FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Engineer, Tech Lead – Trust, Security, Privacy & Compliance
Atomic - Remote Jobs. Design and implement identity, authentication, authorization, service identity, secrets management, production access, and audit controls .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in designing and implementing identity, authentication, and authorization systems, with a strong focus on SOC 2 Type II and HIPAA compliance. Proven ability to lead security initiatives, automate audit processes, and translate regulatory requirements into actionable engineering practices.
Highest-signal resume keywords
SOC 2 Type II ExperienceHIPAA ComplianceCloud-Native Production ExperienceInfrastructure as CodeThreat Modeling
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Identity and Access Systems DesignAuthenticationRole-Based AuthorizationSecrets ManagementAudit LoggingCI/CD PipelinesProduction Environment SetupAutomated Evidence CollectionIncident ResponseTechnical Audit Findings Closure
Soft Skills
Autonomous WorkCollaboration with AuditorsCommunication with Product Leads
Tools & Technologies
AWSNodeTypeScript
Certifications & Qualifications
NIST 800-53FedRAMPISO 27001
Industry Keywords
HealthcareFintechGovernmentProduction Access ControlsAudit Controls
Tech Stack
Tools & technologiesAWSCloudNode.jsTypeScript
About the role
Key responsibilities & impact- Design and implement identity, authentication, authorization, service identity, secrets management, production access, and audit controls
- Define and implement isolation for environments, tenants, workloads, and sensitive data
- Build audit logs and change history suitable for external auditor testing
- Maintain technical SOC 2 Type II and HIPAA controls
- Automate access reviews and audit evidence collection
- Close technical audit findings and collaborate with auditors during testing
- Build secure CI/CD release paths and infrastructure-as-code controls with production approvals
- Publish shared modules and reference implementations so teams receive controls by default
- Run threat models for critical workflows and convert findings into engineering requirements
- Review security-sensitive code, infrastructure, and architecture changes
- Own engineering-side logging, detection, runbooks, and escalation paths
- Lead or support incident investigations and containment
- Participate in tabletop exercises with the Trust Product Manager and leadership
- Translate NIST requirements into controls and priorities
- Provide leadership with a technical roadmap for state and federal environments, including FedRAMP-aligned practices where applicable
- Serve as senior engineer and technical lead for security, privacy, and compliance controls
- Partner technically with the Trust Product Manager, who owns requirements, governance, and roadmap
Requirements
What you’ll need- 7+ years of software engineering experience, including a few years as the senior or lead engineer on production systems
- Committed application and infrastructure code personally within the last year or two
- Hands-on SOC 2 Type II and HIPAA experience, including implementing and running controls through an audit
- Experience building or operating a system holding protected health information
- Cloud-native production experience, ideally on AWS
- Experience with infrastructure as code and CI/CD pipelines with approval steps
- Experience setting up production environments independently
- Experience designing identity and access systems, including authentication, role- or attribute-based authorization, service identities, secrets management, production access controls, and audit logging
- Threat modeling carried through to shipped controls
- Experience closing audit, penetration-test, or incident findings
- Ability to explain enforcement trade-offs to product leads, auditors, and engineers
- Ability to work autonomously while architecture and the operating model are still taking shape
- Must be based in the U.S.
- Bonus: NIST 800-53 or other 800-series controls mapped to real system changes
- Bonus: FedRAMP or ISO 27001 experience
- Bonus: Automated evidence collection or continuous control monitoring accepted by an auditor
- Bonus: Incident-response runbooks or tabletop exercise experience
- Bonus: Node, TypeScript, and AWS in the same production environment
- Bonus: Software built for government, healthcare, or fintech customers
Benefits
Comp & perks- Fully remote role within the U.S.
- Full-time employment through an Employer of Record (EOR)
- Real technical ownership of design decisions and control-building priorities
- Direct collaboration with Product & Engineering leadership
- Mission-driven impact protecting the data of families who rely on public benefits