This is a remote position.
The opportunityOur Client is looking for a Senior Backend Engineer to help the platform move from reporting risks to actively enforcing security policy. Your work will sit on the path between the client's verdicts and customer actions: warning or blocking unsafe installs, serving safer alternatives and, over time, coordinating revocation actions across a customer fleet.
Our client scans and inventories AI artifacts such as prompts, skills, MCP servers, hooks and IDE extensions. It gives security teams a verdict they can defend and helps prevent unsafe artifacts from causing harm. The platform is in production with early external users and runs primarily on TypeScript, Next.js, Node.js, Python and Google Cloud.
• Lead the initial four-week project to ship install interception for Claude Code through the client’s hook and MCP server, including warn and block modes driven by tenant policy.
• Build secure enforcement paths that can serve a sanitized alternative when an unsafe artifact is blocked and record intercepted installs as events.
• Design and implement robust integrations with third-party security, infrastructure or identity APIs.
• Build event-driven backend systems with sound handling of queues, webhooks, idempotency, retries and back-pressure.
• Make privileged actions safe and auditable through approval flows, dry runs, audit logs and rollback mechanisms.
• Potentially continue into fleet revocation through endpoint, repository and browser controls, plus integrations with security platforms and AI audit logs.
Requirements What you bring
• Three or more years of backend engineering experience, including at least two years building integrations against third-party security or infrastructure APIs such as EDR, SIEM, cloud security, identity or MDM.
• Strong server-side experience in TypeScript, Go or Python, with sound judgment about the right tool for the problem.
• Practical experience building event-driven systems and dependable integration workflows.
• Experience shipping a privileged action in a customer environment and explaining the safeguards you used to keep it safe.
• The ability to work through incomplete or inconsistent vendor documentation and validate how an API behaves in practice.
• Clear communication and comfort collaborating remotely with a small engineering team.
• Hands-on experience with CrowdStrike, Microsoft Defender, SentinelOne, Wiz, Lacework or Datadog APIs.
• OpenTelemetry or log-pipeline experience.
• A cybersecurity background or strong curiosity about AI agents and their security implications.
Benefits How the engagement works
The first engagement is a paid, full-time four-week project beginning in October 2026. It is real work from the client’s roadmap with a written deliverable and clear success test, not a take-home assessment.
At the end of the project, both sides will decide whether to continue through future projects or an ongoing full-time or part-time role.
You will contract directly with Apricot, which manages contracting, payments and administrative support. Day to day, you will work with the client and report to the CTO. You will need your own laptop, reliable connectivity, a secure work environment and two-factor authentication where required.
To help us align early, You’ll be asked to share your expected fee for the initial engagement and your preferred ongoing arrangement and compensation expectations (full-time or part-time).
Apricot is a nonprofit sourcing firm connecting displaced and underserved professionals from Palestine and the wider MENA region with global employment opportunities. We combine a clear social-impact mission with fast, high-quality recruitment delivery for international clients.
Similar Jobs
What you need to know about the Colorado Tech Scene
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

.png)