The premise of the role is that a modern compliance program is mostly infrastructure. Evidence arrives through API integrations, controls are verified by automated checks, access flows through an identity provider, and policies live in version control. Someone has to build, monitor, and debug all of that — and that someone needs engineering skills, not just framework knowledge. When an automated check goes red, the fix is usually an IAM policy, a Terraform change, or a broken integration, not a memo. The title is newer than the work; teams have been doing it quietly since compliance platforms made programs automatable.
A compliance manager runs the program: schedules the audit, tracks tasks, coordinates people, owns the auditor relationship. A compliance engineer makes the machinery underneath actually work — evidence collection that doesn’t depend on screenshots, integrations that don’t silently break, alerts when a control drifts out of spec. Small companies rarely employ both, so the duties get bundled onto one overloaded hire or moved outside entirely. The concrete task list is at What Does a Compliance Engineer Do.
People fluent in both audits and engineering are rare, expensive, and hard to keep busy at seed stage. That economics produced the forward-deployed engineer model — shared compliance engineers embedded across client programs. Agency delivers the role that way inside managed compliance services and treats the discipline as its own practice area; see GRC Engineering.