Job details
About this role
Role overview
A senior engineering role on a Security Governance team that treats compliance and risk management as engineering problems. The position focuses on building data pipelines, integrations, and agentic AI workflows that convert manual governance processes into continuously running, auditable products. Work spans partnership with security, compliance, and engineering stakeholders in an early-stage program where framing problems is as important as solving them.
Responsibilities
- Build and operate pipelines and integrations that aggregate, normalize, and join risk, control, and asset signals from systems of record, including source control, service registry, identity, ticketing, data platforms, and CI/CD tooling - Translate security standards and compliance requirements into policy-as-code: enforceable, testable rules that run continuously instead of as periodic spreadsheet exercises - Design agentic AI workflows that combine LLM reasoning with deterministic, auditable decision layers for evidence analysis, control monitoring, classification, and assessment - Build evaluation harnesses, benchmarks, and calibration tooling that keep automated governance outputs accurate and trustworthy - Automate evidence collection and continuous control monitoring to replace point-in-time audit preparation - Define technical direction for ambiguous, cross-team problem spaces and partner with governance, compliance, and engineering teams to identify the manual processes most worth turning into product - Help govern the AI systems built on the same platform, including assessing the autonomy and safety of internal agents
Requirements
- 7+ years building production software in backend, platform, data, or security engineering - Multi-year ownership of a production system, including on-call responsibilities, SLO management, and the maintenance work that follows launch - Proficiency in at least one of Python, Kotlin, Java, or Go, with comfort reading unfamiliar codebases - Hands-on experience building with LLMs (prompting, tool use, agents, or LLM-backed features) and informed opinions about where model judgment belongs - Experience with integration patterns including REST APIs, webhooks, authentication flows, and event-driven architectures - Experience pulling, normalizing, and joining data from multiple imperfect sources and handling edge cases gracefully - Track record of defining technical direction where the problem was ambiguous and carrying it across team boundaries
Nice to have
- Working knowledge of a security or compliance framework such as PCI DSS, SOX, SOC 2, ISO 27001, or NIST (governance experience is not required) - Production-scale LLM or agentic systems experience
Benefits and work setup
- Market-based compensation, with U.S. salary ranges spanning roughly $185,000–$327,000 depending on geographic zone - Remote work options, medical insurance, flexible time off, retirement savings plans, and modern family planning benefits