Senior Full-Stack / Cloud Engineer – AI SaaS Compliance Platform (Next.js, FastAPI, PostgreSQL, RAG)
Költségvetés: $1000.0
FIXED /
⭐ 0.00 (0)
Ireland
web-services-development
Előnyben részesített képesítések
- Tapasztalat: Szakértő
Job description
About the Project
ASIY Solutions Limited is developing ComplianceOS, a multi-tenant SaaS platform designed to help organisations discover, assess, manage and evidence their use of AI, with an initial focus on AI governance and the EU AI Act.
We already have substantial product planning completed, including:
Product and screen feature specifications
High-level system architecture
Technical architecture
User/profile definitions
System workflows
Core algorithms
MVP and future-phase scope
We are now looking for an experienced Senior Full-Stack / Cloud Engineer who can take these specifications and build the production-ready MVP.
This is not a simple website or dashboard project. We need an engineer who is comfortable designing and implementing a secure multi-tenant SaaS application with AI/RAG functionality, regulatory workflows and cloud infrastructure.
What you will build
The initial ComplianceOS MVP will include:
Multi-tenant organisation/workspace architecture
Secure authentication and role-based access control (RBAC)
ASIY Super Admin portal
Customer Admin portal
Compliance Manager profile
Manager profile
Employee profile
Auditor/read-only profile
Company onboarding
AI/software inventory
AI use-case registration and assessment
EU AI Act regulatory mapping engine
Compliance requirements and gap management
Risk/readiness scoring
Tasks and remediation workflows
Policy management
Approval and escalation workflows
Incident management
Employee compliance training
Evidence repository
Audit trail
Compliance dashboards and reports
Knowledge Base available within relevant user profiles
Ask ComplianceOS, an AI-powered contextual compliance assistant
Ask ComplianceOS
An important part of the platform is an AI assistant that allows users to ask questions such as:
“Can I upload this customer information to ChatGPT?”
or:
“Why does this AI system require additional review?”
The system should use the user's role, organisation, AI system/use case, company policies and regulatory knowledge to provide a simple, contextual answer with supporting sources and recommended actions.
We expect this to use a controlled RAG architecture, permission-scoped retrieval, structured outputs and appropriate AI guardrails.
The LLM must not act as the authoritative regulatory decision engine. Regulatory mapping and workflow decisions should use deterministic/versioned rules where appropriate, while the LLM is primarily used for retrieval, explanation and contextual assistance.
Proposed technology stack
Our current proposed architecture is:
Frontend
Next.js
TypeScript
Responsive web application
Backend
Python
FastAPI
REST APIs
Database
PostgreSQL
pgvector
Infrastructure
Docker
Cloud deployment (AWS/Azure/GCP or suitable managed services)
S3-compatible object storage
Redis/queue architecture
Background workers
CI/CD
Development, staging and production environments
AI
LLM API integration
RAG
Embeddings/vector search
Structured AI outputs
AI provider abstraction
Prompt-injection protection
Permission-aware retrieval
We are open to well-reasoned technical recommendations rather than requiring the engineer to blindly follow the proposed stack.
Key architecture requirements
The platform must be designed for:
Multi-tenancy
Strong tenant isolation
Server-side RBAC
Object-level authorisation
Secure APIs
GDPR-conscious data handling
Encryption in transit and at rest
Audit logging
Evidence versioning
Background processing
Scalable integrations
Secure document processing
Monitoring and error logging
Backups and recovery
AI security
Prevention of cross-tenant RAG/data leakage
Compliance and security need to be considered from the beginning rather than added after development.
AI discovery
The architecture should allow ComplianceOS to eventually discover software and AI tools used within an organisation.
The MVP may begin with manual inventory and selected integrations.
Future phases may include:
Microsoft Entra / Microsoft 365
Google Workspace
SSO/OAuth sources
SaaS discovery
Browser-based signals
Endpoint/device agent
Endpoint monitoring is not required for the initial MVP.
The architecture should, however, be designed so that these capabilities can be added later.
What we need from you
We need someone who can do more than simply implement UI screens.
You should be capable of:
Reviewing our existing product and architecture specifications
Challenging technical decisions where necessary
Finalising database architecture
Creating/implementing the database schema
Designing APIs
Building frontend and backend
Implementing multi-tenancy
Implementing RBAC
Building workflow engines
Implementing the regulatory rules architecture
Integrating LLM/RAG functionality
Building secure document/evidence storage
Setting up cloud infrastructure
Implementing CI/CD
Testing
Deploying the MVP
Producing technical documentation
Required experience
We are particularly interested in engineers with strong experience in several of the following:
Next.js
React
TypeScript
Python
FastAPI
PostgreSQL
SaaS architecture
Multi-tenant applications
REST API design
AWS/Azure/GCP
Docker
CI/CD
Authentication/RBAC
LLM APIs
RAG
Vector databases/pgvector
Background workers/queues
Secure file storage
Audit logging
Application security
Previous experience building B2B SaaS, RegTech, GRC, cybersecurity, compliance, enterprise workflow or AI governance products would be a major advantage.
Deliverables
The engagement should ultimately deliver:
Technical review of our existing architecture and specifications
Final database ERD/schema
API design
Development environment and repository setup
Frontend application
Backend/API
Multi-tenant authentication and RBAC
Core ComplianceOS modules
EU AI Act rules/mapping architecture
Ask ComplianceOS RAG implementation
Evidence and audit architecture
Cloud infrastructure
CI/CD
Automated testing
Staging environment
Production deployment
Source code and infrastructure configuration
Technical/deployment documentation
Handover
Important
We are looking for an engineer who will build a maintainable product, not a prototype that becomes difficult to extend.
All source code, infrastructure configuration, database migrations and technical documentation produced for the project must be delivered to ASIY Solutions Limited as part of the engagement.
Megnyitás Upworkön
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Bejelentkezés