Live opening · Posted 8 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
SustainGRC is a governance intelligence infrastructure platform for non-financial data. Founded in London in 2022 and endorsed by the UK government as an innovator, we hold risk, internal audit, compliance, resilience, board governance, AI governance and sustainability on a single data model — built as one system rather than assembled through acquisition.
Our customers are mid-to-large enterprises and sovereign entities across EMEA and the GCC, operating under DORA, NIS2, the EU AI Act and equivalent regional supervision. When a regulator or auditor asks them to defend a number, our platform is what makes that number defensible.
The engineering standard follows from that: assurance-grade data, traceable to source, attributable to a person, and able to survive scrutiny years after the fact.
The role
You own the engineering function. The services, the architecture, the security model, the production behaviour, and the engineers who build it.
This is hands-on. You write code, you review it, and you raise the standard of a team that is capable but early in its career. Roughly two-thirds engineering, one-third leadership, shifting as the function scales.
It suits someone entrepreneurial — comfortable making decisions without complete information, moving at the pace a platform company at this stage demands, and taking ownership of outcomes rather than tickets. If you need a defined remit handed to you, this will frustrate you.
What you will own
Engineering leadership
Delivery for the full platform: scope, sequencing, quality, production outcomes
A distributed engineering team — hiring, technical direction, code review standards, performance
Architectural authority, and the defence of those trade-offs to product, security and the executive team
Translating regulatory and customer commitments into engineering constraints before they become rework
The practices this stage requires: design review, incident response, on-call, release discipline
Backend and platform
Scalable backend services in Node.js (TypeScript); REST APIs and microservices across the platform
End-to-end ownership: design → implementation → deployment → monitoring
Architectural risk, edge cases and scalability constraints identified early
Clean architecture, SOLID principles, long-term maintainability
Security, access control and auditability
Authentication and authorisation architecture (JWT, OAuth2, RBAC)
Permission models and data access controls for multi-tenant enterprise and sovereign deployments
Immutable audit logging and evidence lineage — every action logged, attributable, tamper-evident
Data residency and segregation across UK, EU and GCC jurisdictions
Control evidence for ISO 27001 and Cyber Essentials Plus surveillance
Data, integrations and performance
PostgreSQL schema, query and index design at scale
Redis for caching, queues and performance
External service integration with reliability and traceability
Real-time features where applicable (Socket.io) and S3-compatible object storage
Reliability and platform operations
Docker-based containerisation and environment parity
CI/CD pipeline ownership (GitHub Actions or similar)
Cloud deployment, GCP-first (GKE, Cloud Run, Cloud SQL, IAM, Cloud Storage); on-premises and VPC patterns for sovereign customers
Monitoring, logging, alerting, error tracking
Safe deployments, high availability, predictable releases
Required
10+ years professional backend engineering, including at least 3 years leading engineers
Strong Node.js and TypeScript; production experience with Express, Fastify or NestJS
Deep PostgreSQL; hands-on Redis
Microservices and distributed systems in production
Docker and CI/CD ownership
Strong grasp of API security, authentication and RBAC
Demonstrable ownership of production systems and of the people building them
Comfortable making architectural decisions and defending the trade-offs to non-engineers
Fluent professional English — you will present to enterprise customers, auditors and partners directly
This role is not suitable for engineers without prior team leadership, or for managers who no longer write code.
Nice to have
Enterprise SaaS, compliance, or regulated-industry platforms
Exposure to audit, GRC or financial services systems
Arabic, in addition to English
What we offer
Ownership of infrastructure that enterprises and sovereign entities depend on to satisfy regulators
Compensation weighted towards equity — a significant allocation for the right candidate, alongside cash. We are building owners, not staffing a function
Fully remote
High ownership, low bureaucracy — architectural decisions are made by the people building the system
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.