About the role
You own the consent layer, which is the thing the entire company rests on. Every access leaves a receipt, every grant is per-field and revocable, and none of that is true because we said so. It is true because you build it that way and then try to break it. We are pursuing FedRAMP High and DoD Impact Levels, so this work is measured against NIST 800-53 rather than against good intentions.
What we need to see
- Security or applied-cryptography engineering, in production rather than in theory
- Authentication, authorisation, and key management designed for least privilege
- You think like an attacker and document like an auditor, and can show examples of both
- You can turn a control framework into engineering work other people can execute
Nice to have
- FedRAMP, SOC 2, or NIST 800-53 experience
- Consent, privacy engineering, or data-rights work
- Published research, CVEs, or a bug-bounty record
What winning looks like
- Consent receipts verifiable and complete for every exchange
- Time-to-remediate findings; zero criticals open
- Progress on the FedRAMP/SOC 2 control map
Where and how we work
In the office together five days a week, in any of these cities. Remote-friendly around your family, arranged one person at a time.