This role is to be an integral part of the engineering effort and ongoing maintenance. Today the platform is architected and largely built by one person — the Chief Systems Architect. You would be the second.
That means two things, and we want to be direct about both.
First, you will write the platform, not just keep it running. This is not an infrastructure-management seat with application work bolted on the side. The core of the job is designing and building production services in Python and React against a PostgreSQL data layer, and carrying the architectural judgment that keeps a federated platform coherent. The cloud, the pipelines, and the security posture are part of the job — but they are the ground the applications stand on, not the point of the role.
Second, this is a succession-track role. You'll start as deputy, pairing daily with the Chief Systems Architect, absorbing not just how the system is built but why it's built the way it is. Over the next few years you'll grow into full architectural ownership of the platform. If the idea of inheriting an opinionated, well-documented system and being trusted to evolve it is exciting rather than daunting, keep reading. If you're looking for a team to manage, this isn't that.
What you'll own (the core)
- Build production application services in Python. Backend services and APIs — currently FastAPI — that run the business. You'll design them, write them, own them.
- Build the front end in React. Real application UI that operators, office staff, and the field depend on every day.
- Model and evolve the data layer. Relational schema design, migrations, and the discipline that keeps a growing PostgreSQL platform clean. Migration work is first-class here, not an afterthought.
- Make architectural decisions and defend them. Designing domain boundaries, integration contracts, access-control models, and data shapes — and documenting the reasoning so the next person inherits the decision instead of rediscovering it.
- Design API integrations between our internal services and third-party systems (including our partners' systems), favoring portable interfaces over vendor lock-in.
- Set and uphold development standards — conventions, review gates, and the structural guardrails that let a very small team move fast without drifting.
What you'll also carry (the breadth)
This is where Azure and operations live. Depth here is welcome, but if you're a strong application engineer who's competent-but-not-expert in Azure, that's fine — it's the half of the job we can grow you into.
- Operate our Azure estate: Container Apps, Static Web Apps, Docker-based workloads, networking, Key Vault, and identity via Microsoft Entra ID.
- Own the delivery pipeline: CI/CD, automated deployments, environment management, infrastructure-as-code.
- Keep the platform secure and compliant by design: identity and access controls, secrets handling, monitoring, vulnerability remediation, and supporting our SOC 2 posture — enforced structurally, in the code and the data model, not by hope and convention.
- Participate in disaster recovery and business continuity planning for the platform.
AI & automation
We use AI heavily and deliberately. Claude Code is a primary development accelerator here, and AI is built into the platform itself — but inside guardrails. Our pattern is propose, not act: AI surfaces structured suggestions for humans to approve, and sensitive data is kept out of AI egress paths by construction. You'll extend that — finding high-value places to apply AI to development, reporting, and operations — while keeping the responsible, secure posture that makes it trustworthy.
Our architecture has opinions
We're telling you this up front because it's the best filter we have. If these make you lean in, you're our person. If they read as overhead, you'll be unhappy here.
- Structural over cultural. Access control, data protection, and policy are enforced in the data shape and the code path — not by discipline or documentation alone.
- Architecture Decision Records. Consequential decisions are written down, with context and trade-offs, so reasoning is inherited rather than reconstructed.
- Append-only activity streams, enforced at the database level.
- Claims-based access control, scoped consistently throughout.
- PII-free AI egress, by construction. Not "we remember to scrub it" — it's structurally impossible by design.
- Portability-first. External dependencies sit behind interfaces with portable fallbacks. Services speak to interfaces, not vendors.
- KISS and defer-with-a-named-trigger. When something is genuinely risky or complex, we defer it explicitly, with documented rationale and a named condition for when it ships.
You don't need to have built a platform exactly like this. You do need to be the kind of engineer who'd have made similar calls — or who can look at one of ours and tell us why we're wrong.
Who you are (required)
- 5+ years building and shipping production web applications you owned — not just supported. Demonstrable depth in Python (FastAPI or comparable) on the backend and React on the front end.
- Strong relational data modeling and migration experience (PostgreSQL preferred).
- Architectural judgment. You've designed systems, made consequential trade-offs, and can walk us through why — including the ones you'd make differently now.
- Working competence in Microsoft Azure and cloud-native operation: containers (Docker), CI/CD, networking and identity basics. Real depth is a plus; willingness and ability to grow into it is required.
- Security built into how you design, not added afterward.
- The temperament for a small, high-trust team: self-directed, low-ego, comfortable owning outcomes end to end, and genuinely interested in the operations the software serves.
Nice to have (and teachable)
- Deeper Azure specialization (architecture, security operations, IaC at scale).
- Experience with operational, field-service, logistics, or home-improvement organizations.
- Azure DevOps / GitHub Actions, reporting and BI, workflow automation.
- Experience applying AI to real engineering and operational work.
Not required: experience with our specific legacy system (FileMaker). We're retiring it. The successor never needs to learn it.
How we hire
Because the expensive, slow-growing part of this job is judgment, that's what we'll evaluate — more than resumé line items. Expect to talk through real architectural decisions from our platform with the conclusion removed, and to reason out loud about where you'd take them. We're not testing whether you've memorized a framework. We're testing whether you think the way this platform is built — and whether you'd make it better or quietly make it generic. Come ready to disagree with us well.
Why this role matters
The platform that powers CIS is a strategic asset, and right now it lives substantially in one person's head and one person's hands. This role is how that stops being true. You're not here to maintain the status quo, and you're not here to be a lieutenant. You're here to become a peer, and eventually a successor — to help shape the next generation of the system and to make sure CIS's technology foundation outlasts any single engineer.
If that's the seat you've been looking for, we'd like to meet you.
Pay: $77,322.59 - $93,119.67 per year
Benefits:
- 401(k) matching
- Dental insurance
- Flexible schedule
- Health insurance
- Health savings account
- Paid time off
- Parental leave
- Retirement plan
Work Location: Hybrid remote in Carrollton, TX 75006