Open role

Privacy / Security / Trust Engineer

This role helps build Lucy, the proactive AI coach from Lucy Labs that lives on your desktop as a cloud-backed app, while the product is in development with design partners.

Builds the controls that make Lucy safe to use with real work.

Planned work

About the role

At Lucy Labs, this role owns the purpose described below.

The Privacy / Security / Trust Engineer owns the technical controls that make Lucy safe to use with real work. This role builds consent enforcement, DLP, auditability, retention/deletion propagation, threat models, and enterprise security-review readiness into the product from the beginning.

This is not a late-stage compliance role. Privacy is product functionality, and the staffing model hires this role early.

The mission

At Lucy Labs, this role's mission is defined by the outcome and work below.

Build trust systems that:

  • Enforce consent, pause state, work-hours boundaries, and customer policy
  • Protect raw capture and derived Actions, Tasks, Goals, Workflows, Coaching, Analytics, and KG updates
  • Make deletion and retention propagate across downstream systems
  • Produce audit evidence for internal governance and enterprise reviews
  • Enable product velocity without eroding user trust

What you'd own

At Lucy Labs, this role turns its mission into concrete responsibilities in each area.

1. Privacy Controls and DLP

For 1. Privacy Controls and DLP, Lucy Labs expects this role to own the responsibilities below.

  • Build DLP, redaction, consent enforcement, and policy filtering into capture and ingestion paths
  • Ensure privacy state travels with derived objects and downstream outputs
  • Design privacy-safe defaults for desktop capture, local buffering, and evidence upload
  • Partner with Product and Design on understandable consent and pause experiences

2. Deletion, Retention, and Auditability

For 2. Deletion, Retention, and Auditability, Lucy Labs expects this role to own the responsibilities below.

  • Define retention/deletion propagation requirements across raw evidence and derived data
  • Build audit logs and evidence trails for policy decisions
  • Test privacy regressions with QA/Release and Data/Evaluation
  • Support customer-specific data residency and governance requirements

3. Security Architecture

For 3. Security Architecture, Lucy Labs expects this role to own the responsibilities below.

  • Threat-model desktop capture, ingestion, inference, KG updates, coaching, and admin review surfaces
  • Own secure defaults for secrets, IAM, encryption, access control, and endpoint trust
  • Review high-risk designs and production changes
  • Build incident response and vulnerability-management foundations

4. Enterprise Trust Readiness

For 4. Enterprise Trust Readiness, Lucy Labs expects this role to own the responsibilities below.

  • Prepare technical evidence for enterprise security reviews
  • Partner with future compliance owners on SOC 2, ISO 27001, ENS, GDPR, and customer security questionnaires
  • Translate security and privacy requirements into engineering work, not policy theater

What success looks like

Lucy Labs defines these milestones as role outcomes, not metrics for measuring the person.

60 days
Privacy threat model and first consent/DLP controls are in the product plan
90 days
Derived-data policy state and deletion propagation are demonstrable
6 months
Design partners can review trust posture with real audit evidence
12 months
Trust Engineering is a load-bearing product function, not a compliance afterthought

Experience and fit

Lucy Labs looks for the essential experience listed here and treats the rest as helpful, not an automatic barrier.

Must have

  • 5+ years security, privacy engineering, trust engineering, or product security experience
  • Strong engineering ability and hands-on security architecture judgment
  • Experience with DLP, access control, audit logging, data lifecycle, or privacy-by-design systems
  • Familiarity with GDPR and enterprise security-review expectations
  • Ability to partner with product and engineering without becoming a blocker

Nice to have

  • Desktop security, endpoint telemetry, or local-first privacy experience
  • SOC 2, ISO 27001, ENS, DPIA, or regulated-market readiness experience
  • Threat modeling for AI/ML, inference, or data-derived products
  • Experience with consent UX, deletion propagation, or policy-as-code

How you work

Lucy Labs looks for these working traits alongside technical experience.

Role DNA

Lucy Labs evaluates these traits as part of the fit for this role.

  • Trust-first systems thinker
  • Pragmatic security engineer
  • Clear writer and reviewer
  • High attention to downstream effects
  • Comfortable saying no when the product would break user trust
Next step

Apply for this role

The Lucy Labs application form opens with this role already selected. You can review the message before sending it.

Apply for this role

Frequently asked questions

Is this role open at Lucy Labs?

Yes. Lucy Labs confirmed this role is open on 25 August 2026.

Where does Lucy Labs base this role?

Lucy Labs bases this role in Madrid, Spain. The exact working arrangement is confirmed during the application conversation.

What does this role own at Lucy Labs?

At Lucy Labs, this role has one central responsibility: Builds the controls that make Lucy safe to use with real work. The full description sets out the mission, responsibilities, and relevant experience.

How do I apply to Lucy Labs?

At Lucy Labs, use the application form. The role is selected automatically, and you can review it before sending.

Talk to Lucy