Featured jobs

Remote Fullstack Engineer (AI & Automation Experience)

fram^ is looking for the Remote Fullstack Engineer.

This is an AI-native platform that lets Swiss fiduciary firms manage client bookkeeping, payroll and compliance through a WhatsApp-first workflow, backed by a Next.js/Supabase application and n8n automation. We’re hiring a backend-leaning full-stack engineer to close a critical security backlog, stabilise the platform for production use, and lay the operational groundwork — CI/CD, observability, staging — needed to onboard more customers safely. You will work directly inside the existing single-contributor codebase, take full ownership of the n8n automation layer, and be one of two engineering hires driving the technical roadmap (the other being an AI/Agent Engineer).

Responsibilities

  • Remediate the platform’s active security exposure: enforce authentication and row-level security (RLS) on every API route; close public database policies exposing payroll and client data; fix a tenant-isolation bug that allows cross-tenant access
  • Replace n8n’s direct database master-key access with an authenticated ingestion API that derives tenant identity server-side — removing the single largest operational risk in the automation layer
  • Design and implement a background job queue for heavy, currently synchronous document processing (PDF/XLSX extraction, multi-account imports) to remove request-timeout failures
  • Make cloud storage private (signed URLs, UUID paths) and put the database schema into version control, paired with a real staging environment
  • Build CI/CD pipelines, automated tests — including tenant-isolation regression tests — and baseline observability (logging, monitoring, alerting)
  • Harden and maintain the n8n workflows that run the WhatsApp document-intake and accounting-automation flows, including error handling, idempotency, and a dead-letter/retry path
  • Implement data-subject-rights tooling (export/erase) and an append-only accounting ledger with reversal entries, in coordination with the company’s external data-protection advisor
  • Redact personal data from application logs and enforce least-privilege access patterns throughout the stack
  • Collaborate with the AI/Agent Engineer on backend integration points for the LLM-driven agent — tool authorization checks, audit logging of agent actions. 

Qualifications

  • 4+ years of professional experience with Node.js/TypeScript in production backend systems
  • Strong hands-on experience with Next.js (App Router) and building/maintaining REST and webhook APIs
  • Deep, practical knowledge of PostgreSQL, including Row-Level Security (RLS) policy design and multi-tenant data isolation
  • Production experience with Supabase, or an equivalent BaaS (Firebase, AWS Amplify) — auth, storage and database
  • Experience with n8n, Zapier, or a comparable workflow-automation tool, ideally including securing/hardening automations that touch production data
  • Working DevOps fluency: CI/CD pipeline design (GitHub Actions or equivalent), staging environments, secrets management, and basic monitoring/alerting setup
  • Solid understanding of authentication/authorization patterns and common web-application security pitfalls (mass assignment, privilege escalation, injection)
  • Comfortable working in and improving a codebase with minimal existing test coverage or documentation — you will be establishing the engineering discipline, not just following it
  • Clear written communication in English; able to work asynchronously across time zones. 

Nice to have 

  • Experience with Swiss or EU data-residency / GDPR-driven architecture decisions
  • Familiarity with double-entry accounting systems, or fintech/regtech products generally
  • Experience integrating LLM-based agents into a production backend (tool-calling, audit trails)
  • Prior experience as the sole or lead engineer on a live production system (start-up background)

Apply now