About us For institutions Press Login Meanwhile
Senior Software Engineer - Platform, GRC
Full-time · Engineering · San Francisco, CA (3 days/week in office)
An engineer to own our governance, risk and compliance layer - KYC, KYB and KYT vendor orchestration, built on our own authoritative profiles of the people and entities we do business with.
Every customer, broker, and counterparty who touches our platform has to be identified, screened, risk-rated, and monitored - across jurisdictions, across entity types, and in a Bitcoin-denominated product where the transaction side of the question is genuinely novel. We are building the governance, risk, and compliance layer that makes those decisions, records why they were made, and can defend them to a regulator years later.
You’ll own that layer. That means integrating and orchestrating our GRC vendors - KYC, KYB, and KYT - and building Meanwhile’s own authoritative profiles for natural persons and legal entities underneath them. Vendors come and go, change their schemas, disagree with each other, and return results that need adjudication. Our internal model of who someone is, what we know about them, when we learned it, and what decision we made as a result has to outlive any one of them.
This is a specialized, hands‑on engineering role working directly with our compliance and risk functions. It’s deep, precise work with real consequences: these systems are what our license depends on.
We’re looking for someone who wants to go deep here as an individual contributor—the person who understands the compliance core of the platform better than anyone else and owns it.
What You’ll Do
- Integrate and orchestrate GRC vendors - KYC (natural persons), KYB (entities and beneficial ownership), KYT (transaction monitoring and blockchain analytics) - behind interfaces that keep us portable rather than locked in
- Design and build Meanwhile’s internal data model for natural persons and legal entities: identity attributes, documents, ownership and control structures, relationships, provenance, and effective dating
- Build the screening and decisioning pipeline - sanctions, PEP, adverse media, risk scoring, ongoing and perpetual monitoring, re‑screening on change
- Adjudicate conflicting vendor signals: entity resolution, match and false‑positive handling, confidence and review thresholds
- Build the case management, audit trail, and evidence surfaces our compliance team and auditors work from—every decision reproducible, with the inputs it was made on
- Work directly with compliance, risk, and legal to turn regulatory obligation into working systems, and to tell them when what they’ve asked for won’t hold up technically
- Write production code across the stack (Python backend, PostgreSQL, React/TypeScript frontend)
- Use AI tooling to move faster, with the judgment to know when its output needs a second look
- Participate in business‑hours on‑call rotation shared across the engineering team (no nights/weekends)
How We Work
We don’t have product managers. You’ll work with the compliance and risk teams directly to understand the obligation, shape the solution, and explain the tradeoffs— that discovery is part of the job, not something that happens before it reaches you.
We lean into AI tooling and you’ll have it. It’s a real accelerant here, and we expect you to use it well. But compliance systems fail quietly—a screening rule that silently stops firing looks exactly like a clean book until an examiner asks—so the work still rests on thinking carefully about the problem, the data model, and the failure modes.
Qualifications
Required
- 8+ years of professional software engineering experience
- Direct experience building or operating GRC systems— KYC/KYB onboarding, AML and sanctions screening, transaction monitoring, or regulatory case management
- Strong Python and relational database experience, with real data modeling depth in PostgreSQL or equivalent— normalization, temporal and bitemporal data, referential integrity, migrations against live data
- Experience integrating third‑party vendor APIs where the vendor is unreliable, the schema is theirs, and the result still has to be correct and auditable
- Experience working directly with non‑technical domain experts— compliance officers, risk teams, auditors, regulators—and turning their obligations into software
- Fluency with AI development tools, and the judgment to evaluate what they produce
- Comfort with ambiguity and a habit of teaching yourself the domain
- Low‑ego approach and a high bar for precision
- Based in the SF Bay Area with the ability to work in‑office 3 days per week
What Makes You Stand Out
- Experience with blockchain analytics and crypto transaction monitoring (Chainalysis, TRM, Elliptic, or similar) and the specific problems Bitcoin creates for KYT
- Multi‑jurisdiction compliance experience, and familiarity with insurance or banking regulators (BMA, FinCEN, FCA, or equivalent)
- Entity resolution, beneficial ownership modeling, or identity graph work at scale
- Experience supporting an examination, audit, or control framework (SOC 2, ISO 27001) with system‑generated evidence
- Insurance domain exposure, or experience at a licensed financial institution
- Startup experience on small engineering teams (<10 people)
Technical Environment
- Backend: Python
- Database: PostgreSQL
- Frontend: React/TypeScript
- CI/CD: GitHub Actions
- Cloud: AWS
Why Join Us?
- A problem with a right answer: Compliance is unforgiving, and building systems that hold up under examination is genuinely satisfying work
- Real Ownership: You’ll own the GRC layer—the system that decides