
OVD226 - SENIOR BACKEND ENGINEER / TECHNICAL LEAD (PYTHON)

OVD226 - SENIOR BACKEND ENGINEER / TECHNICAL LEAD (PYTHON)
IT
Senior
Remote
Full-time
Responsibilities
This is our technical lead seat. You will own the backend architecture of the platform and set the engineering bar for a small, growing team - mentoring two junior engineers while still writing production code yourself. You will translate the product roadmap (MCP gateway, PIM/JIT, sensitivity classification, multi-agent trust graph) into well-architected, secure, scalable services, and you will be the person who makes the build/buy and design calls that keep us shipping.
You will split your time roughly 60% hands-on engineering, 40% technical leadership: code review, architecture, mentoring, and unblocking the team.
Own backend architecture for our identity-security platform - service boundaries, data models, APIs, and the MCP governance gateway.
Lead the engineering team: set standards, run code review, mentor a junior backend and junior frontend engineer, and grow their skills.
Partner with the Product Manager in developing and refining the PRD and Product Roadmap.
Build core capabilities: PIM/JIT for human, non-human and agent identities; integrations with Active Directory and Entra ID; cross-cloud posture (ISPM) with custom connectors.
Make the calls: architecture decisions, build-vs-buy, technical trade-offs, and security design reviews - documented as lightweight ADRs.
Own quality and delivery: CI/CD, testing strategy, observability, performance, and production reliability.
Embed security by design: threat modelling, secure coding, least privilege, and alignment to NIST / ISO 27001 in everything we ship.
You’ll work with:
Languages: Python (primary), PowerShell (Microsoft/AD automation), NoSQL (DynamoDB).
Cloud & infra: AWS (primary), GCP and Azure; containers (Docker), CI/CD, infrastructure-as- code.
Identity & Microsoft ecosystem: Active Directory, Entra ID, Microsoft Graph; OAuth2 / OIDC / SAML.
Platform: REST APIs, the Model Context Protocol (MCP), PostgreSQL, event-driven services.
Security tooling: ISPM, posture and threat-detection pipelines.
AI engineering: Claude Code, Codex, or Cursor as part of the daily workflow.
Requirements
4-6 years building and operating backend systems in production, with strong Python.
Proven experience designing distributed services and APIs on AWS (and/or Azure).
Track record of technical leadership - mentoring engineers, owning architecture, driving delivery
Strong security fundamentals: authentication/authorisation, secrets handling, least privilege, secure SDLC.
Hands-on, current use of AI coding tools (Claude Code, Codex or Cursor) and clear judgement about when to trust their output.
Excellent written communication - you can document a decision and explain a trade-off clearly.
*** Nice to have
Identity security or IAM background (AD/Entra ID, PIM/PAM, IGA, or NHI).
Experience with the MCP, agentic AI systems, or LLM application security.
Microsoft ecosystem depth (Graph API, PowerShell automation).
Familiarity with NIST, ISO 27001, ISO 42001 or the EU AI Act.
Early-stage / startup experience.
Benefits
Working location: Remote full-time (Vietnam time)
Salary range: Up to USD 2,000 gross
Infomation
Offered Salary
1,500 $ - 2,000 $
Skills

