CareerPlanGet AI match score →

Member of Technical Staff - Principal Software Engineer - Health Privacy & Compliance

United Kingdom, London, Enfield💼 Full-time🗓 2026-07-09 → 2026-07-31

Core

Primary point of contact for privacy, compliance, and regulatory matters within engineering, ensuring products like Copilot Health are built with privacy-by-design principles.

Role type

Principal Software Engineer (Health Privacy & Compliance)

Builds

Foundational privacy infrastructure including data classification, policy-driven access controls, consent management, audit logging, and data lineage.

Domain

Health technology and data protection regulation (GDPR, HIPAA, EU AI Act)

Deliverable

production ML models | infrastructure

Required skills

Software engineering at scale, programming in C#/Python/Go/Java, translating regulations to technical designs, privacy-by-design, data minimization, access-control models (RBAC/ABAC), encryption, audit logging, data lifecycle management, threat modeling, cross-functional communication.

Preferred skills

Health technology experience, financial services/government/insurance experience, health-data standards (HIPAA, HITRUST, ISO 27001/27701, FHIR), privacy-enhancing technologies (differential privacy, anonymization, secure enclaves, federated learning), AI/ML privacy considerations, cloud platforms (Azure), large-scale data systems.

Technologies

C#, Python, Go, Java, Azure, FHIR

Responsibilities

Lead privacy and security design reviews and threat modeling, design and build foundational privacy infrastructure, partner across legal/compliance/security/product to balance protections with velocity, stay ahead of emerging health-privacy regulation.

Seniority

Principal, hands-on IC with mentorship

Rewrite
## About the role - Be the primary point of contact for privacy, compliance, and regulatory matters within the engineering team - the person product and engineering turn to for guidance, design review, and decisions. - Ensure products such as Copilot Health are designed and built in a privacy-preserving way, embedding data minimization, purpose limitation, and privacy-by-design into architecture from the outset. - Translate complex health and data-protection regulations - including UK and EU GDPR, HIPAA, and the EU AI Act - into concrete technical requirements, engineering guardrails, and automated, continuously verifiable controls. - Lead privacy and security design reviews and threat modeling for new features and models, identifying risks early and architecting practical, scalable mitigations. - Design and build foundational privacy infrastructure: data classification, policy-driven access controls, consent and preference management, audit logging, data lineage, and retention and lifecycle controls. - Evaluate and apply privacy-enhancing technologies - such as differential privacy, de-identification, secure enclaves, and federated approaches - where they meaningfully reduce risk to users. - Build reusable libraries, patterns, and tooling that let every engineer ship privacy-preserving features by default, and raise the team's privacy and compliance fluency through mentorship and clear standards. - Partner across legal, compliance, security, and product to balance strong user protections with product velocity, and to support audits, certifications, and regulator-facing evidence. - Stay ahead of emerging health-privacy regulation and industry practice, bringing that perspective into roadmaps before requirements become blockers. ## Requirements - Extensive professional software engineering experience building and operating production systems at scale, with significant depth in privacy, security, or data protection. - Strong programming skills in at least one major language (e.g., C#, Python, Go, Java, or similar) and a track record of shipping reliable backend and infrastructure systems. - Demonstrated ability to translate privacy and regulatory requirements (such as GDPR or HIPAA) into technical designs and enforceable controls. - Hands-on command of privacy and security fundamentals: privacy-by-design, data minimization, access-control models (RBAC/ABAC), encryption, audit logging, and data lifecycle management. - Experience conducting privacy and security reviews, threat modeling, and risk assessments. - Excellent cross-functional communication - able to influence product, engineering, legal, and compliance stakeholders and explain trade-offs clearly. - Bachelor's degree in Computer Science or a related field, or equivalent practical experience. ## Nice to have - Experience in health technology (strongly preferred), or in another highly regulated industry such as financial services, government, or insurance (acceptable). - Familiarity with health-data standards and governance frameworks (e.g., HIPAA, HITRUST, ISO 27001/27701, NHS data governance, FHIR and clinical data handling). - Practical experience applying privacy-enhancing technologies - differential privacy, anonymization/de-identification, secure enclaves, or federated learning. - Experience with AI/ML systems and the privacy considerations of training and inference on sensitive data. - Experience with cloud platforms (Azure preferred) and large-scale data systems. - Relevant certifications such as CIPP/E or CIPT.
Sourced via microsoft · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply at Microsoft ↗