Introduction
The role in one line:
An independent backend engineer to help build, harden, and scale our secure APIs - strong on API craft, security, and testing, and able to help drive delivery, not just execute tickets.
Context:
Work across our API surface, held to real financial-institution standards for security, reliability, and testing. It's a deliberately simple, well-structured codebase. No internal/domain business knowledge required, that's owned in-house. We need backend and API strength.
Where they add the most value:
Since internal logic is covered, their leverage is on the partner-facing platform and developer experience:
- Growing the API surface cleanly (new endpoints, webhooks/callbacks, richer querying)
- Developer experience - clear contracts, published API specs, integration docs, sandbox environments
- Hardening - rate limiting, secret rotation, contract testing, pen-test remediation
- Scaling - repeatable multi-partner onboarding, tenant isolation, load/performance testing, caching
- Platform quality - SLOs, alerting, resilience patterns
Ways of working:
- Independent and self-directing - takes a capability from spec → design → tested delivery without hand-holding
- Helps manage the work - can break down a body of work, sequence it, and drive it to a clear "done"
- Spec- and documentation-driven - at home working from and writing specs, acceptance criteria, and decision records; a clear, concise writer
- Comfortable with AI-assisted / agentic development - this project is built heavily with agentic tooling; someone who can direct and review that output well is a real multiplier
- Quality-first and pragmatic - treats security, testing, and observability as ship-blocking, while favoring simple solutions over over-engineering
Requirements
Core skills:
- Modern backend development in TypeScript / Node.js - server-side HTTP services, networking fundamentals, clean typed code
- REST/JSON API design - versioning, consistent error contracts, idempotency, pagination, and an API-as-contract mindset (OpenAPI)
- Relational data - schema design, migrations, and a data-integrity mindset
- Asynchronous & queue-driven systems - background workers, job lifecycles, retries, idempotent processing
- API security - token-based auth (OAuth/JWT), authorization and tenancy isolation, secure secret handling, "fail-closed" defaults, and awareness of industry baselines (e.g. OWASP API Security Top 10)
- Test-forward development - comfortable driving work through unit, integration, and contract tests as a first-class part of building, not an afterthought
- Hands-on AWS experience (mandatory) - must know the specifics of core AWS services (containers/compute, queuing, managed databases, secrets, load balancing). Given the short timeline and MVP nature, we prefer they not need to onboard onto a new cloud;
- Cloud-native delivery - building and shipping containerized services, infrastructure-as-code (Terraform ideal), CI/CD pipelines
- Observability - structured logging, metrics, tracing, and audit trails; can debug production from telemetry
Nice-to-haves:
fintech or other regulated-domain experience · platform / API-gateway team background · leading a small delivery independently.
By continuing you agree to our Terms & Privacy Policy.