Sustain GRC is a governance intelligence infrastructure platform for non-financial data. Founded in London in 2022 and endorsed by the UK government as an innovator, we hold risk, internal audit, compliance, resilience, board governance, AI governance and sustainability on a single data model — built as one system rather than assembled through acquisition.
Our customers are mid-to-large enterprises and sovereign entities across EMEA and the GCC, operating under DORA, NIS2, the EU AI Act and equivalent regional supervision. When a regulator or auditor asks them to defend a number, our platform is what makes that number defensible.
The engineering standard follows from that: assurance-grade data, traceable to source, attributable to a person, and able to survive scrutiny years after the fact.
The role You own the engineering function. The services, the architecture, the security model, the production behaviour, and the engineers who build it.
This is hands-on. You write code, you review it, and you raise the standard of a team that is capable but early in its career. Roughly two-thirds engineering, one-third leadership, shifting as the function scales.
It suits someone entrepreneurial — comfortable making decisions without complete information, moving at the pace a platform company at this stage demands, and taking ownership of outcomes rather than tickets. If you need a defined remit handed to you, this will frustrate you.
What you will own Engineering leadership Delivery for the full platform: scope, sequencing, quality, production outcomes A distributed engineering team — hiring, technical direction, code review standards, performance Architectural authority, and the defence of those trade-offs to product, security and the executive team Translating regulatory and customer commitments into engineering constraints before they become rework The practices this stage requires: design review, incident response, on-call, release discipline Backend and platform Scalable backend services in Node.js (Type Script); REST APIs and microservices across the platform End-to-end ownership: design → implementation → deployment → monitoring Architectural risk, edge cases and scalability constraints identified early Clean architecture, SOLID principles, long-term maintainability Security, access control and auditability Authentication and authorisation architecture (JWT, OAuth2, RBAC) Permission models and data access controls for multi-tenant enterprise and sovereign deployments Immutable audit logging and evidence lineage — every action logged, attributable, tamper-evident Data residency and segregation across UK, EU and GCC jurisdictions Control evidence for ISO 27001 and Cyber Essentials Plus surveillance
Data, integrations and performance Postgre SQL schema, query and index design at scale Redis for caching, queues and performance External service integration with reliability and traceability Real-time features where applicable (Socket.io) and S3-compatible object storage
Reliability and platform operations Docker-based containerisation and environment parity CI/CD pipeline ownership (Git Hub Actions or similar) Cloud deployment, GCP-first (GKE, Cloud Run, Cloud SQL, IAM, Cloud Storage); on-premises and VPC patterns for sovereign customers Monitoring, logging, alerting, error tracking Safe deployments, high availability, predictable releases
Required10+ years professional backend engineering, including at least 3 years leading engineers Strong Node.js and Type Script; production experience with Express, Fastify or Nest JSDeep Postgre SQL; hands-on Redis Microservices and distributed systems in production Docker and CI/CD ownership Strong grasp of API security, authentication and RBACDemonstrable ownership of production systems and of the people building them Comfortable making architectural decisions and defending the trade-offs to non-engineers Fluent professional English — you will present to enterprise customers, auditors and partners directly
This role is not suitable for engineers without prior team leadership, or for managers who no longer write code.
Nice to have Enterprise Saa S, compliance, or regulated-industry platforms Exposure to audit, GRC or financial services systems Arabic, in addition to English
What we offer Ownership of infrastructure that enterprises and sovereign entities depend on to satisfy regulators Compensation weighted towards equity — a significant allocation for the right candidate, alongside cash. We are building owners, not staffing a function Fully remote High ownership, low bureaucracy — architectural decisions are made by the people building the system
Sustain GRC هي منصة بنية تحتية لذكاء الحوكمة للبيانات غير المالية. تأسست في لندن عام 2022 وحصلت على اعتماد حكومة المملكة المتحدة كجهة مبتكرة، ونحن نجمع المخاطر، والتدقيق الداخلي، والامتثال، والمرونة، وحوكمة مجالس الإدارة، وحوكمة الذكاء الاصطناعي، والاستدامة في نموذج بيانات واحد — تم بناؤه كنظام متكامل بدلاً من تجميعه من خلال الاستحواذ.
عملاؤنا هم من الشركات المتوسطة إلى الكبيرة والكيانات السيادية في منطقة أوروبا والشرق الأوسط وأفريقيا (EMEA) ودول مجلس التعاون الخليجي، الذين يعملون تحت مظلة قوانين DORA وNIS2 وقانون الذكاء الاصطناعي للاتحاد الأوروبي والرقابة الإقليمية المماثلة. عندما يطلب منهم جهة تنظيمية أو مدقق حسابات تبرير رقم ما، فإن منصتنا هي ما يجعل ذلك الرقم قابلاً للدفاع عنه.
المعيار الهندسي يتبع ذلك: بيانات ذات مستوى ضمان، يمكن تتبعها إلى مصدرها، ويمكن نسبتها إلى شخص، وقادرة على الصمود أمام التدقيق بعد سنوات من وقوع الحدث.
الدور: أنت المسؤول عن الوظيفة الهندسية. الخدمات، والهيكلية، ونموذج الأمان، وأداء الإنتاج، والمهندسون الذين يبنون ذلك.
هذا دور عملي. أنت تكتب الكود، وتراجعه، وترفع مستوى فريق يتمتع بالكفاءة ولكنه في بداية مسيرته المهنية. حوالي ثلثي العمل هندسي، وثلث قيادي، مع تغير النسبة مع توسع الوظيفة.
يناسب هذا الدور شخصاً يتمتع بروح ريادية — يشعر بالراحة في اتخاذ القرارات دون معلومات كاملة، ويتحرك بالسرعة التي تتطلبها شركة منصة في هذه المرحلة، ويتولى مسؤولية النتائج بدلاً من الاكتفاء بإنهاء المهام. إذا كنت بحاجة إلى نطاق عمل محدد يُسلم لك، فقد تشعر بالإحباط هنا.
ما ستتولى مسؤوليته: القيادة الهندسية، والتسليم للمنصة الكاملة: النطاق، والتسلسل، والجودة، ونتائج الإنتاج، وفريق هندسي موزع — التوظيف، والتوجيه الفني، ومعايير مراجعة الكود، والأداء. السلطة المعمارية، والدفاع عن تلك المقايضات أمام فريق المنتج والأمن وفريق الإدارة. ترجمة الالتزامات التنظيمية وعملاء الشركة إلى قيود هندسية قبل أن تصبح عملاً إضافياً. الممارسات التي تتطلبها هذه المرحلة: مراجعة التصميم، الاستجابة للحوادث، الاستعداد للعمل، وانضباط الإصدار. الخلفية والمنصة: خدمات خلفية قابلة للتوسع في Node.js (TypeScript)؛ واجهات برمجة تطبيقات REST وخدمات مصغرة عبر المنصة. مسؤولية شاملة: من التصميم ← التنفيذ ← النشر ← المراقبة. تحديد المخاطر المعمارية والحالات الاستثنائية وقيود القابلية للتوسع في مرحلة مبكرة. بنية نظيفة، مبادئ SOLID، وقابلية صيانة طويلة الأمد. الأمان والتحكم في الوصول والتدقيق: هيكلية المصادقة والتفويض (JWT, OAuth2, RBAC). نماذج الأذونات وضوابط الوصول إلى البيانات للمؤسسات متعددة المستأجرين والكيانات السيادية. سجلات تدقيق غير قابلة للتغيير وتسلسل أدلة - كل إجراء مسجل، قابل للنسبة، ومضاد للتلاعب. إقامة البيانات وتجزئتها عبر ولايات المملكة المتحدة والاتحاد الأوروبي ومجلس التعاون الخليجي. أدلة التحكم للامتثال لمعايير ISO 27001 وCyber Essentials Plus.
البيانات والتكامل والأداء: تصميم مخطط Postgre SQL، والاستعلام والفهرسة على نطاق واسع. Redis للتخزين المؤقت، وقوائم الانتظار والأداء. تكامل الخدمات الخارجية مع الموثوقية والتتبع. ميزات الوقت الفعلي حيثما أمكن (Socket.io) وتخزين الكائنات المتوافق مع S3.
الموثوقية وعمليات المنصة: الحاويات القائمة على Docker وتكافؤ البيئات. مسؤولية خط أنابيب CI/CD (GitHub Actions أو ما شابه). النشر السحابي، اعتماد GCP أولاً (GKE, Cloud Run, Cloud SQL, IAM, Cloud Storage)؛ أنماط محلية (on-premises) وVPC للعملاء السياديين. المراقبة، التسجيل، التنبيه، تتبع الأخطاء. عمليات نشر آمنة، توفر عالي، وإصدارات يمكن التنبؤ بها.
المتطلبات: خبرة 10 سنوات فما فوق في هندسة الخلفية، بما في ذلك 3 سنوات على الأقل في قيادة المهندسين. خبرة قوية في Node.js وTypeScript؛ خبرة إنتاجية مع Express أو Fastify أو NestJS. خبرة عميقة في Postgre SQL؛ خبرة عملية في Redis. خدمات مصغرة وأنظمة موزعة في مرحلة الإنتاج. ملكية Docker وCI/CD. فهم قوي لأمن واجهة برمجة التطبيقات، والمصادقة، وRBAC. مسؤولية مثبتة عن أنظمة الإنتاج وعن الأشخاص الذين يبنونها. مريح في اتخاذ القرارات المعمارية والدفاع عن المقايضات أمام غير المهندسين. إنجليزية مهنية بطلاقة — ستقدم عروضاً مباشرة لعملاء المؤسسات والمدققين والشركاء.
هذا الدور غير مناسب للمهندسين الذين ليس لديهم قيادة سابقة للفريق، أو للمديرين الذين لم يعودوا يكتبون الكود.
يفضل: خبرة في البرمجيات كخدمة (SaaS) للمؤسسات، أو منصات الامتثال، أو الصناعات الخاضعة للتنظيم. تعرض لأنظمة التدقيق، أو GRC، أو الخدمات المالية. العربية، بالإضافة إلى الإنجليزية.
ما نقدمه: ملكية البنية التحتية التي تعتمد عليها الشركات والكيانات السيادية لإرضاء المنظمين. تعويضات مرجحة نحو الأسهم — مخصص كبير للمرشح المناسب، إلى جانب النقد. نحن مالكون مؤسسون، لا نوظف لمجرد ملء وظيفة. العمل عن بعد بالكامل. مسؤولية عالية، بيروقراطية منخفضة — يتم اتخاذ القرارات المعمارية من قبل الأشخاص الذين يبنون النظام.