Granicus

Principal Software Architect - Emerging Technologies

Granicus$175K — $206K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in distributed systems and CI/CD pipelines.
  • Expertise in security architecture, including least-privilege design and secrets management.
  • Hands-on experience with LLM agents in production, including orchestration and evaluation.
  • Demonstrated ability to set engineering standards for others to follow.
  • Knowledge of NIST 800-53 Rev 5 and mapping controls to engineering requirements.
  • Ability to balance accountability without becoming a bottleneck in processes.

Responsibilities

  • Own the generator-verifier architecture and establish quality assurance for agent outputs.
  • Define secure agent orchestration patterns and management of state and credential handling.
  • Build and manage CI/CD processes tailored for high-volume autonomous pull requests.
  • Establish eval-driven development practices for objective validation of code changes.
  • Maintain security boundaries and ensure compliance standards are met within the architecture.
  • Serve as the final gatekeeper for agent-generated code merges, ensuring human review is prioritized.
  • Define and manage engineering standards that all delivery teams adhere to.

Benefits

  • Flexible Time Off to recharge and maintain work-life balance.
  • Company-Wide Wellbeing Days for mental health focus.
  • Reimbursement for home office set-up to enhance productivity.
  • Multiple health plan options with a fully employer-paid plan.
  • Employer contributions to Health Savings Accounts for qualifying plans.
  • Fitness reimbursement program to encourage health and activity.
  • Paid parental leave for both birthing and non-birthing parents.
  • Generous company match on Traditional & Roth 401(k) contributions.
  • Employer-paid life and AD&D insurance for peace of mind.
  • Access to online learning platforms for professional development.
Full Job Description
Job Summary

Granicus serves more than 7,000 public-sector agencies and powers approximately 30 billion digital interactions annually. Within the Office of the CTO, we operate an AI-native software development lifecycle: a production engineering model in which autonomous agents perform high-confidence implementation work and senior engineers orchestrate, review, and own the outcome. The model is established and operating; we are scaling it across additional delivery teams.

This role joins one of those teams. Our engineering standards are calibrated to the practices used by leading software and AI organizations - generator-verifier architecture, eval-driven development, staged deployment, and high-volume autonomous pull-request pipelines - operated within a FedRAMP-authorized environment. We are hiring practitioners who will set and uphold these standards, not engineers who simply use AI tooling.

Operating constraints (non-negotiable): agents execute only within branches; all agent-generated code passes senior human review before merging to production; autonomous execution is a force multiplier and does not transfer accountability away from the responsible engineer. Compliance obligations - NIST 800-53 Rev 5, WCAG, SOC 2, and applicable FedRAMP authorizations - are treated as engineering requirements and a source of competitive advantage.

Why this role exists

High-volume autonomous agent pipelines are straightforward to demonstrate and difficult to operate safely, performantly, and auditably at scale. This role owns that problem. It is responsible for the generator-verifier architecture, agent orchestration patterns, the eval-driven development discipline, and a continuous integration and delivery system engineered for a high volume of autonomous agent pull requests - all within a security boundary that keeps model inference inside the VPC (AWS Bedrock) and sandboxes agent actions (WASM-isolated runtime with encrypted credential storage). The role sets the engineering standards inherited by every delivery team and is the final human accountability gate before agent-generated code merges to productio

What Your Impact Will Look Like

  • Own the generator-verifier architecture - the loop in which generator agents produce changes and verifier agents, automated tests, evaluation suites, SAST/DAST, and policy checks validate them, enabling volume to scale without quality regression.
  • Define agent orchestration patterns - task decomposition, dispatch, sandboxing, and reassembly across the agent array, including secure state and credential handling via WASM-isolated runtimes and encrypted credential vaults.
  • Build and operate CI/CD for autonomous pull-request volume - a pipeline that triages, tests, and routes a high volume of agent-generated pull requests while keeping human review efficient and high-signal.
  • Establish eval-driven development as the default discipline - define measurable acceptance criteria so changes are validated against evaluation suites rather than subjective judgment.
  • Own the security boundary - in-VPC inference via AWS Bedrock (including GovCloud), least-privilege agent permissions, and an explicit mapping from NIST 800-53 Rev 5 controls to concrete pipeline guardrails, so that compliance is enforced by the architecture rather than by manual audit.
  • Serve as the final human accountability gate - define and enforce the requirement that no agent-generated code reaches production without senior human review, supported by review tooling that maximizes signal.
  • Define the engineering standards inherited by every team - branching model, review protocol, evaluation conventions, and staged deployment, and maintain the reference implementation the organization builds on.
  • Govern graduated autonomy - define the criteria by which a workstream advances from supervised to autonomous execution, supported by measured agent reliability rather than assumption.

Ownership and growth

Ownership from Day One-
  • Generator-verifier loop and orchestration patterns for a delivery team
  • CI/CD engineered for agent pull-request volume with human review as a hard gate
  • In-VPC Bedrock inference and sandboxed agent runtime as the security boundary
  • Evaluation conventions and the branching and review protocol


Scope you will Grow Into-
  • Generator-verifier loop and orchestration patterns for a delivery team
  • CI/CD engineered for agent pull-request volume with human review as a hard gate
  • In-VPC Bedrock inference and sandboxed agent runtime as the security boundary
  • Evaluation conventions and the branching and review protocol


You Will Love This Job If You Have

Required
  • Architecture of systems at scale with accountability for outcomes. Distributed systems, CI/CD, and developer platforms where your design decisions carried significant operational consequence.
  • Deep CI/CD and developer-platform expertise. You have built pipelines that other engineers depend on - testing, staged deployment, rollback, and observability - with demonstrated reliability and performance.
  • Hands-on experience operating LLM agents in production paths, including orchestration, tool use, sandboxing, evaluation, and the failure modes that emerge at volume.
  • Security-architecture expertise. Least-privilege design, secrets management, network boundary enforcement, and threat modeling, with work that withstands both audit and adversarial review.
  • A track record of setting standards adopted by others. A branching model, review protocol, or platform pattern in active use because you defined it.
  • The ability to serve as an accountability gate without becoming a bottleneck. You design review tooling and conventions that maintain high signal and low latency.

Preferred
  • High-assurance security architecture is strongly preferred for this role specifically. Demonstrated experience designing and defending a security boundary within FedRAMP, FedRAMP High, defense, financial services, or healthcare, including direct experience with formal audit. Candidates without experience operating inside an audited boundary are unlikely to be effective setting the standard for one.
  • NIST 800-53 Rev 5 fluency, including the ability to map controls to engineering guardrails directly.
  • AWS Bedrock or GovCloud experience maintaining inference and data within a compliance boundary.
  • Experience with eval-driven development or generator-verifier architectures at a frontier-model or leading platform organization.

Indicators of a strong fit
  • You regard making autonomy safe and auditable as the central technical problem, and it is the problem you want to own.
  • You hold strong, evidence-based positions on pipeline reliability and operational resilience.
  • You prefer validation against evaluation suites to subjective assessment of a pull request.
  • You read NIST 800-53 as an engineering specification rather than as administrative overhead.
  • You are prepared to own the standard the organization builds on and accept the accountability that entails.

Indicators this role is not a fit
  • You prefer feature development to platform and standards work. This role's leverage is deliberately indirect.
  • You consider compliance to be administrative work to delegate. Here it is architecture you own.
  • You favor delivery speed over demonstrable safety when the two conflict. Within a FedRAMP boundary, demonstrable safety takes precedence.
  • You expect autonomy to mean the absence of review. The review gate is the core deliverable and is yours to safeguard.
  • You are uncomfortable declining a request for greater autonomy than a workstream's measured reliability supports.


Pay Range

USD $175,000.00 - USD $206,500.00 /Yr.

Security and Privacy Requirements
  • Responsible for Granicus information security by appropriately preserving the Confidentiality, Integrity, and Availability (CIA) of Granicus information assets in accordance with the company's information security program.
  • Responsible for ensuring the data privacy of our employees and customers, their data, as well as taking all required privacy training in a timely manner, in accordance with company policies.


The Team
  • We are a remote-first company with a globally distributed workforce across the United States, Canada, United Kingdom, India, Armenia, Australia, and New Zealand.


The Benefits

At Granicus, we offer a comprehensive and flexible benefits package designed to support your well-being, growth, and work-life balance-starting from day one.

Here's what you can expect as a U.S.-based team member:

Flexibility & Balance
  • Flexible Time Off - Take the time you need to rest, recharge, and live your life.
  • Company-Wide Wellbeing Days - Paid days off to unplug and focus on your mental health.
  • Work From Home Reimbursement - Support a productive home office environment.

Health & Wellness
  • Multiple Health Plan Options - Including a 100% employer-paid plan.
  • Employer HSA Contributions - When enrolled in a High-Deductible Health Plan.
  • Fitness Reimbursement Program - Stay active, your way.
  • On-Demand Mental Health Support - Access to Headspace and other wellness tools.

Family & Future
  • Paid Parental Leave - For both birthing and non-birthing parents.
  • Traditional & Roth 401(k) - With a generous company match.
  • Life & AD&D Insurance - 100% employer-paid coverage for peace of mind.

Growth & Recognition
  • Online Learning Platforms - Fuel your professional development.
  • Competitive Salary & Bonuses - Your contributions are valued and rewarded.

About Granicus

Granicus is a provider of cloud-based software solutions for government organizations. The company's platform helps government agencies streamline their workflows, engage with citizens, and improve transparency. Granicus offers a range of solutions, including meeting management, website design, and digital communications. The company's mission is to help government organizations better serve their communities through technology.
Learn more about Granicus
Size
500 employees
Industry
Founded
1999

Similar Jobs

More Jobs at Granicus

More Information Technology Jobs

Find similar Principal Software Architect - Emerging Technologies jobs: