Backend Engineer (TypeScript/Python) - Patent Intelligence Platform
United StatesJob Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
About the Role
Patent Intelligence is an active Labrynth engagement delivering an AI-assisted patent intelligence platform. The current product ingests and analyzes public patent data, identifies white-space opportunities, generates and evaluates ideas, and supports patent drafting workflows. The next product is an invite-only B2C platform for personal and team accounts, built as a greenfield product alongside the current application, with a modular TypeScript BFF as the sole customer authorization and domain-mutation boundary and private Python workers handling patent retrieval, embedding, and model workloads.
This engagement owns the application backend for the first secure B2C foundation: the greenfield B2C API and authorization boundary, private data model, durable asynchronous operations, and Python worker integration. It is an agency / Statement-of-Work contract with a fixed 60-90 day initial term and option to extend, reporting to the Patent Project engineering lead and coordinating closely with Frontend, DevOps / Platform, and Security. The role does not own the entire B2C roadmap within one term, the AWS/Terraform enforcement substrate (DevOps / Platform), or security review (Security); application authorization policy remains Backend-owned. Meaningful overlap with US and Australian project hours is required for weekly planning, architecture reviews, and scheduled failure drills.
Stack: Node.js 22, TypeScript, Fastify, JSON Schema/OpenAPI 3.1, PostgreSQL 18 with forced RLS and pgvector, Amazon Cognito, SQS, S3, Python 3.14 with uv and pydantic-ai, OpenTelemetry.
What You'll Do
- Build the versioned REST/OpenAPI contract and modular TypeScript BFF, with stable success/error envelopes, generated TypeScript clients, and contract-drift CI gates.
- Integrate Cognito identity with opaque application sessions, and implement admission, invitations, personal/team accounts, memberships, capabilities, explicit account switching, and guarded account conversions that preserve asset identity and history.
- Implement the minimal separate operator admission service and audited break-glass workflows, keeping customer and operator identities, sessions, routes, roles, and audit paths independent.
- Design PostgreSQL domain models, migrations, forced-RLS authorization, transaction-bound authorization contexts, and immutable account_id constraints, proving cross-account denial through BFF tests and direct runtime-role SQL tests.
- Deliver the durable asynchronous operation path: idempotent acceptance, typed payment-disabled beta entitlements, transactional outbox, account-fair SQS dispatch, worker lease/heartbeat/fencing, result commit, retry, cancellation, and DLQ/redrive.
- Implement durable progress delivery: append-only operation events, resumable SSE, and cursor polling with no lost or duplicated logical events.
- Maintain usage, provider, and observability foundations: exactly-once logical usage ledgers, safe (customer-content-free) logs, metrics, and traces, and the worker and operation signals Platform dashboards need.
- Support current-and-prior compatibility semantics across database, OpenAPI, events, queues, and worker callbacks, including expand/deploy/backfill/verify/contract changes and rollback.
- Build private Python worker workflows and typed pydantic-ai agent boundaries, and hand over API documentation, ADRs, threat models, tests, fixtures, runbooks, and a dependency-aware plan for the next B2C vertical.
What We're Looking For
- TypeScript backend engineering: strong Node.js and TypeScript experience building modular production APIs; Fastify, JSON Schema, generated OpenAPI, and schema-first tooling such as TypeBox strongly preferred.
- PostgreSQL security and data modeling: advanced schema design, migrations, transactions, row-level security, database roles, composite foreign keys, append-only ledgers, and concurrency control.
- Identity and authorization: integrating Cognito or another OIDC provider while keeping product admission, account membership, and capabilities in authoritative application state.
- Distributed work execution: transactional outbox, SQS or comparable queues, idempotency, at-least-once delivery, leases, heartbeats, fencing tokens, cancellation, retries, and DLQ recovery.
- Revisioned domain design: immutable revisions, compare-and-swap updates, ETags, lineage, state machines, and evidence-preserving lifecycle transitions.
- Python worker integration: modern typed Python, uv, Pydantic, pydantic-ai, and clear service contracts between TypeScript application code and private Python workers.
- AI trust boundaries: typed model tools and outputs, server-resolved authority, bounded retrieval context, citation validation, and fail-closed persistence of model proposals.
- Testing and operability: TDD, contract and integration tests, adversarial tenant-isolation tests, failure drills, OpenTelemetry instrumentation, and end-to-end execution against realistic services.
Nice to Have
- Patent, legal-tech, document-workflow, or other evidence-heavy domain experience.
- Pgvector retrieval, embedding pipelines, and public/private retrieval separation.
- Neo4j or graph-query experience for a read-only public reference plane.
- Stripe webhook, entitlement projection, and usage-reconciliation experience.
- Secure source-document ingestion, malware-scanning, and provenance pipelines.
- Experience building operator and audited break-glass application workflows.
What We Offer
- High-impact work at the intersection of AI and critical infrastructure regulation
- Direct customer exposure and a seat at the table when we decide what to build
- Small team with outsized influence; your field learning shapes the product roadmap
- Modern AI-native development environment (Claude Code, Cursor, multi-model orchestration)
- Remote-first
- Competitive compensation
How would you rate this job post?
See what other professionals think about this role.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.