Senior Software Engineer, AI Governance

🏢 Natera · all 87 jobs
📍 US Remote
📅 Posted Sep 23, 2026 · via Greenhouse
Apply on original site ↗

ABOUT THE ROLE

Natera is deploying AI into clinical, diagnostic, and patient-facing workflows at scale. As that portfolio grows, AI governance infrastructure has to be real: working controls embedded in the platform, automated risk intake, runtime policy enforcement, and production monitoring that catches drift before it becomes an incident. This role builds that infrastructure.

This role is a software engineering role. You will design, build, and operate the technical systems that make AI governance work at Natera: guardrails in the LLM Gateway, PHI/PII detection in the RAG infrastructure, automated risk scoring in the intake pipeline, observability dashboards, and incident response tooling. You translate frameworks like NIST AI RMF, CHAI, and ISO 42001 into platform controls, not policy documents. Roughly 75% of your time is engineering work. The remaining 25% is the process and cross-functional work that gives the engineering its direction.

You report to the Head of AI & Data Governance. You work hands-on with platform engineers, Legal, Privacy, RAQA, and business teams. The job is to make AI governance a platform capability, not a committee function.

WHAT YOU'LL DO

Build governance controls into the AI platform

- Design, build, and own the guardrail layer inside Natera's LLM Gateway: content filtering, output validation, PHI/PII detection, prompt injection defenses, session retention, and audit logging. You write the code; you own the component.

- Engineer the governance layer for Natera's agentic runtime and RAG infrastructure: policy enforcement hooks, output routing by risk tier, retrieval filtering, citation integrity checks, and PHI exposure prevention.

- Ensure every control is instrumented with observability from day one: what is filtering, what is flagging, what is escalating, and what is drifting from its approved risk profile. Governance without observability is not governance.

- Ensure every AI platform control meets HIPAA, RAQA, and Natera's data classification requirements at design time. Retrofitting after deployment is not an option.

- Build governance as a runtime capability: the platform enforces policy; you define what that policy is, implement it, and verify it works under real conditions.

Build the automated risk intake and monitoring systems

- Design and implement the automated AI risk intake pipeline: structured intake form, automated risk scoring, tiering (Low / Medium / High / Critical), and routing to the right review path, aligned to NIST AI RMF, CHAI, and the EU AI Act.

- Build and maintain the AI Risk Register as an engineering artifact: risk scores, treatment decisions, mitigation steps, and review history, queryable and auditable.

- Define and build the monitoring systems for every production AI use case: accuracy tracking, drift detection, misuse alerting, and escalation thresholds. These must be instrumented and verified before go-live, not documented and hoped for.

- Build and maintain the AI incident response tooling: automated detection, alert routing, decision logging, and remediation tracking.

Run the risk assessment and governance review process

- Run the AI use-case intake process end to end: evaluate every new use case against the risk tiering model before it gets built or deployed, using the automated systems you built.

- Facilitate high-risk use-case reviews with the AI Governance Board (Legal, Privacy, RAQA) and produce clear, time-bound recommendations and controls. Flagging the problem is not enough.

- Keep the risk questionnaire, scoring rubric, and tiering criteria current as the AI portfolio scales and applicable frameworks, regulations, and internal policies change.

Gate what gets bought or integrated

- Own the technical due diligence process for AI vendors and foundation model providers: evaluate data residency, model transparency, API security, contractual controls, and regulatory alignment before any external AI system con

Flights + hotels

This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels →

← All remote jobs

Comparing Software Engineer pay and openings — the live median is $130k?All remote Software Engineer jobs →Software Engineer salary data →
Get new remote jobs like this by email
Daily email, only when there's something new. One click to stop.

Get remote jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you