Infinity - Backend Platform Engineer
Requirements
• TypeScript backend engineering: strong Node.js and TypeScript experience building modular production APIs; Fastify, JSON Schema, generated OpenAPI, and schema-first tooling such as TypeBox strongly preferred. • TypeScript backend engineering: • Identity and authorization: integrating Cognito or another OIDC provider while keeping product admission, account membership, and capabilities in authoritative application state. • Identity and authorization: • Distributed work execution: transactional outbox, SQS or comparable queues, idempotency, at-least-once delivery, leases, heartbeats, fencing tokens, cancellation, retries, and DLQ recovery. • Distributed work execution: • Revisioned domain design: immutable revisions, compare-and-swap updates, ETags, lineage, state machines, and evidence-preserving lifecycle transitions. • Revisioned domain design: • Python worker integration: modern typed Python, uv, Pydantic, pydantic-ai, and clear service contracts between TypeScript application code and private Python workers. • Python worker integration: • AI trust boundaries: typed model tools and outputs, server-resolved authority, bounded retrieval context, citation validation, and fail-closed persistence of model proposals. • AI trust boundaries: • Testing and operability: TDD, contract and integration tests, adversarial tenant-isolation tests, failure drills, OpenTelemetry instrumentation, and end-to-end execution against realistic services. • Testing and operability: • Patent, legal-tech, document-workflow, or other evidence-heavy domain experience. • Pgvector retrieval, embedding pipelines, and public/private retrieval separation. • Neo4j or graph-query experience for a read-only public reference plane. • Stripe webhook, entitlement projection, and usage-reconciliation experience. • Secure source-document ingestion, malware-scanning, and provenance pipelines. • Experience building operator and audited break-glass application workflows.
Responsibilities
• Build the versioned REST/OpenAPI contract and modular TypeScript BFF, with stable success/error envelopes, generated TypeScript clients, and contract-drift CI gates. • Integrate Cognito identity with opaque application sessions, and implement admission, invitations, personal/team accounts, memberships, capabilities, explicit account switching, and guarded account conversions that preserve asset identity and history. • Implement the minimal separate operator admission service and audited break-glass workflows, keeping customer and operator identities, sessions, routes, roles, and audit paths independent. • Design PostgreSQL domain models, migrations, forced-RLS authorization, transaction-bound authorization contexts, and immutable account_id constraints, proving cross-account denial through BFF tests and direct runtime-role SQL tests. • Deliver the durable asynchronous operation path: idempotent acceptance, typed payment-disabled beta entitlements, transactional outbox, account-fair SQS dispatch, worker lease/heartbeat/fencing, result commit, retry, cancellation, and DLQ/redrive. • Implement durable progress delivery: append-only operation events, resumable SSE, and cursor polling with no lost or duplicated logical events. • Maintain usage, provider, and observability foundations: exactly-once logical usage ledgers, safe (customer-content-free) logs, metrics, and traces, and the worker and operation signals Platform dashboards need. • Support current-and-prior compatibility semantics across database, OpenAPI, events, queues, and worker callbacks, including expand/deploy/backfill/verify/contract changes and rollback. • Build private Python worker workflows and typed pydantic-ai agent boundaries, and hand over API documentation, ADRs, threat models, tests, fixtures, runbooks, and a dependency-aware plan for the next B2C vertical.
Benefits
• High-impact work at the intersection of AI and critical infrastructure regulation • Direct customer exposure and a seat at the table when we decide what to build • Small team with outsized influence; your field learning shapes the product roadmap • Modern AI-native development environment (Claude Code, Cursor, multi-model orchestration) • Values We Hire For • Values We Hire For • Character: integrity and trustworthiness above all • Character: • Competency: evoking trust and reliably delivering • Competency: • Togetherness: family-level support and alignment • Togetherness: • Impact: meaningful outcomes over activity • Impact: • Commitment: ownership and follow-through • Commitment: • Labrynth is committed to fair and competitive pay, ensuring that compensation reflects both market conditions and the value each team member brings. Hourly rates are determined based on factors such as location, relevant experience, skills, internal pay equity, and market conditions. • During the interview process, your Talent Acquisition Partner will confirm the hourly rate range applicable to your location. For contractors outside the U.S., compensation is aligned with local market conditions and cost of living. • While every engagement is unique, our compensation philosophy is designed to ensure fairness, consistency, and competitiveness across Labrynth. Additional details regarding compensation, contract terms, and the scope of the engagement will be discussed throughout the hiring process. • Equal Opportunity Statement:
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT