For Employers

Atomic HR

Senior Engineer / Tech Lead, Trust (Security, Privacy & Compliance) | GovTech

Posted 6 hours ago
$14583 - $17500 per month
5-10 years experience
Apply Now

Please mention DailyRemote when applying

?
Resume Match Score

See how much of this job your resume covers, and what’s missing.

Want a recruiter to go through it line by line?

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

You will lead the architecture and implementation of security, privacy, and compliance controls for a govtech platform. This includes managing identity and access systems, audit logging, and aligning technical infrastructure with NIST and SOC 2 standards.

Company Overview:

Our client is a venture-backed govtech startup that helps families find the benefit programs they qualify for, apply to several at once and stay enrolled as rules change. State agencies, Medicaid managed care organizations and employers pay for the platform. It now runs eligibility checks and applications across federal, state and local programs. Its customers are highly regulated, so security and privacy shape how the team builds. The team is small and fully remote across the U.S.

Your Role:

  • This is not a "review and advise" security role. You build the controls yourself.

  • State and federal buyers are asking for stricter security standards. Security and privacy are now core parts of the platform, not side projects.

  • You'll be the senior engineer and tech lead for the platform's security, privacy and compliance controls, and the technical partner to the Trust Product Manager. The PM owns requirements, governance and the roadmap. You own the architecture and the working systems.

  • You'll start with the engineering behind the existing SOC 2 Type II and HIPAA controls. Recurring manual work like access reviews and evidence collection moves into code.

  • Then you'll lead the technical side of the company's NIST 800-series alignment..

What you'll do

  • Identity & Production Access (primary focus)

    • Design how people and services sign in, what each role is allowed to do, and where secrets are stored.

    • Decide how engineers get into production and who approves that access.

    • Write the design and the code, and agree on the requirements with the Trust PM.

  • Isolation & Audit Logging

    • Keep environments, tenants, workloads and sensitive data separate from each other.

    • Build audit logs and change history that show who did what, in a form outside auditors can test.

  • SOC 2 Type II & HIPAA Controls

    • Keep the technical controls working, and move access reviews and evidence pulls from manual steps into code.

    • Take every technical audit finding through to closure, and work with auditors on their tests.

  • Secure Delivery

    • Build the release path in CI/CD and infrastructure as code, with approvals before anything reaches production.

    • Publish shared modules and reference implementations so other teams get the controls by default.

  • Threat Modeling & Review

    • Run threat models on critical workflows and turn each finding into an engineering requirement.

    • Review security-sensitive code, infrastructure and architecture changes before they go live.

  • Incident Readiness

    • Own logging, detection, runbooks and escalation paths on the engineering side.

    • Lead or support investigation and containment when an incident happens, and join tabletop exercises with the PM and leadership.

  • NIST 800-series Path

    • With the PM, translate NIST requirements into controls and priorities.

    • Give leadership a technical roadmap for state and federal environments, moving toward FedRAMP-aligned practices where they apply.

You Bring:

  • 7+ years of software engineering, including a few years as the senior or lead engineer on production systems. You've committed application and infrastructure code yourself in the last year or two.

  • Hands-on SOC 2 Type II and HIPAA experience: controls you implemented and ran through an audit, and a system holding protected health information that you built or operated.

  • Cloud-native production experience, ideally on AWS, including infrastructure as code, CI/CD pipelines with approval steps, and environments you set up yourself.

  • Identity and access systems you designed: authentication, role- or attribute-based authorization, service identities, secrets management, production access controls and audit logging.

  • Threat modeling carried through to shipped controls, and audit, pen-test or incident findings you closed yourself.

  • Good judgment on what to enforce in software and what to leave as a process, and the ability to explain that trade-off to a product lead, an auditor and an engineer.

  • Comfort working autonomously while the architecture and operating model are still taking shape.

  • You must be based in the U.S.

Bonus points:

  • NIST 800-53 or other 800-series controls you mapped to real system changes

  • FedRAMP or ISO 27001 experience, even on one part of a system

  • Automated evidence collection or continuous control monitoring that an auditor accepted

  • Incident-response runbooks you wrote, or a tabletop exercise you ran

  • Node, TypeScript and AWS in the same production environment

  • Software built for government, healthcare or fintech customers

What They Offer:

  • A fully remote role within the U.S.

  • $14,583–$17,500 USD/month, depending on experience

  • Full-time employment through an Employer of Record (EOR)

  • Real technical ownership: the design decisions, and the order in which controls get built, are yours

  • Direct collaboration with Product & Engineering leadership in a small, fast-growing team

  • Mission-driven impact: your work protects the data of families who rely on public benefits

Interview Process:

1️⃣ Application review (resume and a few questions)
2️⃣ 30-minute screening call with Atomic HR about what you've built and what you want next
3️⃣ Profile shared with the hiring manager, who decides whom to meet. We'll update you either way.
4️⃣ Interviews with the hiring manager covering your access, audit logging and isolation designs, how you run threat models, and how you decide which controls to build now
5️⃣ Offer

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Software Development jobs →

Data Scientist

Full Time United States Software Development

Software Engineer/Senior Software Engineer (Full Stack)

Full Time Canada 90000 - 110K per year Software Development

Director, AI Infrastructure Ecosystem Market DevelopmentT

Full Time Australia, Malaysia, Singapore Software Development

Revenue Cycle Managed Services - AR Supervisor

Full Time United States Software Development

Associate Analytics Engineer

Full Time United States $75000 - $85000 per year Software Development

Sales Engineer

Full Time United States Software Development
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 220,531+ Jobs in Software Development

Answer easy questions

Answer easy questions

220,531+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified