Guidehouse is a company specializing in Cyber Engineering, and they are seeking a Senior Full-Stack Security/GRC Platform Engineer to maintain and extend a large full-stack Governance, Risk, and Compliance platform. The role involves working across backend services, frontend workflows, database migrations, and security controls, while also ensuring the quality and integrity of the platform.
Responsibilities:
- Maintain and extend a FastAPI backend with hundreds of registered API routes
- Build and refine React/TypeScript product workflows across a large frontend surface
- Design and maintain SQLAlchemy models, Alembic migrations, PostgreSQL queries, and data integrity rules
- Support scanner integrations, finding normalization, deduplication, evidence workflows, and compliance mapping
- Maintain AI-assisted features through a centralized provider abstraction rather than direct calls to providers
- Work across GRC workflows including findings, evidence, SSPs, POA&Ms, RMF, FedRAMP/FISMA, SCRM, ZTA, ISCM, risk acceptance, and reporting
- Keep local development and test environments healthy using Docker Compose, Redis, PostgreSQL, worker queues, Ollama, observability services, and frontend tooling
- Maintain quality gates including linting, type checking, OpenAPI drift checks, migration safety, SDK drift, architecture boundaries, and test suites
- Debug issues across frontend state, API contracts, database state, workers, scanner output, generated SDKs, and deployment configuration
- Treat documentation as helpful but secondary to the codebase; validate assumptions against source, tests, migrations, and running behavior
Requirements:
- Minimum of SIX (6) years' experience with Python backend development
- Strong FastAPI, Pydantic, SQLAlchemy, Alembic, async Python, and pytest experience
- Strong React, TypeScript, Vite, React Router, React Query, and component architecture experience
- PostgreSQL experience, including schema design, migrations, indexes, JSON/JSONB, and relational integrity
- Experience maintaining large API surfaces and generated frontend API clients
- Experience with background jobs or async workers using Redis-backed queues
- Strong security engineering fundamentals: authentication, authorization, RBAC, audit logs, secret handling, dependency risk, and input validation
- Ability to diagnose source-of-truth issues when documentation, generated code, database schema, and runtime behavior disagree
- Vulnerability findings and remediation workflows
- Evidence collection and evidence sufficiency
- SSPs, POA&Ms, control mappings, audit packages, and risk acceptance
- NIST 800-53, RMF, FedRAMP/FISMA, CMMC, SCRM, ZTA, ISCM, and related compliance concepts
- Scanner output from tools such as cloud security scanners, vulnerability scanners, SAST/IaC tools, secret scanners, identity/M365 scanners, and web security scanners
- Provenance, auditability, and defensibility requirements for regulated workflows
- Experience building AI-assisted product features, preferably in security, compliance, document review, or workflow automation
- Understanding of RAG, embeddings, document extraction, prompt/context design, and evidence citation
- Ability to enforce scoped context, provenance, guardrails, and human-review boundaries
- Comfort maintaining provider abstractions across local and cloud AI providers
- Docker Compose for local development
- AWS-style production operations: containers, managed databases, caches, object storage, CDN, IAM, logs, and deployment pipelines
- Terraform or similar infrastructure-as-code experience
- CI/CD debugging and release discipline
- Observability, logs, health checks, and operational runbooks
- Prior experience with GRC, audit automation, security consulting tools, vulnerability management, FedRAMP/FISMA, or SSP/POA&M workflows
- Experience with generated OpenAPI SDKs
- Experience producing PDF, Excel, DOCX, PowerPoint, or audit package exports
- Experience with immutable audit logs, provenance chains, multi-tenant permissions, or evidence workflows