Senior Engineer / Tech Lead, Trust (Security, Privacy & Compliance) | GovTech

Atomic HR•Miami, FL
•$14,583 - $17,500•Remote

About The Position

Our client is a venture-backed govtech startup that helps families find the benefit programs they qualify for, apply to several at once and stay enrolled as rules change. State agencies, Medicaid managed care organizations and employers pay for the platform. It now runs eligibility checks and applications across federal, state and local programs. Its customers are highly regulated, so security and privacy shape how the team builds. The team is small and fully remote across the U.S. This is not a "review and advise" security role. You build the controls yourself. State and federal buyers are asking for stricter security standards. Security and privacy are now core parts of the platform, not side projects. You'll be the senior engineer and tech lead for the platform's security, privacy and compliance controls, and the technical partner to the Trust Product Manager. The PM owns requirements, governance and the roadmap. You own the architecture and the working systems. You'll start with the engineering behind the existing SOC 2 Type II and HIPAA controls. Recurring manual work like access reviews and evidence collection moves into code. Then you'll lead the technical side of the company's NIST 800-series alignment.

Requirements

  • 7+ years of software engineering, including a few years as the senior or lead engineer on production systems.
  • You've committed application and infrastructure code yourself in the last year or two.
  • Hands-on SOC 2 Type II and HIPAA experience: controls you implemented and ran through an audit, and a system holding protected health information that you built or operated.
  • Cloud-native production experience, ideally on AWS, including infrastructure as code, CI/CD pipelines with approval steps, and environments you set up yourself.
  • Identity and access systems you designed: authentication, role- or attribute-based authorization, service identities, secrets management, production access controls and audit logging.
  • Threat modeling carried through to shipped controls, and audit, pen-test or incident findings you closed yourself.
  • Good judgment on what to enforce in software and what to leave as a process, and the ability to explain that trade-off to a product lead, an auditor and an engineer.
  • Comfort working autonomously while the architecture and operating model are still taking shape.
  • You must be based in the U.S.

Nice To Haves

  • NIST 800-53 or other 800-series controls you mapped to real system changes
  • FedRAMP or ISO 27001 experience, even on one part of a system
  • Automated evidence collection or continuous control monitoring that an auditor accepted
  • Incident-response runbooks you wrote, or a tabletop exercise you ran
  • Node, TypeScript and AWS in the same production environment
  • Software built for government, healthcare or fintech customers

Responsibilities

  • Design how people and services sign in, what each role is allowed to do, and where secrets are stored.
  • Decide how engineers get into production and who approves that access.
  • Write the design and the code, and agree on the requirements with the Trust PM.
  • Keep environments, tenants, workloads and sensitive data separate from each other.
  • Build audit logs and change history that show who did what, in a form outside auditors can test.
  • Keep the technical controls working, and move access reviews and evidence pulls from manual steps into code.
  • Take every technical audit finding through to closure, and work with auditors on their tests.
  • Build the release path in CI/CD and infrastructure as code, with approvals before anything reaches production.
  • Publish shared modules and reference implementations so other teams get the controls by default.
  • Run threat models on critical workflows and turn each finding into an engineering requirement.
  • Review security-sensitive code, infrastructure and architecture changes before they go live.
  • Own logging, detection, runbooks and escalation paths on the engineering side.
  • Lead or support investigation and containment when an incident happens, and join tabletop exercises with the PM and leadership.
  • With the PM, translate NIST requirements into controls and priorities.
  • Give leadership a technical roadmap for state and federal environments, moving toward FedRAMP-aligned practices where they apply.

Benefits

  • A fully remote role within the U.S.
  • $14,583–$17,500 USD/month, depending on experience
  • Full-time employment through an Employer of Record (EOR)
  • Real technical ownership: the design decisions, and the order in which controls get built, are yours
  • Direct collaboration with Product & Engineering leadership in a small, fast-growing team
  • Mission-driven impact: your work protects the data of families who rely on public benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service