and deploys through the team's existing pipeline
Handover package    Architecture notes, runbooks, and open-issue list in the team repo
All code lands in CoreWeave repositories under CoreWeave ownership. Work is accepted by the Source Control and Governance team lead. Nothing is considered delivered until it is merged and running in the target environment.

Required skills
•    7+ years building production software.
•    Production Go development. Writing, testing, and shipping Go services and
o    command line tools, including concurrency, memory behavior, and performance work at scale.
•    Python for scripting and data collection work alongside the Go codebase.
•    Designed and built CI/CD pipelines in GitHub Actions, GitLab CI, Jenkins, or
o    Buildkite, with a clear view of pipeline architecture and design patterns.
•    Hands-on with the GitHub platform at org scale. Rulesets, code ownership,
o    teams and permissions, and the REST and GraphQL APIs, including App
•    Terraform for managing real infrastructure, including reading a plan and
o    knowing when not to apply it.
•    Comfortable with Linux systems and networking fundamentals.
•    Self-directed. Takes a workstream, runs it, and reports status without being

Useful but not required
•    Policy-as-code tools: OPA/Rego, Sentinel, Checkov, InSpec.
•    Working knowledge of SOC 2, SOX, ISO 27001, or NIST CSF. Auditor experience is
o    not needed. Knowing what a control is and why it exists is.
•    Cloud infrastructure, bare metal, or compute platform background.
•    Web application work in TypeScript or similar, enough to contribute to an
o    internal portal rather than only backend services.
•    Querying large log datasets in S3 with Athena, Presto, or equivalent, including
o    partitioning and cost awareness.
•    Secrets and credential management: rotation, short-lived tokens, and
o    just-in-time access patterns.

Similar jobs