Senior Full-Stack Engineer, Platform and Compliance (Node.js / GCP)
Summary
Part-time (50% capacity, ~4 hrs/weekday during US business hours) remote engineer who owns the whole platform of a QR-based physical access-control product for retailers: Node.js/Next.js product work on GCP, DevOps and reliability, plus end-to-end SOC 2 and ISO 27001 compliance leadership and hardware integration.
Senior Full-Stack Engineer, Platform and Compliance (Node.js / GCP)
| Remote | Part-time, 50% capacity: about four hours per weekday, worked during US business hours
Project makes secure mobile access simple. Retailers and grocers use our QR-based system to control access to restrooms, fitting rooms, and locked merchandise. A visitor scans a QR code on our signage, opens a lightweight web app in their browser (no app download, no account, no PII), and receives a one-time digital pass that opens the door. The platform maintains SOC 2 compliance and is live with national retail and grocery chains.
We are a small, senior, distributed team. You will be our primary engineer, working directly with our CTO and leadership. This is a part-time position at 50% capacity: roughly four hours each weekday, and those hours must fall within US business hours. Where you work is flexible; when you work is not. The role deliberately blends three things: product engineering, DevOps, and security compliance ownership. If you want narrow scope, this isn't the job. If you want to run the whole platform of a real product in the field, it is.
What you'll own
Product engineering. Our stack is Node.js and Next.js: a multi-tenant web application on Google Cloud that generates and validates one-time access credentials, plus the services and databases behind it. You'll ship features, fix what's broken, and steadily improve the codebase.
Platform and DevOps. The full GCP footprint: services, managed databases, IAM, secrets management, backups and tested restores, and cloud cost. CI/CD and release engineering with safe, reversible deploys (we use Bitbucket with a PR-based workflow).
Reliability. Monitoring and alerting (Sentry for errors, BetterStack for uptime), incident response, and real root-cause discipline: no production changes before diagnosis, and postmortems that actually change things.
Security and compliance leadership. You own our SOC 2 program end to end: controls, evidence collection, and audit cycles, managed in Drata with our external auditor. You will also lead our ISO 27001 certification, from gap analysis and ISMS scoping through risk assessment, controls, policies, and the certification audit.
Provisioning tooling. Config-file-based device provisioning across our product SKUs, QR and signage file generation, and our internal sign-to-door linkage app. Part of this job is documenting and automating these workflows so they never depend on a single person.
Hardware integration. Our credentials are validated by access-control hardware running our OEM partner's firmware (Wiegand protocol). You'll work with the partner's engineers on integration and field issues, define test cases, and represent engineering in those conversations.
Data and support. Software-side support escalations and usage reporting (Looker Studio), in partnership with our operations team.
What we're looking for
5+ years building and running production web applications, including meaningful time as the owner of a system, not just a contributor to one.
Expert-level Node.js and production experience with Next.js, plus solid relational database and API design skills.
Hands-on GCP experience: deploying and operating services and managed databases, IAM, monitoring, and cost management. Strong AWS/Azure backgrounds welcome if you can come up to speed on GCP fast.
Real DevOps chops: CI/CD pipelines, environment management, secrets handling, backup and restore you've actually tested.
Compliance experience you've lived, not just read about: you've carried a SOC 2 program through at least one audit cycle (Drata, Vanta, or similar), and you've led or materially contributed to an ISO 27001 implementation, or are ready to lead one with auditor support.
Operational maturity: you've been the person responsible when things broke. You care about root cause before fixes, reversible changes, and writing things down.
Comfort in a small company: self-directed, pragmatic, and a strong written communicator. We run on Notion and Slack.
Availability for about four hours per weekday, scheduled during US business hours. This is essential, not preferred: our team, customers, and hardware partner all operate on US time, and daily presence in our tools during those hours is part of the job.
Nice to have
Physical access control, IoT, or other hardware-adjacent software experience (Wiegand, credential systems, embedded/firmware coordination).
ISO 27001 Lead Implementer training or equivalent.
Infrastructure-as-code experience (Terraform or similar).
Looker Studio or similar BI tooling.
Time as the sole, founding, or first engineer at a startup.
How we work
Low ceremony, high trust. A weekly product meeting keeps everyone aligned; the rest is written communication and focused work. You'll have direct access to a hands-on CTO, and your work will be visible to customers within weeks, not quarters.
Hiring process
[HR + Tech → Intro call with CTO → technical conversation on a real system you've owned → references → offer.]
