AI Governance Engineer
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Natera is deploying AI into clinical, diagnostic, and patient-facing workflows at scale. As that portfolio grows, AI governance infrastructure has to be real: working controls embedded in the platform, automated risk intake, runtime policy enforcement, and production monitoring that catches drift before it becomes an incident. This role builds that infrastructure.
This role is a software engineering role. You will design, build, and operate the technical systems that make AI governance work at Natera: guardrails in the LLM Gateway, PHI/PII detection in the RAG infrastructure, automated risk scoring in the intake pipeline, observability dashboards, and incident response tooling. You translate frameworks like NIST AI RMF, CHAI, and ISO 42001 into platform controls, not policy documents. Roughly 75% of your time is engineering work. The remaining 25% is the process and cross-functional work that gives the engineering its direction.
You report to the Head of AI & Data Governance. You work hands-on with platform engineers, Legal, Privacy, RAQA, and business teams. The job is to make AI governance a platform capability, not a committee function.
What You’ll Do
Build governance controls into the AI platform
- Design, build, and own the guardrail layer inside Natera’s LLM Gateway: content filtering, output validation, PHI/PII detection, prompt injection defenses, session retention, and audit logging. You write the code; you own the component.
- Engineer the governance layer for Natera’s agentic runtime and RAG infrastructure: policy enforcement hooks, output routing by risk tier, retrieval filtering, citation integrity checks, and PHI exposure prevention.
- Ensure every control is instrumented with observability from day one: what is filtering, what is flagging, what is escalating, and what is drifting from its approved risk profile. Governance without observability is not governance.
- Ensure every AI platform control meets HIPAA, RAQA, and Natera’s data classification requirements at design time. Retrofitting after deployment is not an option.
- Build governance as a runtime capability: the platform enforces policy; you define what that policy is, implement it, and verify it works under real conditions.
Build the automated risk intake and monitoring systems
- Design and implement the automated AI risk intake pipeline: structured intake form, automated risk scoring, tiering (Low / Medium / High / Critical), and routing to the right review path, aligned to NIST AI RMF, CHAI, and the EU AI Act.
- Build and maintain the AI Risk Register as an engineering artifact: risk scores, treatment decisions, mitigation steps, and review history, queryable and auditable.
- Define and build the monitoring systems for every production AI use case: accuracy tracking, drift detection, misuse alerting, and escalation thresholds. These must be instrumented and verified before go-live, not documented and hoped for.
- Build and maintain the AI incident response tooling: automated detection, alert routing, decision logging, and remediation tracking.
Run the risk assessment and governance review process
- Run the AI use-case intake process end to end: evaluate every new use case against the risk tiering model before it gets built or deployed, using the automated systems you built.
- Facilitate high-risk use-case reviews with the AI Governance Board (Legal, Privacy, RAQA) and produce clear, time-bound recommendations and controls. Flagging the problem is not enough.
- Keep the risk questionnaire, scoring rubric, and tiering criteria current as the AI portfolio scales and applicable frameworks, regulations, and internal policies change.
Gate what gets bought or integrated
- Own the technical due diligence process for AI vendors and foundation model providers: evaluate data residency, model transparency, API security, contractual controls, and regulatory alignment before any external AI system connects to Natera data or workflows.
- Maintain the vendor AI risk assessment framework; ensure contracts include AI-specific provisions on data handling, model versioning, and auditability. A completed technical assessment is required before any vendor or model goes into production.
Drive policy and workforce enablement
- Help write and maintain Natera’s AI acceptable-use policy, grounded in what the platform actually enforces rather than aspirational guidelines.
- Be the practical engineering resource teams call when they are building something new and need to understand what governance requires: not just the person who says no, but the person who shows them how to build it right.
What We’re Looking For
Required
- 7+ years of software engineering experience, with at least 3 years working directly in AI/ML systems, LLM infrastructure, or AI safety and governance engineering. You have written the code, debugged the failures, and shipped the controls.
- Hands-on experience building production AI systems: LLM pipelines, RAG architectures, agentic runtimes, or AI observability and monitoring infrastructure.
- Deep, practical understanding of LLM risks in production: hallucination, bias, prompt injection, data leakage, model drift and experience building technical mitigations, not just documenting them.
- Proficiency in Python and experience building API-level integrations, middleware, and data pipelines in production environments.
- Experience with ML observability and monitoring: you know how to instrument a model, define drift thresholds, and build alerting that fires on the right conditions.
- Experience in a regulated environment (healthcare, life sciences, or financial services) with real HIPAA or equivalent compliance obligations and hands-on PHI/PII data handling.
- Working knowledge of NIST AI Risk Management Framework (AI RMF 1.0) or ISO 42001: you have applied these frameworks by building the controls they require, not just by citing them in documentation.
- Ability to write crisp technical specs and documentation that both engineers and Legal can read.
Nice to Have
- Direct hands-on experience building LLM gateway architectures, RAG pipeline controls, content moderation systems, or agentic AI safety infrastructure.
- Background in AI red-teaming, adversarial testing, or structured model evaluation.
- Experience with trust and safety infrastructure or ML monitoring platforms (Arize, Fiddler, Whylogs, or similar).
- Direct experience in diagnostics, genomics, or clinical AI: you understand the specific risk surface of patient-facing and clinical decision support systems.
- Experience building HIPAA, FDA GxP (GMLP, GMP, GCP), CLIA, PMDA, or GDPR-compliant systems.
- Certifications: CIPP, CIPT, or Responsible AI credentials from a recognized body.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Natera
Explore Top Companies in this Space
Apogeetherapeutics
Biotechnology
Twistbioscience
Biotechnology
Worldwide Clinical Trials
Biotechnology
Apogee Therapeutics
Biotechnology
Natera
View Company ProfileNatera is a genetic testing company that specializes in non-invasive prenatal testing and other genetic analysis services. Founded in 2004, the company has established itself as a leader in the field of genetic testing, providing advanced diagnostic solutions for reproductive health, oncology, and other medical applications. Natera's flagship product, Panorama, is a non-invasive prenatal test that analyzes fetal DNA in a pregnant woman's bloodstream to detect genetic disorders and chromosomal abnormalities. The company's testing services are designed to provide accurate and reliable results, empowering healthcare providers and patients to make informed decisions about pregnancy, cancer treatment, and other medical conditions. With a strong commitment to innovation and customer satisfaction, Natera has become a trusted partner for healthcare providers and patients worldwide.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.

