Live opening · Posted 18 hours ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
This is a new role, and there is exactly one of it. You sit next to the CTO, not under a layer of managers, and your roadmap is whatever is currently hardest, riskiest, or most ambiguous in a ~60-engineer organization. One week that means reading a CERT-In kernel advisory in the morning and having a remediation rolling across EKS and Docker Swarm fleets by evening. Another week means settling a whiteboard argument about sender-constrained tokens by shipping a working OpenResty/Lua prototype. You are the person the CTO trusts to walk into any codebase, any incident, any vendor pitch, or any client security review and come back with the truth and a plan. There are no direct reports, by design. Influence here is earned through working code, sharp writing, and judgment, not headcount.
Responsibilities:
Parachute engineering. Take the gnarliest cross-team problems; performance cliffs, data-integrity scares, migration landmines, and one-tenant-only prod mysteries; and drive them to root cause and closure, hands-on keyboard.
Zero-to-one prototypes. Turn the CTO's what-if into a working spike in days, not quarters: internal platforms, security primitives, and AI-powered workflows. Some get killed. That's the point.
Technical due diligence. Run build-vs-buy and vendor/OSS evaluations (PAM tooling, observability, AI platforms, databases), and write the decision memo that survives both engineering scrutiny and an auditor.
Security and compliance engineering. Threat-model features before they ship, respond to CVEs and advisories across the fleet, and design controls that satisfy RBI and SOC 2 auditors without strangling developer velocity.
AI leverage. Push our agentic-coding rollout, LLM MR-review pipelines, and self-hosted model experiments further. Measure honestly. Kill what doesn't earn its cost.
Architecture pressure-testing. Review designs for multi-tenancy, session and token security, BFF-layer hardening, and PostgreSQL at scale (Patroni, PgBouncer, replication, and lock behavior) before problems become incidents.
Stand in for the CTO. Client security reviews, incident bridges, and internal design debates when he can't be in the room; you are the room.
Requirements:
Principal-grade depth: typically 8+ years of shipping and operating production systems, with the scar tissue to prove it.
Genuine polyglot fluency. Production work in at least four of PHP (Laravel), TypeScript, Python, Go, Rust, and Lua. You pick up a new language over a weekend, and it shows in the code review on Monday.
Deep Linux and infrastructure chops. Kubernetes (EKS) and container internals, Docker Swarm realities, HAProxy/OpenResty, Cloudflare Zero Trust, and the ability to debug from strace all the way up to Grafana dashboards.
PostgreSQL beyond CRUD. Replication topologies, connection pooling behavior, lock contention, and what actually happens under load.
A security instinct. OWASP is table stakes. You can reason about mTLS, token binding, IDOR/BOLA, key custody, and crucially what an RBI or SOC 2 auditor will ask about your design.
An AI-native workflow. You already use agentic coding tools daily, know precisely where they break, and can teach others to get leverage without losing rigor.
Sharp technical writing. RFCs, decision memos, postmortems. Half this job is making hard decisions legible to engineers, auditors, and the board.
Ownership under ambiguity. You can be handed a question, not a ticket, and return with the answer, the fix, and the prevention.
Nice to have:
BFSI or fintech domain depth: loan origination, credit underwriting flows, payments, or core banking integrations.
Fleet-scale CI/CD on self-hosted GitLab; supply chain security (SBOMs, dependency tracking, CERT-In reporting).
Hands-on experience self-hosting LLMs or building evaluation harnesses for AI in production. Open-source contributions anywhere in our stack.
Skills
JavaScript, Python, PHP, TypeScript, Laravel, Kubernetes, Docker, PostgreSQL, Golang
Experience
8-12 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.