Skip to content

Open nowPosted 26 days ago

Staff Engineer

Workable (global search)108,016 open roles

Where
Denver, CO, United States
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowStaff EngineerWorkable (global search) · Denver, CO, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 26 days ago

Workable (global search) median: 7 days open

The posting

We operate a multi-tenant automotive SaaS platform serving thousands of dealer groups across the United States. Our backend — event-driven serverless on AWS — orchestrates everything from dealer onboarding to inventory management to real-time transaction processing. That platform works. Now we need to make it think — and keep it modern, secure, and safe to ship. We also run a monolith that needs upkeep while we build the next-gen platform and redesign its components, a few at a time, into microfrontends.

This is a hands-on engineering role at its core. Day to day you build, ship, and operate agentic AI systems — autonomous, tool-using agents (AgentCore, MCP servers) that observe platform state, reason over dealer context, and take action through production APIs. But you are also the engineer who keeps the whole platform current and trustworthy: you continuously hunt and fix security vulnerabilities, upgrade the frameworks and runtimes underneath us, drive adoption of an agentic development harness to speed up delivery, and lead modernization of our existing systems.

You work across the org, not inside one team's walls. You own production monitoring and the SRE practices that keep us reliable, and you are the champion for safe releases — defining the checks and balances that gate production, setting the engineering standards, and making sure they are actually enforced. When something misbehaves in production, your instrumentation, your guardrails, and your release discipline are what make it fail safe instead of fail loud.

Reports to: SVP, Engineering.

What You'll Own

- Hands-on agentic development — designing, building, and operating agentic AI systems (AWS Bedrock AgentCore, MCP servers) every day: agent code, tool interfaces, evaluation harnesses, and production AI workflows.

- Driving adoption of the agentic development harness — making agent-assisted development a first-class way the org ships, and measurably improving speed of delivery across teams.

- Security vulnerability management — continuously monitoring for vulnerabilities (dependencies, CVEs, container images, IAM/config drift), remediating quickly, and keeping frameworks, libraries, and runtimes patched and upgraded.

- Platform modernization — creating and driving initiatives to modernize existing platforms: retiring legacy patterns, adopting current frameworks, and staying close to the leading edge.

- Production monitoring & SRE — owning observability (OpenTelemetry, CloudWatch), SLOs and error budgets, on-call and incident response.

- Third-party integration observability — a standardized way to organize all third-party integration calls, report on them with precision, and run anomaly detection on call volumes with continuous monitoring, so a spike, drop, or failure surfaces before it becomes an outage or a cost problem.

- On-call cookbook — keeping applications well documented so an on-call engineer can quickly query a cookbook, understand the likely problem areas, and know where to look.

- Release governance — champion across releases: defining and enforcing the checks and balances (CI/CD quality gates, security and test gates, rollback criteria, progressive delivery) required to move change into production.

- Setting and enforcing engineering standards — establishing the patterns, guardrails, and review bar the org follows, and holding the line so they are consistently applied.

- Working across the org — partnering with every engineering team to raise the technical, security, and reliability bar broadly.

Tech & Tools

- Cloud: Lambda, EventBridge, DynamoDB, S3, ECS Fargate, Aurora, API Gateway, CloudWatch, Secrets Manager.

- AI & Agentic: AWS Bedrock AgentCore, MCP servers, LangChain/LangGraph.

- Languages: Python and Java (Spring Boot), TypeScript/React (Next.js), legacy PHP/Laravel.

- Security: Dependabot/Snyk, SAST/DAST, container image scanning, secrets management, IAM hardening.

- Reliability & Observability: OpenTelemetry, CloudWatch, SLO/error-budget tooling, PagerDuty, Datadog.

- CI/CD & Release: CircleCI, CloudFormation, progressive delivery, quality/security gates, rollback automation.

- Integration Surfaces: REST, SOAP/XML, EventBridge, SES, Playwright.

How You'll Use AI

This is not a "we are AI-curious" company. This is the role that makes agent-assisted development the norm for everyone else — building and operating production agents, triaging CVEs and generating patch/upgrade PRs, driving framework upgrades, reviewing PRs across the stack, standing up observability, and drafting ADRs and runbooks.

Hands-On Expectations

Roughly 60–70% building and operating, 20–30% on design and standards, and ~10% on cross-team enablement.

First 12 Months

- Months 1–3: Immerse in the codebase, ship your first meaningful changes, audit our security posture, dependency/framework currency, and release pipeline, and publish a baseline of engineering standards and release checks.

- Months 4–6: Ship agentic automation into at least one production workflow, roll out the agentic development harness, stand up the SRE baseline (SLOs, on-call, dashboards), and automate vulnerability scanning and patching.

- Months 7–9: Drive a modernization initiative end to end; harden the release gates and enforce them across teams.

- Months 10–12: Measurable delivery-speed gains from agentic adoption, production reliability against SLOs, and engineering standards adopted org-wide.

Requirements

Must Have

- 6+ years of software engineering experience, including 2+ years at a Senior or Staff level building and operating production systems.

- Hands-on agentic / LLM development (AWS Bedrock, MCP, LangChain/LangGraph) — or a strong, demonstrated track record of getting up to speed fast on modern frameworks.

- Strong hands-on experience with AWS serverless (Lambda, EventBridge, DynamoDB, Step Functions) and traditional service architectures (ECS, RDS, API Gateway).

- Security-minded engineering — dependency and vulnerability management, timely patching/upgrades, and secure-by-default practices.

- SRE practices — observability, SLOs/error budgets, on-call, and incident response.

- CI/CD and release management — quality/security gates, rollback, and progressive delivery.

- Comfortable in at least two of Python, Java (Spring Boot), and TypeScript/React — and able to read and safely modify PHP.

- A track record of setting standards and getting them enforced, plus the writing to make a design or standard clear enough for a peer to implement.

Strongly Preferred

- Experience running security tooling (Snyk/Dependabot, SAST/DAST) and observability/on-call tooling (Datadog, PagerDuty) in production.

- Automotive, fintech, or multi-tenant marketplace platform experience.

- Experience with data pipelines (Glue/Athena) or ETL/data-lake tooling.

- Familiarity with Auth0, or with browser automation (Playwright) in production integration flows.

Role Specifics

- Location: Denver, CO (hybrid, 2 days/week in office) or Remote (US, outside the Denver market).

- Employment type: Full-time.

- Reports to: SVP, Engineering.

Scope & Scale

- 5,000+ destination dealer tenants, each with isolated databases and per-tenant configuration.

- Billions in annual GMV flowing through platform transactions.

- Tens of thousands of API requests per minute across REST, SOAP, and event-driven integration surfaces.

- Data pipelines spanning 6 integration domains with multi-protocol vendor connectivity.

Benefits

At A2Z Sync, we replace the friction of disconnected systems with the velocity of a single platform. We pride ourselves on a fun, casual, and collaborative culture, and we're committed to our employees' well-being.

- Employer-Paid Health, Dental, and Vision Insurance, starting on day one.

- Flexible work: Denver hybrid (2 days/week in office) or fully remote anywhere in the US.

- 401(k) Retirement Plan with Company Match.

- Generous Paid Time Off: Unlimited PTO and 10 paid holidays.

- Short-Term and Long-Term Disability Coverage, fully employer-paid.

- Life and AD&D Insurance, employer-paid.

- Free Mental Health Support via BetterHelp.

- Pet Insurance options.

- Identity Theft Protection.

- On-site gym in Denver, great co-workers, and a stocked kitchen with snacks and beverages.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.