Search Jobs

Search by job, company or skills

Senior Backend & Platform Security Engineer (Node.js)

Senior Backend & Platform Security Engineer (Node.js)

sustaingrc
3-5 Years
  • Posted 2 hours ago
  • Be among the first 10 applicants

Job Description

About SustainGRC

SustainGRC is a governance intelligence infrastructure platform for non-financial data. Founded in London in 2022 and endorsed by the UK government as an innovator, we hold risk, internal audit, compliance, resilience, board governance, AI governance and sustainability on a single data model — built as one system rather than assembled through acquisition.

Our customers are mid-to-large enterprises and sovereign entities across EMEA and the GCC, operating under DORA, NIS2, the EU AI Act and equivalent regional supervision. When a regulator or auditor asks them to defend a number, our platform is what makes that number defensible. The engineering standard follows from that: assurance-grade data, traceable to source, attributable to a person, and able to survive scrutiny years after the fact.

Role Overview

You will take technical ownership of core backend services, platform security architecture, and production reliability for a system carrying regulated enterprise workloads.

This is not a feature-delivery role. You will own systems end to end and be accountable for their behaviour in production.

Suited to engineers who have owned backend systems in production, think in platforms rather than endpoints, and treat security and auditability as design constraints rather than later additions.

Backend & Platform Engineering

  • Design, build and own scalable backend services in Node.js (TypeScript)
  • Architect and maintain REST APIs and microservices across the platform
  • End-to-end ownership: design → implementation → deployment → monitoring
  • Identify architectural risk, edge cases and scalability constraints early
  • Enforce clean architecture, SOLID principles and long-term maintainability

Security, Access Control & Auditability

  • Design and maintain authentication and authorisation systems (JWT, OAuth2, RBAC)
  • Build permission models and data access controls suitable for multi-tenant enterprise and sovereign deployments
  • Implement immutable audit logging and evidence lineage — every action logged, attributable and tamper-evident
  • Support data residency and segregation requirements across UK, EU and GCC jurisdictions
  • Maintain secure integration patterns with third-party services and internal components
  • Contribute to control evidence for ISO 27001 and Cyber Essentials Plus surveillance

Data, Integrations & Performance

  • Design and optimise PostgreSQL schemas, queries and indexing
  • Use Redis for caching, queues and performance
  • Integrate external services (APIs, messaging, email) with reliability and traceability
  • Support real-time features where applicable (Socket.io)
  • Work with S3-compatible object storage

Platform Reliability & DevOps

  • Docker-based containerisation and environment parity
  • Maintain and improve CI/CD pipelines (GitHub Actions or similar)
  • Cloud deployments, GCP-first (GKE, Cloud Run, Cloud SQL, IAM, Cloud Storage); on-premises and VPC deployment patterns for sovereign customers
  • Monitoring, logging, alerting and error tracking
  • Safe deployments, high availability, predictable releases

Required Experience

  • 3+ years professional backend engineering
  • Strong Node.js and TypeScript expertise
  • Production experience with Express, Fastify or NestJS
  • Strong SQL; deep PostgreSQL experience
  • Hands-on Redis
  • Microservices and distributed systems
  • Docker and CI/CD
  • Strong grasp of API security, authentication and RBAC
  • Demonstrable ownership of production systems, not ticket delivery
  • Comfortable making architectural decisions and defending the trade-offs

This role is not suitable for junior engineers or recent graduates.

Nice to Have

  • Google Cloud Platform, hands-on
  • Kubernetes (GKE) or managed container platforms
  • Observability tooling (Prometheus, Grafana, Sentry, GCP Monitoring)
  • Enterprise SaaS, compliance, or regulated-industry platforms
  • Exposure to audit, GRC or financial services systems

What We Offer

  • Ownership of infrastructure that enterprises and sovereign entities depend on to satisfy regulators
  • Fully remote, intially.
  • Competitive compensation; including equity and perfoemance based incentives.
  • High ownership, low bureaucracy — architectural decisions are made by the people building the system
  • A path into platform or technical leadership as the engineering function scales

More Info

About Company