Logo for atomic* HR

Senior Engineer / Tech Lead, Trust (Security, Privacy & Compliance) | GovTech

Role overview

Qualifications

  • 7+ years of software engineering experience
  • Hands-on SOC 2 Type II and HIPAA experience
  • Cloud-native production experience, ideally on AWS
  • Comfort working autonomously

Responsibilities

  • Design and implement production access controls
  • Build audit logging and change history for sensitive data
  • Manage SOC 2 Type II and HIPAA controls, transitioning manual steps into code
  • Lead threat modeling and incident readiness initiatives

Hard skills

Other skills

  • Collaboration

About the company

atomic* HR logo

atomic* HR

Staffing & Recruiting

At atomic*hr, we believe the right people can transform your startup. That's why we're dedicated to connecting you with top global talent. We've seen firsthand how the perfect hire can fuel a company's success, and we want to bring that power to your team. Our Services Recruitment Solutions: We specialize in finding exceptional tech talent worldwide, navigating the complexities of international hiring with ease. Employer Branding: Let us help you craft a compelling story that attracts the best candidates. HR & ATS Setup: We'll establish smooth onboarding processes that support your rapid growth. Diversity, Equity & Inclusion (DEI): Build a truly inclusive workplace where diverse talent can flourish. Why Choose Us We understand the unique challenges and exciting potential of startups. Our expertise in tech, global hiring, and startup dynamics makes us more than consultants – we're your partners in building a world-class team. We're committed to finding the talent that will help your vision take flight. Ready to transform your startup? Contact us today!

Company details

Company typeSmall startup
IndustryStaffing & Recruiting
Company size2 - 10

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Company Overview:

Our client is a venture-backed govtech startup that helps families find the benefit programs they qualify for, apply to several at once and stay enrolled as rules change. State agencies, Medicaid managed care organizations and employers pay for the platform. It now runs eligibility checks and applications across federal, state and local programs. Its customers are highly regulated, so security and privacy shape how the team builds. The team is small and fully remote across the U.S.

Your Role:

  • This is not a "review and advise" security role. You build the controls yourself.

  • State and federal buyers are asking for stricter security standards. Security and privacy are now core parts of the platform, not side projects.

  • You'll be the senior engineer and tech lead for the platform's security, privacy and compliance controls, and the technical partner to the Trust Product Manager. The PM owns requirements, governance and the roadmap. You own the architecture and the working systems.

  • You'll start with the engineering behind the existing SOC 2 Type II and HIPAA controls. Recurring manual work like access reviews and evidence collection moves into code.

  • Then you'll lead the technical side of the company's NIST 800-series alignment..

What you'll do

  • Identity & Production Access (primary focus)

    • Design how people and services sign in, what each role is allowed to do, and where secrets are stored.

    • Decide how engineers get into production and who approves that access.

    • Write the design and the code, and agree on the requirements with the Trust PM.

  • Isolation & Audit Logging

    • Keep environments, tenants, workloads and sensitive data separate from each other.

    • Build audit logs and change history that show who did what, in a form outside auditors can test.

  • SOC 2 Type II & HIPAA Controls

    • Keep the technical controls working, and move access reviews and evidence pulls from manual steps into code.

    • Take every technical audit finding through to closure, and work with auditors on their tests.

  • Secure Delivery

    • Build the release path in CI/CD and infrastructure as code, with approvals before anything reaches production.

    • Publish shared modules and reference implementations so other teams get the controls by default.

  • Threat Modeling & Review

    • Run threat models on critical workflows and turn each finding into an engineering requirement.

    • Review security-sensitive code, infrastructure and architecture changes before they go live.

  • Incident Readiness

    • Own logging, detection, runbooks and escalation paths on the engineering side.

    • Lead or support investigation and containment when an incident happens, and join tabletop exercises with the PM and leadership.

  • NIST 800-series Path

    • With the PM, translate NIST requirements into controls and priorities.

    • Give leadership a technical roadmap for state and federal environments, moving toward FedRAMP-aligned practices where they apply.

You Bring:

  • 7+ years of software engineering, including a few years as the senior or lead engineer on production systems. You've committed application and infrastructure code yourself in the last year or two.

  • Hands-on SOC 2 Type II and HIPAA experience: controls you implemented and ran through an audit, and a system holding protected health information that you built or operated.

  • Cloud-native production experience, ideally on AWS, including infrastructure as code, CI/CD pipelines with approval steps, and environments you set up yourself.

  • Identity and access systems you designed: authentication, role- or attribute-based authorization, service identities, secrets management, production access controls and audit logging.

  • Threat modeling carried through to shipped controls, and audit, pen-test or incident findings you closed yourself.

  • Good judgment on what to enforce in software and what to leave as a process, and the ability to explain that trade-off to a product lead, an auditor and an engineer.

  • Comfort working autonomously while the architecture and operating model are still taking shape.

  • You must be based in the U.S.

Bonus points:

  • NIST 800-53 or other 800-series controls you mapped to real system changes

  • FedRAMP or ISO 27001 experience, even on one part of a system

  • Automated evidence collection or continuous control monitoring that an auditor accepted

  • Incident-response runbooks you wrote, or a tabletop exercise you ran

  • Node, TypeScript and AWS in the same production environment

  • Software built for government, healthcare or fintech customers

What They Offer:

  • A fully remote role within the U.S.

  • $14,583–$17,500 USD/month, depending on experience

  • Full-time employment through an Employer of Record (EOR)

  • Real technical ownership: the design decisions, and the order in which controls get built, are yours

  • Direct collaboration with Product & Engineering leadership in a small, fast-growing team

  • Mission-driven impact: your work protects the data of families who rely on public benefits

Interview Process:

1️⃣ Application review (resume and a few questions)
2️⃣ 30-minute screening call with Atomic HR about what you've built and what you want next
3️⃣ Profile shared with the hiring manager, who decides whom to meet. We'll update you either way.
4️⃣ Interviews with the hiring manager covering your access, audit logging and isolation designs, how you run threat models, and how you decide which controls to build now
5️⃣ Offer

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Engineering Lead Related jobs

Other jobs at atomic* HR

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.