FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Principal Software Engineer, Security & Compliance
Thomson Reuters. Set the technical direction for how CoCounsel earns and maintains trust for privileged, sensitive, and regulated data .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in compliance architecture, technical controls, and secure-by-design development for privileged data systems. Proficient in translating regulatory requirements into engineering roadmaps while mentoring teams on incident response and compliance practices.
Highest-signal resume keywords
SOC 2 Type II ComplianceISO 27001 CompliancePython Backend EngineeringIdentity And Access ManagementNIST 800-53 Knowledge
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Compliance ArchitectureData EncryptionKey ManagementAudit LoggingContinuous Control MonitoringPolicy-As-CodeThreat ModelingIncident ResponseCloud InfrastructureProduction Systems
Soft Skills
Excellent CommunicationMentoring
Tools & Technologies
AWSGRC ToolingVantaDrataOneTrust
Certifications & Qualifications
CISSPCISMCCSP
Industry Keywords
FedRAMP AuthorizationRegulated IndustriesSensitive Data HandlingCompliance AutomationSecurity Initiatives
Tech Stack
Tools & technologiesAWSCloudJavaPythonGo
About the role
Key responsibilities & impact- Set the technical direction for how CoCounsel earns and maintains trust for privileged, sensitive, and regulated data
- Own the compliance architecture and evolve technical controls across infrastructure, data pipelines, and AI systems
- Understand implications of new compliance requirements and certifications
- Replace point-in-time audit preparation with automated evidence collection, continuous control monitoring, and policy-as-code
- Design encryption, key management, data residency, tenant isolation, and audit logging for systems handling privileged legal documents and concurrent AI interactions
- Partner with Security, Legal, Privacy, Product, platform, identity, and AI/ML engineering teams
- Translate regulatory and contractual requirements into engineering roadmaps
- Mentor staff and senior engineers on secure-by-design development, threat modeling, and incident response
- Establish SLOs, observability, and incident response practices for compliance-critical systems
- Build dashboards, alerting, and control-testing tooling for real-time confidence in the control environment
Requirements
What you’ll need- Bachelor's Degree in Computer Science, Computer Engineering, a related field, or equivalent experience
- Direct, hands-on experience building or operating production systems that achieved and maintained SOC 2 Type II, ISO 27001 and/or ISO 42001, and HIPAA compliance
- Experience supporting a FedRAMP authorization process at the Moderate or High baseline
- Deep backend engineering expertise in Python, Java, Go, or similar
- Experience with production systems on a major cloud provider, AWS preferred
- Working knowledge of NIST 800-53, NIST CSF, or CIS Benchmarks
- Hands-on experience with identity and access management, including SSO, SAML, OIDC, OAuth 2.0, RBAC/ABAC
- Experience with encryption and key management
- Experience with audit logging
- Proven track record owning large, complex compliance or security initiatives end-to-end
- Excellent communication skills and ability to partner with auditors, security, legal, product, and engineering teams
- Preferred: Experience achieving or maintaining a FedRAMP ATO with JAB or agency sponsorship, including direct interaction with 3PAOs and federal agency security teams
- Preferred: Experience with GRC and compliance automation tooling such as Vanta, Drata, or OneTrust
- Preferred: Experience in regulated industries handling sensitive data
- Preferred: Relevant certifications such as CISSP, CISM, or CCSP
- Preferred: Experience building compliance and security controls for AI/LLM systems
Benefits
Comp & perks- Flexible hybrid working environment for office-based roles
- Flexible work arrangements, including work from anywhere for up to 8 weeks per year
- Flexible vacation
- Two company-wide Mental Health Days off
- Access to the Headspace app
- Retirement savings
- Tuition reimbursement
- Employee incentive programs
- Resources for mental, physical, and financial wellbeing
- Two paid volunteer days off annually
- Opportunities to participate in pro-bono consulting projects and ESG initiatives
- Career development, continuous learning, and skills development through Grow My Way programming
- Flexible work-life balance policies through Flex My Way