Principal Engineer - Founding Architect (India)

Principal Engineer - Founding Architect (India)

04 Aug
|
Emeritus
|
India

04 Aug

Emeritus

India

Principal Engineer — Founding Architect

Enterprise Platform · Architecture, Identity & Data Core Function:Platform Engineering

Level:Principal (L6)

Location:Remote (India)

Type:Full-time About the role

We are building a multi-tenant platform that Fortune 1000 L&D; teams use to procure, configure, and deliver premium executive education inside the tools their people already use. The product is moving from validated prototype to full-scale production, and the architecture is still an empty repository.

This is the first architectural hire on that platform. You will make the decisions everything else is built on top of: the repository structure, the service boundaries, the identity and entitlement model, and the event contract that becomes the platform's long-term data asset. What you'll own

Architecture and the technical spine (primary mandate)

Repository structure, service boundaries, and the Architecture Decision Record practice that keeps them honest. One monorepo, one tree - several workflow-specific product surfaces sharing a single identity domain, data model, and event pipeline.

Tier-differentiated data access, enforced at the identity and IAM layer rather than in the UI - such that a service belonging to one commercial tier has no credential path to another tier's data, even under arbitrary code execution. You will design both the enforcement model and the CI harness that proves it.

The canonical event contract. Every meaningful event on every surface flows through one pipeline, because the longitudinal data asset it produces cannot be reconstructed retroactively. Instrumentation is a precondition of merge, not a follow-up ticket.

The multi-tenant data model, the isolation strategy, and the documented migration triggers that decide when the analytics tier separates from the transactional one - settled in advance, not under load.

Hands-on delivery

Write production code. This is a hands-on Individual Contributor role, and we expect the architecture to be legible in the commits, not only in the diagrams.

Build the platform spine yourself rather than specifying it for someone else.

Own reliability, security, and performance for a platform handling enterprise customer identity and employee data.

What we're looking for

Must-have

10+ years engineering, with 3+ at Staff, Principal, or Architect level - including more than one multi-tenant B2B SaaS product you took from an empty repository to paying enterprise customers, where you made the architectural decisions rather than implementing someone else's.

Python 3.10+ with a modern typed async web framework, or Go - our backend is FastAPI on Python 3.12 with Pydantic v2. Django with async, Litestar, Flask, or Go are all accepted backgrounds - we expect you to be productive in FastAPI within weeks, if you don’t have experience on it already.

TypeScript, with enough front-end literacy to hold an API contract honest - our front end will be Next.js 14 with the App Router. You do not need to have written it; you do need to be able to read it and argue about it.

PostgreSQL 14+ at depth - query planning with EXPLAIN ANALYZE, indexing strategy, partitioning, connection pooling,



and zero-downtime schema migration against live customer data. We will run Postgres with the TimescaleDB extension.

Multi-tenant isolation designed and shipped in production - PostgreSQL row-level security, schema-per-tenant, or database-per-tenant - and you can explain the failure modes of the two approaches you did not choose.

Enterprise identity as an implementer - SAML 2.0, OIDC / OAuth 2.0, SCIM 2.0 - you have built the provider side (assertion signing and validation, JIT provisioning, token lifecycle), not only configured Auth0, Okta, or Firebase Auth as a consumer.

Cloud-native architecture with infrastructure-as-code - we run on GCP - Cloud Run, Cloud SQL, Pub/Sub, Memorystore, Workload Identity Federation - with Terraform throughout. Deep AWS or Azure experience transfers

- Terraform is not optional.

Event-driven architecture in production - we use Google Pub/Sub

- Kafka, Kinesis, or equivalent transfers directly. You have designed an event schema with explicit delivery, ordering, and idempotency guarantees, and lived with it.

Agentic AI development tooling in daily use - we use Claude Code/Codex as a first-class part of the workflow

- Cursor, Copilot Workspace, or equivalent are fine. Harness, Loop Engineering knowledge required. Expect to discuss specific workflows, where the tools help, and where you have learned not to trust them.

Nice-to-have

L&D;, EdTech, or HR-Tech domain background.

Analytics and warehouse pipelines at production scale - dbt, BigQuery, or Snowflake.

Prior first-architect experience at a product company.

Public artifacts - written ADRs, conference talks, meaningful open-source contributions.

Requirements at a glance Experience

10+ yrs total; 3+ yrs Staff / Principal / Architect

First architect at a product company

Backend language

Python 3.10+ with a typed async framework, or Go

FastAPI + Python 3.12 + Pydantic v2

Frontend literacy

TypeScript; able to read and review React

Next.js 14 App Router Database

PostgreSQL 14+ - indexing, partitioning, live migration

TimescaleDB; an executed warehouse migration

Tenancy

Shipped RLS, schema-per-tenant, or DB-per-tenant

Migrated a live system between two models

Identity

SAML 2.0, OIDC / OAuth 2.0, SCIM 2.0 - provider side

Okta, Entra ID, Ping, Google Workspace

Cloud

GCP, AWS, or Azure in production

GCP: Cloud Run, Cloud SQL, Memorystore

IaC

Terraform

Workload Identity Federation

Events

Pub/Sub, Kafka, or Kinesis in production

Google Pub/Sub; schema registry

Security posture

Has worked under enterprise security review

SOC 2 Type II or ISO 27001 delivered

AI tooling

Claude Code, Cursor, or equivalent in daily use

Claude Code — our stack; drove team-level adoption THE ARCHITECTURAL SURFACE





These are the decisions that will be yours in the first six months. We are looking for someone who reads this list and finds it interesting rather than daunting.

Decision and What you'll design against it

Tier-differentiated access

Commercial entitlements enforced at the identity and IAM layer, with a CI harness that fails the build when the boundary is violated in code.

Canonical event pipeline

Every event on every surface, emitted from commit one, because the longitudinal data asset cannot be rebuilt after the fact.

One repo, many surfaces

Several distinct product experiences over a shared network and data core, held in a single tree as the team grows from three engineers to thirty.

Multi-tenant data model

Tenant isolation, secrets and credential handling, authz, and privacy for customer employee data.

Enterprise identity

SAML 2.0, OIDC, and SCIM 2.0 as provider-side implementations against Okta, Entra ID, Google Workspace, and Ping.

Migration triggers The documented conditions under which the analytics tier separates from Postgres — decided in advance, not during an incident. What success looks like — first 90 days

Days 1–30 — Monorepo scaffolded; environments and IAM separation live; the first three ADRs written and argued through

- CI/CD pipeline running.

Days 31–60 — Identity, tenancy, and entitlement service in production; the tier-boundary enforcement harness passing in CI and failing the build when violated.

Days 61–90 — Event pipeline v1 emitting from the first product surface; hiring bar defined, loops running, first two offers out.

Our stack.

Frontend: Next.js 14, TypeScript.

Backend: FastAPI, Python 3.12.

Data: PostgreSQL with TimescaleDB, Pub/Sub, dbt.

Infra: GCP (Cloud Run, Cloud SQL, Pub/Sub, Memorystore Redis, Vertex AI Vector Search), Terraform, Workload Identity Federation.

Intelligence layer: Anthropic Claude API.

Tooling: Claude Code as a first-class part of our development workflow.

A note on scope. This is a hands-on architecture and platform Individual contributor role. It is not a solutions-architect role - customer-facing implementation, integration scoping, and customer identity onboarding are owned by a separate function.

It is not an engineering-management role - we treat management as a separate track rather than a promotion, and staff and principal IC is a viable terminal level here. AI/ML model development is owned by a separate, dedicated hire. If any of those three is what you are looking for, this isn't that role How we work

Small, senior, high-trust team. We move fast, we write things down, and we hold a high engineering bar. You'll have real ownership and direct line of sight from your code to enterprise customers going live. We value people who can defend their design decisions clearly, take well-reasoned pushback, and make rapid calls once convinced.

We are distributed across India and documentation-first: written decisions, service READMEs, and runbooks carry more weight here than meetings. AI development tooling is a working expectation rather than a preference - we screen for judgment in how you use it, and we evaluate the leverage you get from it.

📌 Principal Engineer - Founding Architect (India)
🏢 Emeritus
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: principal engineer - founding architect (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: principal engineer - founding architect (india) / india