Location: Travel to customer locations will be required.
Role Summary
We are hiring a senior full-stack engineer to help build and harden the platform that runs manufacturing execution on live shop floors: real-time, machine-connected, and multi-tenant. This is a broad senior engineering role. For the first year its primary drivers are platform integrity and FedRAMP Moderate authorization. Over time it grows with our compliance program and product as we take on new authorizations, customers, and capabilities.
The role owns the application and code-architecture layer: server-side authorization and access control, distributed and multi-tenant reliability, auditable data flows, and dependency and cryptographic security. Infrastructure hardening (Kubernetes, Terraform, OS and container) is led by our platform team; this role supports and adds depth there.
Our GRC consultants own control interpretation, policy, and audit coordination. This role owns the building, and stands behind its implementation when the 3PAO comes asking.
Core Responsibilities
- Own server-side authorization, validation, and access control across the platform
- Design fine-grained, role-based access control and scoping by user and customer
- Own multi-tenant isolation architecture across services and data
- Build resilient, recoverable write paths across distributed services and third-party (ERP) integrations
- Own dependency and supply-chain security: patching, FIPS-validated cryptography, and vulnerability management
- Implement logging, monitoring, and continuous monitoring (ConMon), and produce the technical evidence behind our controls
- Partner with GRC consultants to turn control requirements into implementation, and stand behind it with the 3PAO
- Support customer deployments on site, at both the platform and product level
How We Work
We build with AI-assisted engineering and expect this role to work the same way: using modern AI tooling to move quickly through implementation, refactoring, and evidence generation without trading away rigor.
Must-Have Qualifications
- Strong senior full-stack engineer who writes production code, not just scripts
- Depth in distributed, multi-tenant systems: reliability, consistency, recovery, clean state boundaries, and access control
- Experience building software to a formal security or compliance framework (FedRAMP, NIST 800-53, SOC 2, HIPAA, PCI, or similar); FedRAMP experience strongly preferred
- US citizen or US permanent resident
Nice-to-Have
- Hands-on experience in a FedRAMP authorization (Moderate or High): writing code, re-architecting services, or producing technical evidence
- Familiarity with NIST 800-53, CIS/STIG hardening, FIPS-validated cryptography, or vulnerability management
- Prior direct work with 3PAOs, or with FedRAMP 20x / OSCAL / automated evidence
- AI-assisted engineering already part of your workflow
- Experience with manufacturing or OT data, or securing SaaS specifically rather than general enterprise IT
Our Stack
- Backend services primarily in TypeScript/Node.js, with Rust for data-processing services and Python for data science
- React on the frontend
- GraphQL and REST APIs
- MySQL and PostgreSQL, plus Redis and DynamoDB
- Event streaming over Kinesis and NATS/JetStream
- AWS (Lambda, S3, RDS, CloudFront), deployed to Kubernetes via GitOps with Terraform for infrastructure
Pay: From $120,000.00 per year
Benefits:
- 401(k) matching
- AD&D insurance
- Bereavement leave
- Dental insurance
- Dependent care reimbursement
- Disability insurance
- Family leave
- Flexible spending account
- Health insurance
- Health savings account
- Life insurance
- Paid sick time
- Paid time off
- Vision insurance
- Volunteer time off
Work Location: Hybrid remote in Northampton, MA 01060