Principal Engineer
$183,100–$183,100 year
On-siteToronto, Ontario, Canada or Ann Arbor, Michigan, United States
Job Summary
Own the compliance architecture for CoCounsel's advanced AI offering, evolving technical controls to satisfy SOC 2 Type II, ISO 27001/42001, HIPAA, and FedRAMP requirements across infrastructure and data pipelines. Build compliance as code by automating evidence collection, continuous control monitoring, and policy-as-code to make compliance state observable and provable. Engineer production-scale systems with encryption, key management, data residency, and tenant isolation for privileged legal documents, while partnering with Security, Legal, and Product to translate regulatory requirements into engineering roadmaps. Establish SLOs, observability, and incident response practices for compliance-critical systems, and mentor staff on secure-by-design development and threat modeling.
Required Qualifications
- Bachelor's Degree in Computer Science, Computer Engineering, a related field, or equivalent experience
- Direct, hands-on experience building or operating production systems that achieved and maintained SOC 2 Type II, ISO 27001 (and/or 42001), and HIPAA compliance
- Experience supporting a FedRAMP authorization process (SSP development, control implementation, 3PAO assessments, or ConMon) at the Moderate or High baseline
- Deep backend engineering expertise (Python, Java, Go, or similar) and experience with production systems on a major cloud provider (AWS preferred)
- Working knowledge of security control frameworks such as NIST 800-53, NIST CSF, or CIS Benchmarks
- Hands-on experience with identity and access management — authentication and authorization at scale (SSO, SAML, OIDC, OAuth 2.0, RBAC/ABAC), encryption and key management, and audit logging
- Proven track record owning large, complex compliance or security initiatives end-to-end: architecture, execution, audit readiness, and long-term operation
- Excellent communication skills and the ability to partner with auditors, security, legal, product, and engineering teams in a fast-moving environment
Desired Qualifications
- Experience achieving or maintaining a FedRAMP ATO with JAB or agency sponsorship, including direct interaction with 3PAOs and federal agency security teams
- Experience with GRC and compliance automation tooling (e.g., Vanta, Drata, OneTrust, or comparable platforms) and building custom evidence-collection pipelines where off-the-shelf tools fall short
- Experience in regulated industries handling sensitive data — legal, healthcare, financial services, or government
- Relevant certifications such as CISSP, CISM, CCSP, or similar
- Experience building compliance and security controls for AI/LLM systems specifically — model access controls, prompt/response data handling, and safeguards around sensitive or privileged content
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.