Full-time contractorm, potential conversion to permanent· Tier-1 India (Bangalore, Hyderabad, Chennai, Pune, Mumbai, Delhi NCR) · Remote-friendly · Reports to the CTO
Leadership and delivery accountability
You are the single accountable owner for technical delivery through to General Availability. This is not a contributor role with a lead above you.
- End-to-end delivery ownership: you hold accountability for every workstream in the product surface, covering application, authentication, billing, CI/CD, security coordination, and launch. Milestone gates do not close without your sign-off on the product-surface evidence package.
- Lead the build phase: own the delivery plan, track progress against milestones, and surface risks and blockers in writing before they become slippage. The CTO is the architecture escalation point, not the day-to-day delivery manager. That is you.
- Coordinate and direct specialists: direct the fractional designer, external legal counsel, and penetration-testing vendor. You translate product and compliance requirements into actionable briefs, integrate their outputs, and hold the delivery line. You do not need to be the expert in each specialism. You need to ensure the right work gets done by the right person at the right time.
- Manage delivery risk proactively: identify slippage before it happens, not after. Escalate scope or capacity risks early and in writing. If a track is at risk, raise it and trigger the relief valve rather than absorbing silently.
- Set and maintain engineering standards: code review, test coverage, architecture decision records, and launch-readiness criteria are not optional. You own them as the senior technical voice on the product surface.
Customer-facing application
- Onboarding wizard: deliver the flow that captures product and facility data, pre-populated from a public-data ingestion layer where available, guided entry where not.
- Core surface: build the bill-of-materials capture, the results dashboard covering screening output, hotspots and confidence tiers, and the improve-loop prompts that let customers contribute more data to raise their confidence score.
- Report builder: produce the branded, externally sendable screening report. You render and format the compliance-readiness mapping the calculation pipeline provides. You do not author the regulatory mapping logic.
- Work with a designer: a fractional product designer owns onboarding UX and the design system. You integrate their work and take it to production quality. Contemporary AI scaffolding tools are used to generate components. Your job is integration, wiring to the calculation API, and hardening.
- Milestone: a working end-to-end flow (sign up, complete profile, see result) on staging by the five-month milestone, then beta-harden through user observation.
Authentication and multi-tenancy Own the security layer that makes the product enterprise-grade from day one, as an integration rather than a from-scratch build.
- Identity platform integration: self-serve sign-up and SSO (passwordless and OAuth), with no accounts created on users' behalf. A managed identity platform and cloud-native row-level security do the heavy lifting. Your work is entitlements, the org, team and seat model, and hardening.
- Tenant isolation: row-level security, AES-256 at rest, TLS 1.3. The acceptance criterion is absolute: one tenant cannot read another tenant's data.
- Build account-management UI,
data-handling terms at sign-up, and a compliant account-deletion path.
- Co-own validation: cross-tenant isolation validated with the cloud architect at the private beta milestone.
Billing and usage metering
- Billing platform integration: subscription billing covering plan tiers, recurring charges, self-serve upgrade and downgrade, dunning and invoicing. Integration, not a billing system built from scratch.
- Metering cap (non-delegable): wire usage metering to the calculation API. The per-tenant cap is the primary guardrail against inference costs eroding margin, and you validate every threshold personally. This is a financial control.
- End-to-end: sign-up, plan, payment, auto-provision, confirmed in a sandbox environment before launch, plus a human billing test run at launch.
AI pipeline interface
- Surface outputs correctly: the pipeline's confidence-tiered outputs (result, lineage, provenance, compliance-readiness map) reach the app intact. No unlabelled numbers reach the customer interface.
- Co-own integrity with the CTO and AI/ML engineer: the surface must never present a low-confidence estimate as high-confidence.
- Flag pipeline-to-surface mismatches as blockers before milestone reviews.
CI/CD, quality and operations
- CI/CD: GitHub Actions, infrastructure-as-code, and dev, staging and prod separation. Environments live and CI green at the mobilisation milestone.
- Tests: automated suites on all AI-scaffolded code. Nothing AI-generated reaches production without human review and coverage.
- Observability and on-call: stand up an observability stack and the initial on-call path. The ongoing support function and on-call rotation transition to a growth and support hire at private beta. You are not the permanent on-call.
- Reproducibility: maintain short architecture decision records so the work is transferable.
- Launch runbook: author it, execute on staging, test rollback, and obtain dry-run sign-off.
Security and data-protection readiness
- Penetration test: coordinate the external test and remediate findings to a no-critical, no-high bar before General Availability.
- Data protection: implement controls to external counsel's specification, covering privacy-policy surfacing, DPA and SCCs, data-subject-request flows, and region-aware EU-default residency under GDPR and DPDP. Counsel owns the legal drafting. You own the implementation.
Milestone gates and launch
- Gate evidence: assemble the product-surface evidence package at each milestone. The programme manager combines workstream evidence and the CTO signs.
- GA co-sign (non-delegable): co-sign the launch with the CTO. Both signatures are required. This and the tenant-isolation sign-off are the human-owned gates.
- Handover: taper toward launch handover after private beta and ensure the support runbook and SLA are operational before launch week.
Scope and escalation This is a scoped role, not an unbounded one.
- Specialists own the specialist work. Design,
legal and penetration testing are owned by the people you work with, not by you.
- A relief valve exists. If the application or billing track slips at a milestone, a short-term contract front-end or QA resource is added rather than expecting you to absorb the overflow.
- Independence: escalate architecture questions to the CTO. You do not need the CTO in the loop on product-surface implementation. That independence is the structural requirement the role is built around.
Required qualifications
- React: production-grade component architecture, API integration, state management. You can take an AI-scaffolded or designer-provided component to production quality.
- Backend integration: REST APIs, multi-tenant data boundaries, billing webhooks, without backend-engineering supervision.
- Auth and multi-tenancy: SSO, OAuth and OIDC, a managed identity platform or equivalent, row-level security. You treat tenant isolation as a security requirement, not a config option.
- Billing: a modern subscription billing platform covering lifecycle, metering, webhooks and dunning. Usage-based billing is a strong plus.
- CI/CD and DevOps: GitHub Actions, environment management, infrastructure-as-code, observability tooling.
- Security fundamentals: encryption at rest and in transit, GDPR and DPDP data minimisation, account-deletion flows. Not a security specialist, but you know what correct looks like and can coordinate one.
- Document generation: Puppeteer, WeasyPrint or equivalent branded export pipelines.
- Fluent with modern AI coding tools as force multipliers, not shortcuts around standards, and able to review, validate and harden AI-generated code to production with automated tests as the safety net.
- Clear-eyed on where AI tooling is not appropriate: billing-cap logic and tenant-isolation decisions are human-owned, always.
- Delivery leadership: demonstrable experience leading technical delivery of a product or significant workstream end to end, not just contributing to one.
- Cross-functional coordination: experience directing external specialists toward a delivery outcome. You can brief a designer, instruct a vendor, or coordinate with legal counsel unsupervised.
- Risk and escalation discipline: you surface delivery risks early and in writing, and you distinguish between what you can resolve independently and what needs founder-level input.
- Startup pace without startup sloppiness: code that would survive an enterprise security review.
- Precise written communication: status, blockers and evidence are written artefacts in an async, distributed team.
Preferred qualifications
- B2B SaaS built and launched end to end, including billing and auth.
- Multi-tenant architecture on a major cloud platform.
- Enterprise compliance exposure: GDPR data-subject rights, DPDP, data residency, DPA and SCC context.
- Observability from scratch: alerting, on-call runbooks, incident response.
- Curiosity about sustainability, ESG or carbon accounting. Domain knowledge is not required.
Experience and education
- Bachelor's degree in Computer Science, Software Engineering or a related field.
- 5 to 7 years' qualified software engineering experience, with 2 or more in a senior or lead capacity.
- Demonstrated shipping of production B2B SaaS, owning deployment, monitoring and go-live, not just features.
- Full-stack breadth: React frontend, REST integration, auth and billing, CI/CD, operational readiness.
📌 Product Lead (Senior Full-Stack Engineer) (India)
🏢 Colleve
📍 India