Sr. Software Engineer - Source Control and Governance

Weights & Biases Weights & Biases · Data AI · Bellevue, WA +3 · Technology

Software Engineer role focused on designing and building tooling and automation for source control and governance within an AI compute platform. The role involves working with compliance frameworks (SOC 2, SOX, ISO 27001), writing policy-as-code, building compliance pipelines, integrating security scanning, and automating evidence collection to ensure the platform is compliant, secure, and audit-ready for enterprise customers.

What you'd actually do

  1. Design and build automated compliance pipelines that enforce policies on infrastructure changes and compute provisioning, bringing a CI/CD-driven approach to governance workflows.
  2. Implement policy-as-code using tools like OPA/Rego, Conftest, or InSpec — ensuring compliance rules are version-controlled, peer-reviewed, and enforced automatically across environments.
  3. Automate audit evidence collection for SOC 2, SOX, and ISO 27001, replacing manual processes with continuous pipelines that produce timestamped, immutable artifacts.
  4. Build and maintain compliance dashboards and reporting to surface posture scores and framework coverage for internal stakeholders and customers.

Skills

Required

  • 7+ years of software engineering experience
  • Go or Python
  • CI/CD pipelines
  • Linux systems
  • networking fundamentals

Nice to have

  • policy-as-code tools (OPA/Rego, Sentinel, Checkov, InSpec)
  • compliance frameworks (SOC 2, SOX, ISO 27001, or NIST CSF)
  • cloud infrastructure
  • bare metal
  • compute platform environments

What the JD emphasized

  • SOC 2
  • SOX
  • ISO 27001