Principal Software Engineer, Security & Compliance

Reposted 5 Days Ago
Be an Early Applicant
Zug, CHE
Hybrid
Senior level
Information Technology
The Role
Lead architecture and engineering for compliance and security across an AI legal product. Design controls for SOC 2, ISO, HIPAA, and FedRAMP, implement compliance-as-code, architect encryption/key management and tenant isolation, build observability and incident response for compliance-critical systems, and partner with security, legal, and product teams while mentoring engineers.
Summary Generated by Built In

CoCounsel is our most advanced AI offering to date — combining generative and agentic AI capabilities to help legal professionals move beyond prompting and start delegating. As a Principal Software Engineer focused on Security & Compliance, you will set the technical direction for how CoCounsel earns and maintains the trust of law firms, corporate legal departments, and government agencies that rely on us with privileged, sensitive, and regulated data every day. You will own the architecture and engineering practices behind our SOC 2, ISO 27001/42001, HIPAA, and FedRAMP programs, turning compliance requirements into resilient, well-instrumented systems rather than one-off audit exercises.

This role sits at the intersection of the CoCounsel Legal engineering organization and our security, privacy, and legal/compliance teams, partnering closely with platform, identity, and AI/ML engineering to deliver world-class, provably trustworthy legal AI experiences at scale.

About the role:

  • Own the compliance architecture: Understand and evolve the technical controls that satisfy the landscape of compliance; including but not limited to SOC 2 Type II, ISO 27001/42001, HIPAA, and FedRAMP (Moderate/High) requirements across CoCounsel's infrastructure, data pipelines, and AI systems. Work to understand implications of new compliance and/or certifications.  Your decisions will shape how every product line proves trust to customers and auditors.

  • Build compliance as code: Look to help make the manual better, determine where point-in-time audit prep can be replaced with automated evidence collection, continuous control monitoring, and policy-as-code so that compliance state is observable and provable at any time, not just during an audit window.

  • Engineer for real production scale and sensitivity: Design encryption, key management, data residency, tenant isolation, and audit logging for systems handling millions of privileged legal documents and thousands of concurrent AI interactions from professionals doing time-sensitive work.

  • Technical leadership and cross-functional influence: Partner with Security, Legal, Privacy, and Product to translate regulatory and contractual requirements (customer security questionnaires, DPAs, government agency requirements) into engineering roadmaps. Mentor staff and senior engineers, raising the bar on secure-by-design development, threat modeling, and incident response across the org.

  • Reliability and assurance: Establish SLOs, observability, and incident response practices for compliance-critical systems, and build the internal tooling (dashboards, alerting, control testing) that gives engineering, security, and leadership real-time confidence in our control environment.

About You:

You are a fit for the position of Principal Software Engineer, Security & Compliance if your background includes:

  • Bachelor's Degree in Computer Science, Computer Engineering, a related field, or equivalent experience.

  • Direct, hands-on experience building or operating production systems that achieved and maintained SOC 2 Type II, ISO 27001 (and/or 42001), and HIPAA compliance — not just reading about it in a policy document.

  • Experience supporting a FedRAMP authorization process (SSP development, control implementation, 3PAO assessments, or ConMon) at the Moderate or High baseline.

  • Deep backend engineering expertise (Python, Java, Go, or similar) and experience with production systems on a major cloud provider (AWS preferred), including how to implement controls natively in cloud infrastructure rather than bolt them on.

  • Working knowledge of security control frameworks such as NIST 800-53, NIST CSF, or CIS Benchmarks, and the ability to map technical implementation to specific control requirements.

  • Hands-on experience with identity and access management — authentication and authorization at scale (SSO, SAML, OIDC, OAuth 2.0, RBAC/ABAC), encryption and key management, and audit logging.

  • Proven track record owning large, complex compliance or security initiatives end-to-end: architecture, execution, audit readiness, and long-term operation.

  • Excellent communication skills and the ability to partner with auditors, security, legal, product, and engineering teams in a fast-moving environment.

Preferred Skills & Experience:

  • Experience achieving or maintaining a FedRAMP ATO with JAB or agency sponsorship, including direct interaction with 3PAOs and federal agency security teams.

  • Experience with GRC and compliance automation tooling (e.g., Vanta, Drata, OneTrust, or comparable platforms) and building custom evidence-collection pipelines where off-the-shelf tools fall short.

  • Experience in regulated industries handling sensitive data — legal, healthcare, financial services, or government.

  • Relevant certifications such as CISSP, CISM, CCSP, or similar.

  • Experience building compliance and security controls for AI/LLM systems specifically — model access controls, prompt/response data handling, and safeguards around sensitive or privileged content.

#LI-IG1




What’s in it For You?

  • Hybrid Work Model: We’ve adopted a flexible hybrid working environment for our office-based roles while delivering a seamless experience that is digitally and physically connected.
  • Flexibility & Work-Life Balance: Flex My Way is a set of supportive workplace policies designed to help manage personal and professional responsibilities, whether caring for family, giving back to the community, or finding time to refresh and reset. This builds upon our flexible work arrangements, including work from anywhere for up to 8 weeks per year, empowering employees to achieve a better work-life balance.
  • Career Development and Growth: By fostering a culture of continuous learning and skill development, we prepare our talent to tackle tomorrow’s challenges and deliver real-world solutions. Our Grow My Way programming and skills-first approach ensures you have the tools and knowledge to grow, lead, and thrive in an AI-enabled future.
  • Industry Competitive Benefits: We offer comprehensive benefit plans to include flexible vacation, two company-wide Mental Health Days off, access to the Headspace app, retirement savings, tuition reimbursement, employee incentive programs, and resources for mental, physical, and financial wellbeing.
  • Culture: Globally recognized, award-winning reputation for inclusion and belonging, flexibility, work-life balance, and more. We live by our values: Obsess over our Customers, Compete to Win, Challenge (Y)our Thinking, Act Fast / Learn Fast, and Stronger Together.
  • Social Impact: Make an impact in your community with our Social Impact Institute. We offer employees two paid volunteer days off annually and opportunities to get involved with pro-bono consulting projects and Environmental, Social, and Governance (ESG) initiatives.
  • Making a Real-World Impact: We are one of the few companies globally that helps its customers pursue justice, truth, and transparency. Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.

DISCLAIMER

The above information in this description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.




About Us

Thomson Reuters informs the way forward by bringing together the trusted content and technology that people and organizations need to make the right decisions. We serve professionals across legal, tax, accounting, compliance, government, and media. Our products combine highly specialized software and insights to empower professionals with the data, intelligence, and solutions needed to make informed decisions, and to help institutions in their pursuit of justice, truth, and transparency. Reuters, part of Thomson Reuters, is a world leading provider of trusted journalism and news.

We are powered by the talents of 26,000 employees across more than 70 countries, where everyone has a chance to contribute and grow professionally in flexible work environments. At a time when objectivity, accuracy, fairness, and transparency are under attack, we consider it our duty to pursue them. Sound exciting? Join us and help shape the industries that move society forward.

As a global business, we rely on the unique backgrounds, perspectives, and experiences of all employees to deliver on our business goals. To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex/gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law. Thomson Reuters is proud to be an Equal Employment Opportunity Employer providing a drug-free workplace.

We also make reasonable accommodations for qualified individuals with disabilities and for sincerely held religious beliefs in accordance with applicable law. More information on requesting an accommodation here.

Learn more on how to protect yourself from fraudulent job postings here.

More information about Thomson Reuters can be found on thomsonreuters.com

Skills Required

  • Bachelor's degree in Computer Science, Computer Engineering, or equivalent experience
  • Direct, hands-on experience building or operating production systems that achieved and maintained SOC 2 Type II, ISO 27001/42001, and HIPAA compliance
  • Experience supporting a FedRAMP authorization process (SSP development, control implementation, 3PAO assessments, ConMon) at Moderate or High baseline
  • Deep backend engineering expertise (Python, Java, Go or similar) and experience with production systems on a major cloud provider (AWS preferred)
  • Working knowledge of security control frameworks (NIST 800-53, NIST CSF, CIS Benchmarks) and ability to map implementations to controls
  • Hands-on experience with identity and access management (SSO, SAML, OIDC, OAuth 2.0, RBAC/ABAC), encryption and key management, and audit logging
  • Proven track record owning large, complex compliance or security initiatives end-to-end (architecture, execution, audit readiness, operation)
  • Excellent communication skills and ability to partner with auditors, security, legal, product, and engineering teams
  • Experience achieving or maintaining a FedRAMP ATO with JAB or agency sponsorship, including interaction with 3PAOs and federal agency security teams
  • Experience with GRC and compliance automation tooling (Vanta, Drata, OneTrust) and building custom evidence-collection pipelines
  • Experience in regulated industries handling sensitive data (legal, healthcare, financial services, or government)
  • Relevant certifications such as CISSP, CISM, CCSP, or similar
  • Experience building compliance and security controls for AI/LLM systems (model access controls, prompt/response handling, safeguards for privileged content)

Thomson Reuters Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Thomson Reuters and has not been reviewed or approved by Thomson Reuters.

  • Flexible Benefits Flexible work options such as hybrid schedules and “Flex My Way” with Work From Anywhere allowances (including limited weeks abroad) are offered and positioned to support work-life balance. Feedback suggests policy-backed flexibility is a notable strength even though application can vary by role and manager.
  • Leave & Time Off Breadth Generous paid time off, enhanced bereavement, caregiver leave, two global mental-health days, and a sabbatical program expand time-away options. Paid parental leave is explicitly highlighted, with a global minimum described at 16 weeks.
  • Healthcare Strength Comprehensive medical, dental, and vision coverage is paired with wellbeing resources such as EAP, mental-health tools, and fitness/wellbeing programs. FSAs/HSAs and related health benefits reinforce the depth of the healthcare offering.

Thomson Reuters Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Toronto, Ontario
33,822 Employees
Year Founded: 2008

What We Do

Thomson Reuters (NYSE / TSX: TRI) informs the way forward by bringing together the trusted content and technology that people and organizations need to make the right decisions. The company serves professionals across legal, tax, accounting, compliance, government, and media. Its products combine highly specialized software and insights to empower professionals with the data, intelligence, and solutions needed to make informed decisions, and to help institutions in their pursuit of justice, truth and transparency. Reuters, part of Thomson Reuters, is a world leading provider of trusted journalism and news. For more information, visit tr.com.

Similar Jobs

Pfizer Logo Pfizer

Sustainability Senior Manager

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote or Hybrid
30 Locations
121990 Employees
112K-207K Annually

Celonis Logo Celonis

Account Executive

Big Data • Information Technology • Productivity • Software • Analytics • Business Intelligence • Consulting
Remote or Hybrid
Switzerland
3000 Employees

Zscaler Logo Zscaler

Commercial Account Executive

Cloud • Information Technology • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
Switzerland
8697 Employees

Pfizer Logo Pfizer

Sr. Director, Product Intelligence & Marketing Lead

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
30 Locations
121990 Employees
215K-358K Annually

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account