Job Openings Software Engineer (EU) - GDPR/CCPA

About the job Software Engineer (EU) - GDPR/CCPA

Our client is a fast-growing B2B SaaS company hiring a backend engineer to own its data deletion and suppression pipeline — the system that handles privacy requests end to end, from any channel, at scale.

Your first major milestone: building and shipping a new system to handle DROP (California privacy deletion requests). Beyond that, you'll own compliance tooling for GDPR, CCPA, and whatever regulations come next.

This is not a role where "move fast and break things" applies. A mistake in a regular feature means a bug in production; a mistake here can mean a lawsuit. We're looking for someone who takes correctness seriously and treats this responsibility with the weight it deserves.

What You'll Do

  • Own the privacy request pipeline end to end: data deletion, suppression, and audit across all channels
  • Design compliance workflows that scale with evolving regulations (GDPR, CCPA, and future frameworks)
  • Work with large, business-critical databases containing high volumes of records
  • Write thoroughly tested, verifiable code — testing discipline is a core part of this job, not an afterthought

What We're Looking For

Must have:

  • 5 years of backend engineering experience with Node.js and Python
  • At least 2 years of experience working with Data Privacy work (GDPR, CCPA)
  • Hands-on experience with NoSQL databases (e.g., MongoDB, Elasticsearch)
  • Comfort working with data at scale — large databases with high record counts
  • A correctness-first mindset: careful, rigorous, and serious about getting things right the first time
  • Strong testing habits — you verify your work before it ships

Nice to have:

  • Elasticsearch experience specifically (deep indexing expertise not required — you can learn the specifics on the job if you know NoSQL fundamentals)
  • Some data engineering exposure
  • Prior experience with privacy/compliance systems (GDPR, CCPA, data subject requests)

Not required:

  • Frontend or accessibility work — this role is purely about the data side of privacy compliance (deletion pipelines, suppression, cookies/consent data), not UI

Why This Role Matters

Privacy regulation is only expanding, and this system sits directly in the path of legal risk. It's a role with clear ownership, real stakes, and visible impact — and a well-scoped technical domain where doing careful, high-quality work is genuinely valued over raw speed.