Auf einen Blick
- Aufgaben: Entwickle Sicherheitslösungen für unsere fortschrittlichste KI-Plattform und forme die Compliance-Strategie.
- Unternehmen: Innovatives Unternehmen im Bereich KI mit einem Fokus auf Sicherheit und Compliance.
- Vorteile: Attraktives Gehalt, flexible Arbeitszeiten, Weiterbildungsmöglichkeiten und ein dynamisches Team.
- Weitere Informationen: Wachstumsorientierte Umgebung mit Möglichkeiten zur beruflichen Weiterentwicklung.
- Warum dieser Job: Gestalte die Zukunft der Rechtsbranche mit modernster Technologie und baue Vertrauen auf.
- Qualifikationen: Erfahrung in der Softwareentwicklung und Kenntnisse in Sicherheitsstandards wie SOC 2 und ISO 27001.
Das prognostizierte Gehalt liegt zwischen 63000 - 77000 € pro Jahr.
Co Counsel is our most advanced AI offering to date — combining generative and agentic AI capabilities to help legal professionals move beyond prompting and start delegating.
As a Principal Software Engineer focused on Security including but not limited to SOC 2 Type II, ISO 27001/42001, HIPAA, and Fed RAMP (Moderate/High) requirements across Co Counsel's infrastructure, data pipelines, and AI systems.
Work to understand implications of new compliance and/or certifications.
Your decisions will shape how every product line proves trust to customers and auditors.
Build compliance as code: Look to help make the manual better, determine where point-in-time audit prep can be replaced with automated evidence collection, continuous control monitoring, and policy-as-code so that compliance state is observable and provable at any time, not just during an audit window.
Engineer for real production scale and sensitivity: Design encryption, key management, data residency, tenant isolation, and audit logging for systems handling millions of privileged legal documents and thousands of concurrent AI interactions from professionals doing time-sensitive work.
Technical leadership and cross-functional influence: Partner with Security, Legal, Privacy, and Product to translate regulatory and contractual requirements (customer security questionnaires, DPAs, government agency requirements) into engineering roadmaps.
Mentor staff and senior engineers, raising the bar on secure-by-design development, threat modeling, and incident response across the org.
Reliability and assurance: Establish SLOs, observability, and incident response practices for compliance-critical systems, and build the internal tooling (dashboards, alerting, control testing) that gives engineering, security, and leadership real-time confidence in our control environment.
About
You: Bachelor's Degree in Computer Science, Computer Engineering, a related field, or equivalent experience.
Direct, hands‑on experience building or operating production systems that achieved and maintained SOC 2 Type II, ISO 27001 (and/or 42001), and HIPAA compliance — not just reading about it in a policy document.
Experience supporting a Fed RAMP authorization process (SSP development, control implementation, 3PAO assessments, or Con Mon) at the Moderate or High baseline.
Deep backend engineering expertise (Python, Java, Go, or similar) and experience with production systems on a major cloud provider (AWS preferred), including how to implement controls natively in cloud infrastructure rather than bolt them on.
Working knowledge of security control frameworks such as NIST 800-53, NIST CSF, or CIS Benchmarks, and the ability to map technical implementation to specific control requirements.
Hands-on experience with identity and access management — authentication and authorization at scale (SSO, SAML, OIDC, OAuth 2.0, RBAC/ABAC), encryption and key management, and audit logging.
Proven track record owning large, complex compliance or security initiatives end-to-end: architecture, execution, audit readiness, and long-term operation.
Excellent communication skills and the ability to partner with auditors, security, legal, product, and engineering teams in a fast-moving environment.
Preferred Skills
Principal Software Engineer, Security & Compliance Arbeitgeber: PowerToFly
Stryker ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern nicht nur ein spannendes Trainee-Programm im Bereich Endoskopie/Visualisierung bietet, sondern auch eine dynamische Arbeitsumgebung, die auf Teamarbeit und persönliche Entwicklung setzt. Mit der Möglichkeit, an bedeutenden medizinischen Veranstaltungen teilzunehmen und wertvolle Erfahrungen im Vertrieb zu sammeln, fördert Stryker aktiv das Wachstum seiner Mitarbeiter und bietet flexible Arbeitsmodelle, einschließlich Home-Office. Die Unternehmenskultur ist geprägt von Innovation und einem starken Fokus auf die Verbesserung der Gesundheitsversorgung, was die Arbeit hier besonders erfüllend macht.