Our Challenge
The platform is in daily use, and the next phase is the interesting part. Instead of asking people for evidence, we want to collect it directly from the systems that already hold it — and, where deterministic automation isn’t practical, have an AI agent prepare evidence for human review. That’s a genuine engineering problem: reliable integrations against a dozen different APIs, a scheduler you can trust, normalized evidence you can put in front of an auditor, and no shortcuts on security.
We’re bringing in a senior engineer on a contract basis to own that build with us.
Your Challenge
- Design and deliver production-grade evidence collectors that pull compliance evidence directly from our security, cloud, and identity tooling — configuration, scheduling, normalization, failure handling, and alerting included.
- Productize the collector framework so that adding the next integration is a well-trodden path rather than a new project.
- Take the remaining platform modules through to production cutover: role-based access from identity-provider claims, admin and audit-logging hardening, and enabling writes back to upstream systems.
- Build agentic evidence collection: an AI “compliance specialist” that interprets a control, designs and executes a review procedure over REST APIs and MCP servers, interacts with control owners in our collaboration tools, and hands its work to a mandatory human review gate.
- Keep the platform boringly reliable — database parity and migration safety in CI, observability, performance, and remediation of internal AppSec findings before anything reaches production.
- Work in the open with our Security & Compliance team: small frequent PRs, tests with the code, ADRs for decisions worth remembering, and documentation that outlives the engagement.
Our Tech Stack
- Backend: Python, FastAPI, SQLAlchemy + Alembic, APScheduler
- Data: PostgreSQL in deployment, SQLite locally and in CI
- Cloud & delivery: Docker on AWS (ECS/ECR), AWS Secrets Manager, Terraform, GitHub + GitHub Actions
- Integrations: REST APIs across our security, cloud, identity, and collaboration tooling; OIDC SSO; MCP servers for agentic workflows
- AI-assisted development: the codebase is built with AI coding tools and we expect you to use them — with full ownership of what you merge
What we are looking for:
- Senior backend experience with strong Python (FastAPI, SQLAlchemy/Alembic), or equivalent depth in a comparable stack and the appetite to work in ours.
- A track record of integrating third-party REST APIs in production: auth flows and token handling, pagination, rate limits, webhooks, retries, and the failure modes that only show up at 3 a.m.
- Working knowledge of AWS (ECS, Secrets Manager, IAM basics) and Docker; able to read and adjust Terraform.
- Strong testing habits and comfort in a documentation-heavy, review-driven workflow.
- A security mindset: least privilege, secret hygiene, and care when handling confidential data.
- Fluent English; Czech is welcome but not required.
Nice to have
- Hands-on experience with SIEM/SOC or security tooling APIs.
- Exposure to GRC and compliance automation (SOC 2, ISO 27001) or products like Vanta or Drata.
- Experience building LLM-agent workflows with tool use, or with Jira, Slack, or Notion APIs.
- Experience with observability stacks (Grafana, Prometheus).
Engagement details
- Contract (B2B/IČO), time & materials, monthly invoicing
- Part-time, 0.5 FTE (approx. 10 man-days per month)
- ASAP through 31 December 2026, with extension into 2027 by mutual agreement
- Remote within the EU, possible to work also from our Prague office
Ataccama is proud to be an Equal Opportunity Employer. We know diversity fuels knowledge exchange, fosters innovation, and empowers us to grow and be better as a company and as humans. We seek to recruit, develop, and retain the most talented people from a diverse candidate pool. We are committed to fair and accessible employment practices. If you are contacted for a job opportunity, please let us know how we can best meet your needs and advise us of any accommodations required to ensure fair and equitable access throughout the recruitment and selection process.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.