CAREERS

Two roles are open at a company whose product is proving what happened.

Exedra Gate builds evidence infrastructure for regulated private capital: one governed place where identity checks, contracts, signatures, data rooms and reports become a record as they happen, hash-chained, signed and independently timestamped. Both roles below are the first of their kind here, and both exist because that record now has to hold up inside somebody else's building.

Both are remote and open to candidates anywhere in the world. Each advert carries its fixed pay range and states its variable component separately, because an advert that names a position and hides the money, or folds a contingent bonus into the headline figure, is doing something this company would not accept from anyone else. What the contract itself looks like depends on where the successful candidate lives, so each advert says that it is settled at offer stage rather than guessing at it here.

OPEN ROLES

Two, described in full, including what they are not.

The company is one person, pre-launch, with no outside investment to announce and no headcount to quote. Both roles report to the founder because there is nobody else to report to. For someone who wants to own a surface outright that is the offer; for someone who needs a team around them it is a warning, and it is meant as one.

2 roles open. Remote, worldwide. Full-time.

Discipline

No open role matches that combination. The application form is read whether or not an advert fits, and the work the company expects to need is named further down.

Senior DevSecOps / Full-stack Engineer

EUR 60,000 to 80,000 per year, gross, full-time

Place of work: Remote, worldwide.

Contracting arrangement. The form of engagement, the contracting entity and the governing law are settled at offer stage and are not stated here, because they depend on where the successful candidate is based and have not been decided in advance. The candidate is responsible for their own right to work where they live, and the specifics are discussed at the same point.

Variable component. An annual variable component contingent on company performance is paid in addition. It is stated separately rather than added into the range, because the range is what the company commits to and the variable component is not: in a year the company does not perform, it is not paid.

Discipline. Engineering

The mission

The platform runs today as managed hosting. Institutional and government buyers in the anchor markets increasingly cannot use it that way: they want it delivered onto their own infrastructure, under their own controls, with no dependency they did not agree to. An engineering blueprint for that delivery exists and is honest about what does not package. This role turns it into a deployment that runs, and keeps shipping product code while doing it.

What the first 90 days actually look like

  1. Vendor the remote module imports the edge functions resolve at boot into a checksummed build artefact, so a deployment inside a private network never reaches for a public registry to start.
  2. Stand up the reference stack in containers: Postgres with its extensions and its full migration history, the auth service, the REST layer, object storage, a gateway and the function runtime, on core Kubernetes primitives that behave the same on any managed cluster.
  3. Decide the canonical fresh-install path in writing, bootstrap schema first and then forward migrations, and prove it on an empty cluster rather than asserting it.
  4. Come back with the honest list of what does not package. The largest known item is that day-to-day operations currently assume a hosting dashboard that a client deployment will not have, and the runbooks that replace it do not exist yet.

What the role owns after that

  • Infrastructure as code and the deployment manifests, written against core primitives rather than one cloud vendor, so the same set runs on a client’s managed Kubernetes whoever operates it.
  • The release path: artefacts built outside the client perimeter, signed, published with their digests and a software bill of materials, and verified at the door. The client’s security team approves every update, which only means something if the mechanism makes it literally true.
  • Default-deny egress, and documenting the exact byte shape of every flow that is allowed through, so the client’s network team can inspect the channel instead of trusting a description of it.
  • The seams. Mail, identity, model endpoint and timestamping are each a switch the client sets, each with a stated consequence for what may then be claimed, and each fail-closed when it is switched on but unbound. Absence of a silent fallback is the security property.
  • Serving a small language model on the client’s own hardware inside the perimeter, for the AI surfaces that are switched on, so a prompt has no path outward at all.
  • Product engineering, continuously. Roughly half the work is the React application and the server-side functions behind it. This is not a platform-only post.

What it takes

  • Has containerised a stateful Postgres service, run it in production, and restored it from backup for real rather than in a runbook.
  • Works in Kubernetes with core primitives and can explain why a stateful set with a volume claim template is not the same thing as an operator-managed database.
  • Writes TypeScript across a front end and server-side functions, and is content to spend half a week in product code.
  • Has kept a fail-closed control closed under delivery pressure, and can describe the conversation that took.
  • Reads Postgres row-level security policies and can explain how a plausible-looking one leaks.
  • Works remotely and unsupervised on a surface nobody else owns. The role is open to candidates anywhere in the world, and the first 90 days above are the honest description of what the first quarter costs.

What this role is not

  • Not a Kubernetes-only platform post. About half of it is application code, and someone who wants to stay out of the product will be unhappy.
  • Not greenfield. The platform exists, carries a long migration history, and every packaging decision is constrained by it and by what the company is allowed to claim.
  • Not an audit or assurance function. The guards here are code that runs, not findings written up about somebody else’s code.
  • Not a lead role with people under it. There is nobody to lead yet, and the advert will not pretend otherwise.

Technical Product Manager / Solutions Engineer

EUR 55,000 to 70,000 per year, gross, full-time

Place of work: Remote, worldwide.

Contracting arrangement. The form of engagement, the contracting entity and the governing law are settled at offer stage and are not stated here, because they depend on where the successful candidate is based and have not been decided in advance. The candidate is responsible for their own right to work where they live, and the specifics are discussed at the same point.

Variable component. An annual variable component contingent on company performance is paid in addition. It is stated separately rather than added into the range, because the range is what the company commits to and the variable component is not: in a year the company does not perform, it is not paid.

Discipline. Product

The mission

Selling evidence infrastructure to a regulated institution is a long technical conversation, not a demo. It runs through security questionnaires, due-diligence packs, architecture review under NDA, and a security architect whose job is to find the sentence that overclaims. This role is the person on the other side of that conversation: it owns the cycle end to end, writes the documents it runs on, and comes back with a queue of engineering work that is costed rather than wished for.

What the first 90 days actually look like

  1. Build the answer library. Assemble the enterprise security questionnaire and due-diligence corpus from what the platform actually does, with every answer pointing at the artefact that shows it rather than at a sentence that asserts it.
  2. Take one architecture blueprint from an internal engineering document to something a client’s architect can read, with every claim consequence still attached rather than smoothed away.
  3. Sit in the first technical alignment sessions and explain hash chaining, signing and independent timestamping to people who will push back, including on what those mechanisms do not establish.
  4. Return a prioritised list of what procurement asked for that the platform cannot yet answer, each item written as engineering work with an estimate against it.

What the role owns after that

  • Enterprise security questionnaires and due-diligence questionnaires, from first request to signature, including the ones the client’s own auditor will read afterwards.
  • Readiness work towards SOC 2 Type 2 and ISO 27001 as it is scoped. The company holds neither today, and this role is part of the reason that sentence might change.
  • Documentation as a deliverable: architecture blueprints, deployment references, and the disclosure wording that has to travel with each configuration switch a client sets.
  • Translating a client’s own obligation into a requirement an engineer can build, and translating an engineering constraint back into something a compliance officer can act on.
  • Holding the claim ladder in the room. Saying tamper-evident, signed and independently timestamped when the room wants something rounder and stronger, and being able to explain why the narrower claim is the one that survives an adversarial reading.
  • Specifying the identity routing work. Routing verification through national and European electronic identity schemes is on the roadmap and is NOT BUILT: the platform verifies identity through a commercial provider today. This role helps decide and specify what replaces or joins it, and must never describe it as shipped.

What it takes

  • Has personally written the answers to enterprise security questionnaires, and been on the call where those answers were challenged line by line.
  • Can read an architecture document and find the sentence that overclaims, then rewrite it without losing the argument.
  • Has run a SOC 2 or ISO 27001 readiness programme, or been the technical owner inside one.
  • Writes well enough that a document goes to a client without being rewritten first.
  • Understands hash chaining, digital signatures and RFC 3161 timestamping well enough to say plainly what each one establishes and what it does not.
  • German or French alongside English is useful rather than decorative: the anchor markets are Germany and Switzerland.
  • Works remotely, and is willing to travel to client sites in the anchor markets when a review has to happen in a room. The role is open to candidates anywhere in the world; that travel is the part of it which is not remote.

What this role is not

  • Not a sales role. No quota, no commission, no pipeline to own. Commercial terms sit with the founder.
  • Not a certification role. The company holds no certification today, and nobody in this post gets to imply that one exists, that a supervisory authority is involved, or that any authority has approved anything here. Frameworks are named on this site; authorities are not.
  • Not roadmap authorship in the usual product sense. The roadmap is constrained by phase gates and by counsel, and those constraints are not negotiable from inside the role.
  • Not a management post. There are no engineering reports attached to it.
HOW THIS TEAM WORKS

Three properties of the system, which are also how the work runs.

Zero trust is an architecture here, not a slogan.

Row-level security in Postgres is the only boundary between one client's data and another's, so a weak or missing policy is treated as an incident rather than a ticket, and every policy change carries a tenant-isolation matrix including the case where no relationship exists at all. Timestamping fails closed: where an independent timestamp is required and cannot be obtained, no evidence pack is produced, because the system declines to issue a record it cannot stand behind. Credentials are referenced by name and never by value, and nothing holds a privilege it does not need to do its job.

Cloud-agnostic, and deliverable onto the client's own infrastructure.

The platform is being packaged so it can be delivered onto a client's infrastructure as a scoped engagement rather than consumed as hosting, using core Kubernetes primitives that behave the same whoever operates the cluster, with dependencies vendored so nothing reaches a public registry to start. Every external module is a switch the client sets, and every position of every switch has a stated consequence for what may then be claimed. Some dependencies stay external on purpose: an independent timestamp means an authority that is neither the client nor Exedra Gate, and internalising it would buy privacy by giving up the strongest claim the product makes.

Evidence discipline applies to us before it applies to the product.

Every claim carries its source. Every guard runs. Nothing ships that cannot be shown, which in practice means a figure without a citation does not go on a page, a capability that is roadmap is written as roadmap, and a defect is not reported without the command that demonstrates it. Autonomy follows from that rather than being offered as a perk: one person owns a surface end to end here, and that is only workable because the guards are not optional and the record of what happened is not anyone's to edit afterwards.

One form, for either role

Five fields and a place for documents. The message matters more than the rest of it: what the work would be in the first months, and why here rather than somewhere with a bigger name on the door.

Documents

PDF, DOC or DOCX. Up to four files, 3 MB in total. Documents are sent straight to the office as email attachments and are not stored on this site or anywhere else: the mailbox is the only copy. They are read to assess the application and for nothing else, kept for six months, then deleted. Deletion can be asked for sooner through the route in the privacy policy, which also sets out the basis for the processing. Please leave out anything that was not asked for, such as health, religious or political details, or a photograph.

WHERE A PERSON MIGHT FIT

The work the company expects to need, named precisely.

The list below is not a set of vacancies. Apart from the two adverts above, no position is open, no terms are advertised, and none of these is a job posting. It exists so that a reader can recognise their own work in it, name it in an application, and be found later when the role does open.

Building the platform

  • Backend Engineer The Postgres data model and the services behind identity checks, contracts, signatures and the chain that ties them together.
  • Frontend Engineer The rooms clients actually work in, on the desktop and on the phone in a counterparty’s pocket.
  • Site Reliability Engineer Deployment, availability and recovery across managed hosting, white-label installations and a client’s own data centre.
  • QA Automation Engineer The automated suite around signing, timestamping and verification, where a silent regression is the most expensive kind.
  • Integrations Engineer The API surface and the connections institutions ask for, including the ones their own auditors will read.

Security, compliance and law

  • Security Engineer Application and infrastructure security for a system whose whole claim is that its records cannot be altered unnoticed.
  • Information Security Officer The internal security management system, and the security questionnaires institutional clients send before they sign anything.
  • Regulatory Compliance Manager Reading what supervisors publish across the target markets and turning it into product requirements and the queue behind the news page.
  • Data Protection Officer Data-protection obligations under the GDPR and the revised Swiss FADP, including the records clients inherit by using the platform. Also posted as Data Protection Manager where no formal appointment is in place.

Working with clients

  • Solutions Engineer Answering, in front of a prospective institution, how the platform meets the obligations that institution actually carries.
  • Implementation Consultant Taking a client from signature to a running deployment, including the custom work institutions ask for.
  • Technical Writer The documentation a reviewer reads: how verification works, what a record proves, and what it does not.
  • Enterprise Account Executive Enterprise sales into regulated industries, where the buying committee includes people whose job is to say no.
  • Customer Success Manager The relationship after go-live, which on this platform is where most of the work begins rather than ends.

Work that is not on this list is still worth writing about. The list describes what the company can already see coming, which is not the same as everything it will need. The form is above.

WHAT THE WORK IS

Compliance infrastructure, built to be checked by strangers.

Exedra Gate is one governed place where private-capital work runs and becomes proof as it happens: identity, contracts, signatures, data rooms and reports, signed and independently timestamped. The claim the company makes is narrow and checkable, which sets the standard for everything built here. A feature that cannot be verified by someone with no reason to trust the company does not ship.