Founding Engineer / Hands-On Head of Engineering
Nenn · Santa Rosa Valley, CA, US
Apply directly on Nenn’s careers site — no account needed. You’re early — this listing comes straight from the source, before the big boards.
About the role
Role Overview
NENN is seeking a Founding Engineer / Hands-On Head of Engineering to serve as the company’s sole engineer and complete technical owner during its initial stage. This is a deeply hands-on role. You will be responsible for building, securing, deploying, operating, and scaling the entire product—from the user interface and backend services to the database, Cloud infrastructure, payments, monitoring, and production support. NENN’s PIMS platform is an AI-assisted MVP containing AI-generated components. Your first priority will be to audit the existing application, identify hidden architectural, security, data-integrity, and operational risks, and transform it into a stable, secure, and maintainable production platform.
Core Responsibilities
Full- Stack Product Development
- Build and maintain responsive, accessible, and reliable user interfaces using React, Next.js, or a comparable framework.
- Develop secure and maintainable backend services using Node.js, Python, or another modern server-side technology.
- Translate business and product requirements into technical plans, milestones, and production releases.
- Establish consistent coding standards, reusable components, shared patterns, and API contracts.
- Develop complete features across the frontend, backend, database, and infrastructure.
- Improve application performance, accessibility, reliability, and usability.
- Balance new feature delivery with security, platform stability, and technical debt.
- Determine when existing AI-generated components should be repaired, replaced, simplified, or removed.
Architecture and MVP Stabilization
- Audit the existing frontend, backend, database, APIs, integrations, and hosting environment.
- Identify structural weaknesses and hidden risks introduced by rapid or AI-assisted development.
- Define a simple, scalable architecture with clear service boundaries, data flows, and ownership.
- Refactor prototypes and AI-generated code into production-grade systems.
- Create separate development, testing, staging, and production environments.
- Define production-readiness standards and release criteria.
- Maintain architectural decision records, system diagrams, technical documentation, and operational runbooks.
AI Automation and Virtual Coding Team
- Build and supervise AI agents to assist with frontend development, backend services, database work, AWS infrastructure, testing, documentation, and security analysis.
- Develop reusable prompts, technical context, templates, and workflows that improve AI-agent consistency while preventing conflicting changes and architectural drift.
- Establish automated workflows for code generation, review, testing, validation, documentation, and deployment preparation.
- Review AI-generated code for incorrect assumptions, unsafe queries, fabricated dependencies, security vulnerabilities, and unnecessary complexity.
- Maintain direct human oversight of database migrations, infrastructure changes, security controls, payment logic, and production releases.
- Prevent AI agents from independently accessing sensitive production data or deploying unverified changes.
SQL and Data-Layer Ownership
- Design and maintain normalized relational database schemas using PostgreSQL, MySQL, or an equivalent database.
- Review and correct AI-generated schemas, migrations, queries, and data-access code.
- Write and optimize complex SQL queries.
- Develop appropriate indexing strategies and analyze query execution plans.
- Protect data integrity through constraints, validation, transactions, and safe concurrency patterns.
- Identify and resolve duplication, inconsistency, race conditions, and incomplete data states.
- Implement audit trails, data lineage, retention policies, and reporting structures where required.
- Implement database backup, restoration, and disaster recovery processes.
- Maintain data integrity during concurrent operations, integration failures, and partial system outages.
Cloud Infrastructure and Cloud Operations
- Design, implement, and operate a secure, reliable, and cost-conscious AWS environment.
- Select the smallest appropriate set of managed AWS services for the platform’s requirements.
- Work with services such as Amazon RDS or Aurora, ECS or Lambda, S3, CloudFront, Route 53, API Gateway, Elastic Load Balancing, SQS, SNS, and EventBridge as appropriate.
- Design secure VPCs, network boundaries, security groups, and access controls.
- Implement least-privilege permissions using AWS Identity and Access Management.
- Manage application secrets and encryption keys using AWS Secrets Manager and AWS Key Management Service.
- Use infrastructure as code through Terraform, AWS CDK, or CloudFormation.
- Design for availability, fault tolerance, horizontal scaling, and operational simplicity.
- Implement centralized logging, metrics, tracing, alerting, and audit records through services such as CloudWatch and CloudTrail.
- Establish backup, restoration, disaster recovery, and business continuity procedures.
Security, Privacy and Risk Management
- Conduct application and cloud security assessments aligned with OWASP and AWS security practices.
- Identify vulnerabilities involving authentication, authorization, sessions, APIs, frontend code, database access, cloud infrastructure, and third-party services.
- Implement secure authentication and role-based access control.
- Apply least-privilege principles across the application and AWS environment.
- Establish secure secrets, credentials, and encryption-key management.
- Add dependency scanning, static analysis, secret detection, container scanning, and infrastructure security checks to CI/CD.
- Define and maintain security logging, anomaly detection, breach detection, and incident-response procedures.
- Clearly communicate security risks and recommend outside specialist assessments when appropriate.
Stripe Payments and Billing
- Architect and implement secure Stripe integrations.
- Support subscriptions, one-time payments, invoicing, refunds, and billing workflows as required.
- Maintain a PCI-safe design that does not store sensitive card information.
- Validate Stripe webhook signatures and protect against spoofing and replay attempts.
- Implement idempotent webhook and payment processing.
- Prevent duplicate charges, race conditions, and inconsistent payment states.
- Build reconciliation processes, payment audit trails, and operational reporting.
- Implement recovery procedures for failed, delayed, or out-of-order payment events.
APIs and Third-Party Integrations
- Design, build, document, and maintain secure REST or GraphQL APIs.
- Establish consistent standards for authentication, authorization, validation, versioning, and error handling.
- Evaluate third-party services for reliability, security, cost, and failure modes.
- Implement appropriate timeouts, retries, exponential backoff, queues, and dead-letter handling.
- Design integrations that remain resilient during partial outages and degraded service conditions.
- Monitor integration health and create recovery procedures for failures.
DevOps, Tesing and Production Operations
- Build and maintain CI/CD pipelines covering the frontend, backend, database, and infrastructure.
- Automate unit, integration, end-to-end, accessibility, performance, and security testing.
- Establish protected branches, required reviews, automated quality gates, and release approvals.
- Use feature flags, staged deployments, and rollback procedures where appropriate.
- Create and maintain development, staging, and production environments.
- Define service-level objectives, health checks, and production-readiness criteria.
- Lead performance testing, release validation, and capacity planning.
- Maintain deployment procedures, operational documentation, and recovery runbooks.
Technical Leadership and Business Partnership
- Serve as the primary technical partner to NENN’s leadership team.
- Communicate technical risks, dependencies, costs, tradeoffs, and schedule impacts clearly.
- Protect essential security, reliability, and data-integrity work from being displaced by lower-priority features.
Required Qualifications
- Five or more years of professional full-stack software engineering experience.
- Demonstrated experience independently owning and delivering production software.
- Strong frontend development experience with React, Next.js, or a comparable framework.
- Strong backend development experience with Node.js, Python, Java, .NET, or a comparable technology.
- Expert-level SQL skills.
- Extensive experience with PostgreSQL, MySQL, or another relational database.
- Hands-on experience designing, deploying, and operating production systems on AWS.
- Working knowledge of AWS IAM, networking, managed databases, monitoring, security, and cost management.
- Experience with infrastructure as code and CI/CD automation.
- Experience designing and integrating secure APIs and third-party services.
- Experience with Stripe or another payment-processing platform.
- Proven ability to audit, repair unfamiliar or rapidly developed codebases.
- Ability to validate AI-generated code rather than treating it as trusted output.
- Strong debugging, systems thinking, prioritization, and technical decision-making skills.
- Ability to work independently in a fast-moving startup with limited resources and evolving requirements.
- Strong written communication and technical documentation skills.
Preferred Qualifications
- Previous experience as a founding engineer, principal engineer, technical lead, or hands-on head of engineering.
- Experience operating as the sole engineer or as part of a very small startup team.
- Familiarity with LLM APIs, agent frameworks, retrieval systems, prompt management, and AI evaluations.
- Experience with Terraform, AWS CDK, or CloudFormation.
- Experience with Docker, ECS, serverless applications, and event-driven architecture.
- Experience with SaaS, operational logistics, or multi-tenant platforms.
- Familiarity with SOC 2, HIPAA, PCI DSS, GDPR, or comparable compliance requirements.
- AWS certifications such as Solutions Architect, Developer, DevOps Engineer, or Security Specialty.
Compensation
$150,000–$200,000 annually, commensurate with experience.
Pay: $150,000.00 - $200,000.00 per year
Work Location: In person
Description sourced from the public Indeed listing — this role isn't indexed from the company's career page yet.
Never be applicant #200 again
Every job here is indexed straight from company career pages — often hours after it opens, before it reaches the big boards. Create a free account and get your best matches in a twice-daily digest.
- Your best matches, twice a day
- No duplicates, no ghost jobs, no recruiter spam
- Every job free to browse — pay only when you apply
Free account — no card required
93 161 live jobs · 17 643 companies tracked · 6 170 added today