← Live-Feed

Senior Full-Stack / Cloud Engineer – AI SaaS Compliance Platform (Next.js, FastAPI, PostgreSQL, RAG)

Budget: $1000.0 FIXED / ⭐ 0.00 (0) Ireland

web-services-development

Bevorzugte Qualifikationen

  • Erfahrung: Experte
Job description About the Project ASIY Solutions Limited is developing ComplianceOS, a multi-tenant SaaS platform designed to help organisations discover, assess, manage and evidence their use of AI, with an initial focus on AI governance and the EU AI Act. We already have substantial product planning completed, including: Product and screen feature specifications High-level system architecture Technical architecture User/profile definitions System workflows Core algorithms MVP and future-phase scope We are now looking for an experienced Senior Full-Stack / Cloud Engineer who can take these specifications and build the production-ready MVP. This is not a simple website or dashboard project. We need an engineer who is comfortable designing and implementing a secure multi-tenant SaaS application with AI/RAG functionality, regulatory workflows and cloud infrastructure. What you will build The initial ComplianceOS MVP will include: Multi-tenant organisation/workspace architecture Secure authentication and role-based access control (RBAC) ASIY Super Admin portal Customer Admin portal Compliance Manager profile Manager profile Employee profile Auditor/read-only profile Company onboarding AI/software inventory AI use-case registration and assessment EU AI Act regulatory mapping engine Compliance requirements and gap management Risk/readiness scoring Tasks and remediation workflows Policy management Approval and escalation workflows Incident management Employee compliance training Evidence repository Audit trail Compliance dashboards and reports Knowledge Base available within relevant user profiles Ask ComplianceOS, an AI-powered contextual compliance assistant Ask ComplianceOS An important part of the platform is an AI assistant that allows users to ask questions such as: “Can I upload this customer information to ChatGPT?” or: “Why does this AI system require additional review?” The system should use the user's role, organisation, AI system/use case, company policies and regulatory knowledge to provide a simple, contextual answer with supporting sources and recommended actions. We expect this to use a controlled RAG architecture, permission-scoped retrieval, structured outputs and appropriate AI guardrails. The LLM must not act as the authoritative regulatory decision engine. Regulatory mapping and workflow decisions should use deterministic/versioned rules where appropriate, while the LLM is primarily used for retrieval, explanation and contextual assistance. Proposed technology stack Our current proposed architecture is: Frontend Next.js TypeScript Responsive web application Backend Python FastAPI REST APIs Database PostgreSQL pgvector Infrastructure Docker Cloud deployment (AWS/Azure/GCP or suitable managed services) S3-compatible object storage Redis/queue architecture Background workers CI/CD Development, staging and production environments AI LLM API integration RAG Embeddings/vector search Structured AI outputs AI provider abstraction Prompt-injection protection Permission-aware retrieval We are open to well-reasoned technical recommendations rather than requiring the engineer to blindly follow the proposed stack. Key architecture requirements The platform must be designed for: Multi-tenancy Strong tenant isolation Server-side RBAC Object-level authorisation Secure APIs GDPR-conscious data handling Encryption in transit and at rest Audit logging Evidence versioning Background processing Scalable integrations Secure document processing Monitoring and error logging Backups and recovery AI security Prevention of cross-tenant RAG/data leakage Compliance and security need to be considered from the beginning rather than added after development. AI discovery The architecture should allow ComplianceOS to eventually discover software and AI tools used within an organisation. The MVP may begin with manual inventory and selected integrations. Future phases may include: Microsoft Entra / Microsoft 365 Google Workspace SSO/OAuth sources SaaS discovery Browser-based signals Endpoint/device agent Endpoint monitoring is not required for the initial MVP. The architecture should, however, be designed so that these capabilities can be added later. What we need from you We need someone who can do more than simply implement UI screens. You should be capable of: Reviewing our existing product and architecture specifications Challenging technical decisions where necessary Finalising database architecture Creating/implementing the database schema Designing APIs Building frontend and backend Implementing multi-tenancy Implementing RBAC Building workflow engines Implementing the regulatory rules architecture Integrating LLM/RAG functionality Building secure document/evidence storage Setting up cloud infrastructure Implementing CI/CD Testing Deploying the MVP Producing technical documentation Required experience We are particularly interested in engineers with strong experience in several of the following: Next.js React TypeScript Python FastAPI PostgreSQL SaaS architecture Multi-tenant applications REST API design AWS/Azure/GCP Docker CI/CD Authentication/RBAC LLM APIs RAG Vector databases/pgvector Background workers/queues Secure file storage Audit logging Application security Previous experience building B2B SaaS, RegTech, GRC, cybersecurity, compliance, enterprise workflow or AI governance products would be a major advantage. Deliverables The engagement should ultimately deliver: Technical review of our existing architecture and specifications Final database ERD/schema API design Development environment and repository setup Frontend application Backend/API Multi-tenant authentication and RBAC Core ComplianceOS modules EU AI Act rules/mapping architecture Ask ComplianceOS RAG implementation Evidence and audit architecture Cloud infrastructure CI/CD Automated testing Staging environment Production deployment Source code and infrastructure configuration Technical/deployment documentation Handover Important We are looking for an engineer who will build a maintainable product, not a prototype that becomes difficult to extend. All source code, infrastructure configuration, database migrations and technical documentation produced for the project must be delivered to ASIY Solutions Limited as part of the engagement.
Auf Upwork öffnen

AI proposal draft

Generate a short cover letter for this job. Edit before sending.

Sign in to generate an AI proposal draft.

Anmelden