
Senior Engineer, Tech Lead – Trust, Security, Privacy & Compliance
Posted 4 hours ago

Posted 4 hours ago
This is a fully remote position, open to applicants in United States.
• Design and execute identity, authentication, authorization, service identity, secrets management, production access, and audit controls.
• Establish and implement isolation for environments, tenants, workloads, and sensitive information.
• Create audit logs and change history that are suitable for external auditor evaluation.
• Uphold technical SOC 2 Type II and HIPAA controls.
• Automate access reviews and the collection of audit evidence.
• Resolve technical audit findings and work collaboratively with auditors during testing.
• Develop secure CI/CD release paths and infrastructure-as-code controls with production approvals.
• Publish shared modules and reference implementations to ensure teams receive controls by default.
• Conduct threat modeling for critical workflows and translate findings into engineering requirements.
• Review security-sensitive code, infrastructure, and architectural modifications.
• Manage engineering-side logging, detection, runbooks, and escalation paths.
• Lead or assist in incident investigations and containment efforts.
• Engage in tabletop exercises alongside the Trust Product Manager and leadership.
• Convert NIST requirements into actionable controls and priorities.
• Provide leadership with a technical roadmap for state and federal environments, including practices aligned with FedRAMP where applicable.
• Act as a senior engineer and technical lead for security, privacy, and compliance controls.
• Collaborate technically with the Trust Product Manager, who oversees requirements, governance, and the roadmap.
• Over 7 years of software engineering experience, including several years as a senior or lead engineer on production systems.
• Personally committed application and infrastructure code within the last year or two.
• Hands-on experience with SOC 2 Type II and HIPAA, including the implementation and operation of controls through an audit process.
• Experience in building or managing a system that handles protected health information.
• Cloud-native production experience, preferably on AWS.
• Proficient in infrastructure as code and CI/CD pipelines with approval steps.
• Experience in independently setting up production environments.
• Skilled in designing identity and access systems, encompassing authentication, role- or attribute-based authorization, service identities, secrets management, production access controls, and audit logging.
• Experience with threat modeling that leads to implemented controls.
• Proven track record in addressing audit, penetration-test, or incident findings.
• Capability to articulate enforcement trade-offs to product leads, auditors, and engineers.
• Ability to work independently while the architecture and operating model are still developing.
• Must be located in the U.S.
• Bonus: Familiarity with NIST 800-53 or other 800-series controls mapped to real system changes.
• Bonus: Experience with FedRAMP or ISO 27001.
• Bonus: Automated evidence collection or continuous control monitoring that is accepted by an auditor.
• Bonus: Experience with incident-response runbooks or tabletop exercises.
• Bonus: Node, TypeScript, and AWS experience within the same production environment.
• Bonus: Development of software for government, healthcare, or fintech clients.
• Fully remote position within the U.S.
• Full-time employment through an Employer of Record (EOR).
• Genuine technical ownership of design decisions and control-building priorities.
• Direct collaboration with Product & Engineering leadership.
• Mission-driven impact, safeguarding the data of families who rely on public benefits.
Affidea
GoFasti
StructureIt
L3Harris Technologies
Get handpicked remote jobs straight to your inbox weekly.