# Founding Security & Backend Engineer (Part-Time, Contract)

Cliente Freelancer · Remoto · Remoto · freelance · mid · 8–15 USD

Publicada el 2026-08-03

Descripción de la oferta

**CLIQ** · Remote (US) · 10–20 hrs/week · Contract with equity --- ## The short version CLIQ helps older adults keep control of their financial lives while giving the people who love them a way to help — without spying on them, and without taking their independence away. That "without" is the entire product, and it lives in the backend. We're looking for one experienced engineer, part-time, to own the security and backend surface of a product where getting authorization wrong is not a bug — it's a betrayal of the person we exist to protect. ## Why this role exists Our founder is non-technical by training and has built the product to this point with a rigorous AI-assisted engineering system: a normative backend specification where every rule carries an ID, contract tests keyed to those IDs, merge gates, and independent review passes. It has taken us further than it has any right to. What it cannot do is replace an engineer who has personally been on the wrong end of a security incident and thinks differently because of it. That's the gap. That's you. You will not be handed a vague mandate. You'll be handed a written spec with numbered rules and asked, first, to tell us where it's wrong. ## What you'd own **The authorization model.** CLIQ's rules about who can see and do what *are* the product, and their correctness is the job. You'd own that model in code: the pure policy functions, the explicit serializer field whitelists, the audit wrapper on every mutation. **Authentication.** We hand-rolled it, deliberately — sessions, magic-link email sign-in, staff password + TOTP, WebAuthn passkeys — on Node's built-in `crypto` with `@simplewebauthn` as the only third-party dependency in the path. It's built to a documented set of non-negotiables covering secret handling, enumeration, rate limiting, and auditing. You'd own it, review changes to it, and tell us honestly which parts of hand-rolling it were a mistake. **The credential-handling design.** Our highest-sensitivity workstream — masked rendering and credential storage — is deliberately gated behind a cryptographic design document that has not been signed off. Nothing ships there until the design is right. Being the person who writes and defends that document is the most consequential part of this job. **Data and schema.** Postgres via Drizzle, migrations, constraints that encode the rules rather than trusting the application layer to remember them. **The review bar.** Every change to a sensitive path gets your eyes. Realistically this becomes a meaningful share of your hours, and it should. **Optionally, mentorship.** We may sponsor a university capstone team on clearly separated, non-critical-path work. If mentoring is something you enjoy, there's room for it and we'd value it. If it isn't, that's completely fine — this role is technical ownership first. We would rather have your judgment than your management. ## Our stack - **TypeScript** end to end - **Next.js 15** (App Router, route handlers — thin, no business logic in them) + **React 19** - **Drizzle ORM** + **Neon Postgres** - **Vitest**, including contract tests named after the spec rule they enforce - **Vercel** for deploys - Auth on `node:crypto` + `@simplewebauthn`. No Auth0, no NextAuth/Auth.js. - A Chrome extension (Manifest V3) as a second client surface House pattern, so you know what you're walking into: route handler parses and rate-limits → service function → pure policy function decides → explicit DTO serializer → mutation wrapped in an audit transaction. Business logic never lives in a route handler. Nothing is serialized by spreading a database row. ## What we need you to have **Required** - **5+ years building production backends**, with real ownership of something where a security failure had consequences — fintech, health, payments, identity, or similar. We care much more about the weight of what you've protected than the logo you protected it at. - **Deep, practiced application-security judgment.** Not "I've read the OWASP Top 10" — you've designed an authorization model, found the hole in someone else's, and can explain why a given design is wrong in terms of what an attacker actually does. - **Hands-on with authentication internals.** Session management, token design, password and secret handling, TOTP, and ideally WebAuthn/passkeys. - **Strong SQL and relational data modeling.** You reach for a database constraint before you reach for an application-layer check. - **Production TypeScript** and comfort in a modern Next.js codebase. Deep Next.js *specialization* isn't required — a strong backend engineer picks up the App Router quickly. Security judgment is the part we can't teach. - **You write.** Design documents, threat models, honest post-incident write-ups. Much of this role is producing artifacts a non-technical founder can act on. - **You write your disagreements down and you argue them.** A specification you think is wrong is a document you respond to, not a constraint you quietly work around. **Strongly preferred** - Applied cryptography: envelope encryption, key management and rotation, secure storage of third-party credentials. This maps directly to our gated workstream. - Experience with regulated or audited data — GLBA, SOC 2, HIPAA-adjacent, PCI. Not because we need a compliance officer, but because it shapes how you think about audit trails and data minimization. - Threat modeling as a practice you've actually run, not just read about. - Prior early-stage experience. You know what "good enough for now" means and, more importantly, where it must never apply. - Mentoring or code-review leadership with junior engineers or students. **Nice to have** - Drizzle specifically; Neon or another serverless Postgres - Chrome extension security (MV3 permissions, content-script isolation, message passing) - Prior work in eldercare, senior living, accessibility, or financial services for older adults **Explicitly not required** - A CISSP, OSCP, or any certification. We'll read your work, not your acronyms. - Frontend or design skills. - Willingness to manage people. - Full-time availability. This role is part-time by design and we mean it. ## Who this is right for You've spent years being the person in the room who asks "wait, who's authorized to do that?" — and you've been tired of being outvoted. Here, that question *is* the roadmap. Our hardest work is already gated behind a design document that doesn't exist yet, deliberately, because nobody has been able to write it well enough. You want scope disproportionate to your hours. You'd rather own a small, genuinely important surface completely than be one of nine engineers on a platform team. You care that the people this protects are, in many cases, not the people who chose to install it. That asymmetry should sit uncomfortably with you. It does with us — it's why the authorization model is written the way it is. ## Who this is wrong for - You want full-time work and are treating this as a bridge. Say so and we'll talk in a few months instead. - You need a large team, a mature platform, or someone else on call. - You'd rather ship fast than be right about permissions. Genuinely valuable instinct. Wrong product. - You want to build the AI assistant. That's a different role, later, deliberately. ## The honest part about money and stage We're pre-close on a **$750K seed round**. Cash is tight and we're not going to pretend otherwise. - **Rate:** `{{$XXX}}–{{$XXX}}/hr`, commensurate with experience. - **Hours:** starting at **10–12 hrs/week**, expanding to 16–20 on close if it's working for both of us. - **Equity:** meaningful, and negotiated openly — this is a founding-team-shaped role at a founding-team-shaped stage. - **Structure:** independent contractor engagement, papered before the first invoice, with a clear path to a larger role on close. - **Location:** fully remote, US. `{{Overlap expectation}}`. If the round closes on plan, this role expands. If you want the security co-founder conversation, we should have it — but we'd both rather have it after working together than before. ## How the process works Deliberately short. We know you have a job. 1. **Apply** — details below. No cover letter. 2. **45-minute conversation** with the founder. Product, stage, what you'd want to own, what you think is naive about our approach. 3. **Spec review (paid, ~2 hours, `{{$XXX}}` flat).** We send you a real excerpt of our backend specification under NDA. You tell us in writing what's wrong with it. This is the core of our process and we pay for it, because asking for free work is a bad way to start. 4. **90-minute technical conversation** walking through your critique and one design problem we're actually facing. 5. **Reference conversations**, then offer. Target: **under four weeks** from first conversation to offer. ## To apply Email **`{{email}}`** with the subject line **"Security & Backend — [your name]"** and include: 1. Your GitHub, LinkedIn, or a paragraph on what you've built — whichever tells the truth best. 2. **One paragraph** on a system you secured where getting it wrong would have hurt someone. What was the hardest authorization decision, and what did you decide? 3. Your hourly rate and realistic weekly availability. 4. Optional, and we'll read it first: something you've written about security — a post, a threat model, an incident retro, a strongly worded code review. No cover letter. Please don't send one. --- *CLIQ is an equal opportunity employer. We're building for people who are routinely underestimated, and we're aware of the irony if we ran hiring the same way. If you're excited about this and unsure whether you're qualified, tell us what you'd need to learn and apply anyway.*

Skills

Fuente original: freelancer

Análisis JobHunter