Principal Software Engineer, Security & Compliance
Core
Set technical direction for SOC 2, ISO 27001/42001, HIPAA, and FedRAMP compliance programs, turning requirements into resilient, instrumented systems for a legal AI platform.
Role type
Principal Software Engineer (Security & Compliance)
Builds
Production AI systems handling privileged legal data with embedded security controls and compliance automation.
Domain
Legal Technology / AI / Cybersecurity Compliance
Deliverable
production ML models | infrastructure
Required skills
SOC 2 Type II, ISO 27001/42001, HIPAA, FedRAMP (Moderate/High), Python, Java, Go, AWS, NIST 800-53, NIST CSF, CIS Benchmarks, Identity and Access Management (SSO, SAML, OIDC, OAuth 2.0, RBAC/ABAC), Encryption and Key Management, Audit Logging, Threat Modeling, Incident Response, Policy-as-Code, Continuous Control Monitoring
Preferred skills
FedRAMP ATO with JAB/agency sponsorship, GRC automation tooling (Vanta, Drata, OneTrust), Regulated industry experience (legal, healthcare, finance), AI/LLM security controls (model access, prompt/response handling), CISSP, CISM, CCSP
