Staff Platform Engineer - Security
Norm AiAbout the role
About Norm Ai
Norm Ai is the Compliance AI Platform for legal standards-based reasoning & workflow automation.
We developed the first Domain Specific Language (DSL) for fully representing regulatory requirements in AI code. This DSL, deployed with our enterprise platform, enables Norm clients to transform workflows and apply compliance checks at the source of business activities.
We are setting the norms for compliance processes at the largest institutions in the world. Our client base includes firms with a combined $17 Trillion in AUM, and growing quickly.
Our Software Engineers came from Palantir, Google, Meta, AWS, Harvard, Stanford, and MIT. Our Legal Engineers are from Harvard Law, Stanford Law, Yale Law, Sullivan & Cromwell, Simpson Thacher, Davis Polk, Greenberg Traurig, the SEC, and FINRA.
We have raised $85 million over the past 18 months from top VCs and global institutions, including Vanguard, Blackstone, Bain Capital, Coatue, Craft Ventures, New York Life, Citi, TIAA, and Marc Benioff.
This Role
As a Security Engineer on the Platform team at Norm Ai, you will architect and build the security foundation for our AI-driven compliance platform. You'll work at the intersection of product security, infrastructure protection, and AI safety, building foundational security services that enable both our platform reliability and our engineering teams' velocity. You will define, build, and own the authentication and authorization posture that protects our entire ecosystem: our core multi-tenant platform and our growing number of isolated, single-tenant customer deployments. You'll have significant input into our security architecture and the freedom to propose and implement security improvements across our entire technology stack.
Our customers depend on us to deliver a secure, trustworthy, and compliant platform for managing regulatory requirements. Earning and maintaining the trust of the world's largest institutions is paramount to our success.
You Will:
Design and implement (and improve on) core security services such as secure authentication systems, access control frameworks, and data protection mechanisms for our AI-driven compliance platform
Build secure-by-default libraries and tools that make the secure path the easiest and most attractive choice for developers
Review security-critical code and own key security components, including authentication, access control, and data protection systems
Contribute meaningfully to the Norm AI codebase, focusing on security enhancements for our DSL execution engine and compliance workflows
Create comprehensive security monitoring and alerting systems to provide visibility into the health and security posture of our infrastructure
Audit the existing codebase for vulnerabilities, particularly in our LLM client and customer data handling
Improve our static analysis and vulnerability management tooling
Conduct red team exercises and penetration testing to identify security gaps
Participate in and drive mitigation strategies during security-related incident responses
Partner closely with engineering teams to incorporate secure design principles at every stage of development
Mentor other engineers on security best practices and secure development methodologies
Skills & Experience - Core
4+ years of experience in product security, application security, offensive security, and/or security-focused software engineering
Strong proficiency in developing secure cloud-native containerized applications in at least one programming language commonly used for backend development, although Python experience is preferred
Demonstrated experience writing high-quality software and raising the quality bar of software engineering teams
Proven ability to identify software vulnerabilities, demonstrated through CVEs, bug bounty awards, blog posts, or prior work experience
Track record of building reliable and scalable security systems and controls
Proficiency with data storage technologies such as PostgreSQL and Redis from a security perspective
Experience with observability and security monitoring tools such as Datadog or OpenTelemetry
Proficiency with at least one of the major cloud providers, preferably both AWS and Azure
Proficiency with Infrastructure as code tools, preferably Terraform
Strong communication and collaboration skills, particularly with engineering teams
Skills & Experience - Pluses
Experience in AI/ML infrastructure security and understanding AI safety consid
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s