Staff Software Engineer

HubSpot

HubSpot

Software Engineering
United Kingdom
Posted on Mar 25, 2026
Staff Engineer, Security Privacy

About The Team

The Security Privacy team builds and operates the services that help HubSpot understand, protect, and manage personally identifiable information (PII) across the entire platform.

We own a suite of backend and frontend systems that automatically scan HubSpot’s codebase and infrastructure to catalog PII usage and ownership, classify datasets, enforce data protection standards, and orchestrate GDPR deletion workflows when customers exercise their rights. Our tools make it straightforward for every engineering team at HubSpot to know what sensitive data they handle and to do the right thing with it.

We sit within the Security Automated Assurance group, and partner closely with HubSpot’s Privacy, Legal, and Security organisations as well as product and infrastructure teams across the company.

About The Role

As a Staff Engineer on the Security Privacy team, you’ll be a senior individual contributor and technical leader shaping how HubSpot discovers, manages, and protects personal data at scale. You’ll:

  • Set and evolve the technical direction for privacy tooling, partnering closely with the team’s TL and PM.
  • Lead delivery of complex, multi-quarter initiatives across data privacy, PII management, and data protection domains, often coordinating work across multiple teams and technical areas.
  • Make high-impact architectural decisions, raising the bar for reliability, performance, and security in our systems.
  • Provide deep technical mentorship, helping other engineers grow their design, coding, and operational skills while contributing to an inclusive, high-trust team culture.

This is a hands-on leadership role: you’ll spend most of your time designing systems, writing code, and reviewing changes, while also acting as a go-to technical expert and thought partner for the Security Privacy team and our stakeholders.

In this role, you’ll get to

  • Lead design and implementation of services that catalog PII, classify datasets, enforce data protection standards, and automate GDPR deletion workflows across HubSpot.
  • Design and evolve distributed systems that scan HubSpot’s codebase and infrastructure to detect PII usage, track dataset ownership, and orchestrate privacy-related actions at scale.
  • Own reliability and on-call for the services you help build, including alerting, incident response, and continuous improvement of our data privacy pipelines.
  • Collaborate with Privacy, Legal, and Security teams to translate data protection requirements and regulations into robust, scalable technical solutions.
  • Drive technical roadmaps and long-term investments for how HubSpot manages and protects personal data, balancing foundational platform work with near-term regulatory and business needs.
  • Mentor engineers across the group through design reviews, pairing, and thoughtful feedback, helping to shape engineering best practices for security and privacy domains.

We’re Looking For People Who

  • Are tenured backend engineers with experience operating at staff-level scope: driving complex technical initiatives, influencing across teams, and providing deep technical leadership without direct people management.
  • Have strong knowledge of data governance concepts and practices (for example, data lineage, classification, retention, and access governance) and experience applying them in large-scale systems.
  • Are comfortable designing and operating distributed systems (e.g., microservices, message queues, data pipelines) in production environments.
  • Have strong experience with at least one JVM language (ideally Java) and relational databases (e.g., MySQL); experience with technologies like Kafka, asynchronous processing, or large-scale data systems is a plus.
  • Care deeply about reliability, observability, and operational excellence, and have participated in or helped run on-call rotations before.
  • Communicate clearly with engineers and non-engineers, and enjoy working closely with product, design, and non-technical partners in security, privacy, and compliance.
  • Value mentorship, feedback, and inclusion, and want to help build a team where people from different backgrounds can do their best work.

Nice to have

  • Experience in security, compliance, risk, or privacy domains (e.g., SOX, ISO 27001, SOC reports, data protection) or a strong interest in developing deep expertise in this space.
  • Background building data or reporting platforms that integrate with third-party systems and internal data warehouses.
  • Experience with Kafka, event-driven architectures, or large-scale data ingestion and processing.
  • Prior work with auditors, risk, or GRC teams, or building systems that support audits and regulatory requirements.

Why HubSpot

HubSpot engineers work in small, autonomous teams with a high degree of ownership over what they ship and how they run it in production. We deploy frequently, learn quickly from our customers, and invest heavily in engineering excellence and developer experience.

In Security Privacy, you’ll see a direct connection between the systems you build and HubSpot’s ability to earn and keep our customers’ trust at scale.

We know the confidence gap and impostor syndrome can get in the way of meeting spectacular candidates, so please don’t hesitate to apply — we’d love to hear from you.

If you need accommodations or assistance due to a disability, please reach out to us using this form.

At HubSpot, we value both flexibility and connection. Whether you’re a Remote employee or work from the Office, we want you to start your journey here by building strong connections with your team and peers. If you are joining our Engineering team, you will be required to attend a regional HubSpot office for in-person onboarding. If you join our broader Product team, you’ll also attend other in-person events, such as your Product Group Summit and other gatherings, to continue building on those connections.

If you require an accommodation due to travel limitations or other reasons, please inform your recruiter during the hiring process. We are committed to supporting candidates who may need alternative arrangements

Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Germany Applicants: (m/f/d) - link to HubSpot's Career Diversity page here.

India Applicants: link to HubSpot India's equal opportunity policy here.

About HubSpot

HubSpot (NYSE: HUBS) is an AI-powered customer platform with all the software, integrations, and resources customers need to connect marketing, sales, and service. HubSpot's connected platform enables businesses to grow faster by focusing on what matters most: customers.

At HubSpot, bold is our baseline. Our employees around the globe move fast, stay customer-obsessed, and win together. Our culture is grounded in four commitments: Solve for the Customer, Be Bold, Learn Fast, Align, Adapt & Go!, and Deliver with HEART. These commitments shape how we work, lead, and grow.

We’re building a company where people can do their best work. We focus on brilliant work, not badge swipes. By combining clarity, ownership, and trust, we create space for big thinking and meaningful progress. And we know that when our employees grow, our customers do too.

Recognized globally for our award-winning culture by Comparably, Glassdoor, Fortune, and more, HubSpot is headquartered in Cambridge, MA, with employees and offices around the world.

Explore More

  • HubSpot Careers
  • Life at HubSpot on Instagram

HubSpot may use AI to help screen or assess candidates, but all hiring decisions are always human. More information can be found here. By submitting your application, you agree that HubSpot may collect your personal data for recruiting, global organization planning, and related purposes. Refer to HubSpot's Recruiting Privacy Notice for details on data processing and your rights.