Senior Engineer / Tech Lead, Trust (Security, Privacy & Compliance) | GovTech
Build the security, privacy and compliance controls behind a platform that helps families access the public benefits they need. You write the code that makes trust the default.
We usually respond within a week
Company Overview:
Our client is a venture-backed govtech startup that helps families find the benefit programs they qualify for, apply to several at once and stay enrolled as rules change. State agencies, Medicaid managed care organizations and employers pay for the platform. It now runs eligibility checks and applications across federal, state and local programs. Its customers are highly regulated, so security and privacy shape how the team builds. The team is small and fully remote across the U.S.
Your Role:
This is not a "review and advise" security role. You build the controls yourself.
State and federal buyers are asking for stricter security standards. Security and privacy are now core parts of the platform, not side projects.
You'll be the senior engineer and tech lead for the platform's security, privacy and compliance controls, and the technical partner to the Trust Product Manager. The PM owns requirements, governance and the roadmap. You own the architecture and the working systems.
You'll start with the engineering behind the existing SOC 2 Type II and HIPAA controls. Recurring manual work like access reviews and evidence collection moves into code.
Then you'll lead the technical side of the company's NIST 800-series alignment..
What you'll do
Identity & Production Access (primary focus)
Design how people and services sign in, what each role is allowed to do, and where secrets are stored.
Decide how engineers get into production and who approves that access.
Write the design and the code, and agree on the requirements with the Trust PM.
Isolation & Audit Logging
Keep environments, tenants, workloads and sensitive data separate from each other.
Build audit logs and change history that show who did what, in a form outside auditors can test.
SOC 2 Type II & HIPAA Controls
Keep the technical controls working, and move access reviews and evidence pulls from manual steps into code.
Take every technical audit finding through to closure, and work with auditors on their tests.
Secure Delivery
Build the release path in CI/CD and infrastructure as code, with approvals before anything reaches production.
Publish shared modules and reference implementations so other teams get the controls by default.
Threat Modeling & Review
Run threat models on critical workflows and turn each finding into an engineering requirement.
Review security-sensitive code, infrastructure and architecture changes before they go live.
Incident Readiness
Own logging, detection, runbooks and escalation paths on the engineering side.
Lead or support investigation and containment when an incident happens, and join tabletop exercises with the PM and leadership.
NIST 800-series Path
With the PM, translate NIST requirements into controls and priorities.
Give leadership a technical roadmap for state and federal environments, moving toward FedRAMP-aligned practices where they apply.
You Bring:
7+ years of software engineering, including a few years as the senior or lead engineer on production systems. You've committed application and infrastructure code yourself in the last year or two.
Hands-on SOC 2 Type II and HIPAA experience: controls you implemented and ran through an audit, and a system holding protected health information that you built or operated.
Cloud-native production experience, ideally on AWS, including infrastructure as code, CI/CD pipelines with approval steps, and environments you set up yourself.
Identity and access systems you designed: authentication, role- or attribute-based authorization, service identities, secrets management, production access controls and audit logging.
Threat modeling carried through to shipped controls, and audit, pen-test or incident findings you closed yourself.
Good judgment on what to enforce in software and what to leave as a process, and the ability to explain that trade-off to a product lead, an auditor and an engineer.
Comfort working autonomously while the architecture and operating model are still taking shape.
You must be based in the U.S.
Bonus points:
NIST 800-53 or other 800-series controls you mapped to real system changes
FedRAMP or ISO 27001 experience, even on one part of a system
Automated evidence collection or continuous control monitoring that an auditor accepted
Incident-response runbooks you wrote, or a tabletop exercise you ran
Node, TypeScript and AWS in the same production environment
Software built for government, healthcare or fintech customers
What They Offer:
A fully remote role within the U.S.
$14,583–$17,500 USD/month, depending on experience
Full-time employment through an Employer of Record (EOR)
Real technical ownership: the design decisions, and the order in which controls get built, are yours
Direct collaboration with Product & Engineering leadership in a small, fast-growing team
Mission-driven impact: your work protects the data of families who rely on public benefits
Interview Process:
1️⃣ Application review (resume and a few questions)
2️⃣ 30-minute screening call with Atomic HR about what you've built and what you want next
3️⃣ Profile shared with the hiring manager, who decides whom to meet. We'll update you either way.
4️⃣ Interviews with the hiring manager covering your access, audit logging and isolation designs, how you run threat models, and how you decide which controls to build now
5️⃣ Offer
- Department
- Technology/Engineering
- Role
- Full-Stack Software Engineer
- Locations
- Multiple locations
- Employment type
- Full-time
About Atomic HR
We connect talented tech professionals in Latin America and Canada with remote career opportunities at innovative startups worldwide. We specialize in finding roles that align with your skills, experience, and career goals. Our personalized approach ensures you're matched with companies that value your contributions and offer opportunities for growth. Whether you're a software engineer, designer, marketer, or other tech professional, we're here to help you take the next step in your career.