Senior Product Engineer
Job description
About the role
You will own the end-to-end enterprise trust and security lifecycle for Orbital Copilot, ensuring that every deliverable from the trust center to architecture diagrams remains accurate and actionable for enterprise customers. You will act as the critical translation layer between deep technical security controls and the procurement, legal, and IT stakeholders who need to understand and act on them without misrepresentation. You will get hands-on with foundational security levers such as data residency, BYOK and key management, multi-tenancy, SSO/SCIM, audit and retention, and subprocessor oversight in partnership with engineering. You will define and own the AI-specific trust primitives including data retention scope, no-training evidence, model inventory, and the governance of how AI agents operate and are audited within our platform. You will drive the delivery of enterprise readiness features like admin controls, audit logging, retention and purge tooling, regional hosting options, and connector permissions that make security scalable. You will convert ad hoc security questionnaires into reusable templates and turn recurring risk questions into shipped product features so that trust processes no longer block deal flow. You will collaborate directly with sales, customer success, legal teams, and our external infosec partners to resolve enterprise security blockers and accelerate high-value deals. You will take end-to-end ownership of enterprise readiness for both new and existing customers, ensuring trust and security continuously evolve as the product and customer base scale.
Key facts
What you'll do
- Own our enterprise trust and security surface as a living product, maintaining the trust center, DDQ responses, security one-pagers, architecture diagrams, and bridge letters that are accurate and ready from day one of any deal.
- Translate complex technical security answers into clear language that procurement, legal, and IT teams can act on, while ensuring we never overstate what the product does or can guarantee.
- Get hands-on with the architecture decisions that underpin enterprise trust, including data residency requirements, BYOK and key management strategies, multi-tenancy guarantees, SSO and SCIM implementation, audit and retention policies, subprocessor management, and our SOC 2 and ISO 27001 posture.
- Own the AI-specific side of enterprise trust, defining data retention scope, providing no-training evidence, maintaining a current model inventory, and specifying what our AI agents are permitted to do and how their actions are audited and monitored.
- Ship the features that make enterprise readiness real and measurable, such as admin controls, comprehensive audit logging, retention and purge tooling, regional hosting options, and fine-grained connector permissions.
- Turn one-off security questionnaires and compliance artifacts into reusable assets, and convert recurring security questions into shipped product features so that security stops becoming a bottleneck for every deal.
- Work directly with sales, customer success, legal, and our external infosec partner to resolve blockers and move enterprise deals forward efficiently and securely.
- Own enterprise readiness across new business acquisition and existing customer renewals or expansions, ensuring trust and security evolve as customer needs and regulatory landscapes change.
Requirements
- A hands-on builder who has personally shipped product features into production, not just documentation or policy, demonstrating an ability to deliver tangible outcomes.
- Real experience engaging in enterprise security conversations, such as sitting opposite a customer's IT or security team on a live deal, or having owned at least one security blocker from identification to resolution.
- Working fluency in core enterprise security domains including data residency, encryption and key management, SSO, audit and retention practices, and security certifications such as SOC 2 and ISO 27001 or equivalent, deep enough to make architecture decisions alongside engineers.
- A clear point of view on how AI agents change security and trust, ideally backed by hands-on use of AI or agent tooling in your own work on products or platforms.
- B2B software experience selling into large organizations, with regulated industries such as legal, finance, or insurance noted as a plus but not required for eligibility.
- A track record of turning one-off problems into reusable systems and processes, rather than applying repeated manual fixes each time an issue arises.
- Comfort operating with autonomy and without direct authority over the people you depend on to unblock security and trust challenges in cross-functional settings.
- Commitment to maintaining the strong culture of security and compliance at Orbital, understanding that security is everyone's responsibility and aligning with practices such as security awareness training and careful handling of sensitive data in line with ISO 27001 standards.
Practical notes
LENGTH: 700-900 words. No HTML, no markdown, no em dashes.
Output the page only.