Member of Technical Staff - Principal Software Engineer - Health Privacy & Compliance
Rewrite
## About the role
- Be the primary point of contact for privacy, compliance, and regulatory matters within the engineering team - the person product and engineering turn to for guidance, design review, and decisions.
- Ensure products such as Copilot Health are designed and built in a privacy-preserving way, embedding data minimization, purpose limitation, and privacy-by-design into architecture from the outset.
- Translate complex health and data-protection regulations - including UK and EU GDPR, HIPAA, and the EU AI Act - into concrete technical requirements, engineering guardrails, and automated, continuously verifiable controls.
- Lead privacy and security design reviews and threat modeling for new features and models, identifying risks early and architecting practical, scalable mitigations.
- Design and build foundational privacy infrastructure: data classification, policy-driven access controls, consent and preference management, audit logging, data lineage, and retention and lifecycle controls.
- Evaluate and apply privacy-enhancing technologies - such as differential privacy, de-identification, secure enclaves, and federated approaches - where they meaningfully reduce risk to users.
- Build reusable libraries, patterns, and tooling that let every engineer ship privacy-preserving features by default, and raise the team's privacy and compliance fluency through mentorship and clear standards.
- Partner across legal, compliance, security, and product to balance strong user protections with product velocity, and to support audits, certifications, and regulator-facing evidence.
- Stay ahead of emerging health-privacy regulation and industry practice, bringing that perspective into roadmaps before requirements become blockers.
## Requirements
- Extensive professional software engineering experience building and operating production systems at scale, with significant depth in privacy, security, or data protection.
- Strong programming skills in at least one major language (e.g., C#, Python, Go, Java, or similar) and a track record of shipping reliable backend and infrastructure systems.
- Demonstrated ability to translate privacy and regulatory requirements (such as GDPR or HIPAA) into technical designs and enforceable controls.
- Hands-on command of privacy and security fundamentals: privacy-by-design, data minimization, access-control models (RBAC/ABAC), encryption, audit logging, and data lifecycle management.
- Experience conducting privacy and security reviews, threat modeling, and risk assessments.
- Excellent cross-functional communication - able to influence product, engineering, legal, and compliance stakeholders and explain trade-offs clearly.
- Bachelor's degree in Computer Science or a related field, or equivalent practical experience.
## Nice to have
- Experience in health technology (strongly preferred), or in another highly regulated industry such as financial services, government, or insurance (acceptable).
- Familiarity with health-data standards and governance frameworks (e.g., HIPAA, HITRUST, ISO 27001/27701, NHS data governance, FHIR and clinical data handling).
- Practical experience applying privacy-enhancing technologies - differential privacy, anonymization/de-identification, secure enclaves, or federated learning.
- Experience with AI/ML systems and the privacy considerations of training and inference on sensitive data.
- Experience with cloud platforms (Azure preferred) and large-scale data systems.
- Relevant certifications such as CIPP/E or CIPT.
Sourced via microsoft · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.