Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Thomson Reuters

Principal Software Engineer, Security & Compliance

Thomson Reuters

. Set the technical direction for how CoCounsel earns and maintains trust for privileged, sensitive, and regulated data .

Posted 9/18/2026full-timeZug • SwitzerlandLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in compliance architecture, technical controls, and secure-by-design development for privileged data systems. Proficient in translating regulatory requirements into engineering roadmaps while mentoring teams on incident response and compliance practices.

Highest-signal resume keywords
SOC 2 Type II ComplianceISO 27001 CompliancePython Backend EngineeringIdentity And Access ManagementNIST 800-53 Knowledge

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Compliance ArchitectureData EncryptionKey ManagementAudit LoggingContinuous Control MonitoringPolicy-As-CodeThreat ModelingIncident ResponseCloud InfrastructureProduction Systems
Soft Skills
Excellent CommunicationMentoring
Tools & Technologies
AWSGRC ToolingVantaDrataOneTrust
Certifications & Qualifications
CISSPCISMCCSP
Industry Keywords
FedRAMP AuthorizationRegulated IndustriesSensitive Data HandlingCompliance AutomationSecurity Initiatives

Tech Stack

Tools & technologies
AWSCloudJavaPythonGo

About the role

Key responsibilities & impact
  • Set the technical direction for how CoCounsel earns and maintains trust for privileged, sensitive, and regulated data
  • Own the compliance architecture and evolve technical controls across infrastructure, data pipelines, and AI systems
  • Understand implications of new compliance requirements and certifications
  • Replace point-in-time audit preparation with automated evidence collection, continuous control monitoring, and policy-as-code
  • Design encryption, key management, data residency, tenant isolation, and audit logging for systems handling privileged legal documents and concurrent AI interactions
  • Partner with Security, Legal, Privacy, Product, platform, identity, and AI/ML engineering teams
  • Translate regulatory and contractual requirements into engineering roadmaps
  • Mentor staff and senior engineers on secure-by-design development, threat modeling, and incident response
  • Establish SLOs, observability, and incident response practices for compliance-critical systems
  • Build dashboards, alerting, and control-testing tooling for real-time confidence in the control environment

Requirements

What you’ll need
  • Bachelor's Degree in Computer Science, Computer Engineering, a related field, or equivalent experience
  • Direct, hands-on experience building or operating production systems that achieved and maintained SOC 2 Type II, ISO 27001 and/or ISO 42001, and HIPAA compliance
  • Experience supporting a FedRAMP authorization process at the Moderate or High baseline
  • Deep backend engineering expertise in Python, Java, Go, or similar
  • Experience with production systems on a major cloud provider, AWS preferred
  • Working knowledge of NIST 800-53, NIST CSF, or CIS Benchmarks
  • Hands-on experience with identity and access management, including SSO, SAML, OIDC, OAuth 2.0, RBAC/ABAC
  • Experience with encryption and key management
  • Experience with audit logging
  • Proven track record owning large, complex compliance or security initiatives end-to-end
  • Excellent communication skills and ability to partner with auditors, security, legal, product, and engineering teams
  • Preferred: Experience achieving or maintaining a FedRAMP ATO with JAB or agency sponsorship, including direct interaction with 3PAOs and federal agency security teams
  • Preferred: Experience with GRC and compliance automation tooling such as Vanta, Drata, or OneTrust
  • Preferred: Experience in regulated industries handling sensitive data
  • Preferred: Relevant certifications such as CISSP, CISM, or CCSP
  • Preferred: Experience building compliance and security controls for AI/LLM systems

Benefits

Comp & perks
  • Flexible hybrid working environment for office-based roles
  • Flexible work arrangements, including work from anywhere for up to 8 weeks per year
  • Flexible vacation
  • Two company-wide Mental Health Days off
  • Access to the Headspace app
  • Retirement savings
  • Tuition reimbursement
  • Employee incentive programs
  • Resources for mental, physical, and financial wellbeing
  • Two paid volunteer days off annually
  • Opportunities to participate in pro-bono consulting projects and ESG initiatives
  • Career development, continuous learning, and skills development through Grow My Way programming
  • Flexible work-life balance policies through Flex My Way