Senior Backend/AI Platform Engineer Needed

via Freelancer ·

Budget / SalaryA$5,000–10,000
TypeFreelance project
LocationRemote
Posted1 hour ago
Freelance Senior Backend / AI Platform Engineer

Engagement: Freelance / Contract
Work arrangement: Remote
Start: ASAP

About the Project

We are developing an AI-powered SaaS platform designed to automate complex business, document and administrative workflows.

The core platform is already built and under active development. We are looking for an experienced Senior Backend / AI Platform Engineer to work alongside our existing development team to restructure, secure and strengthen the platform architecture in preparation for enterprise deployment.

This is not a greenfield project. The successful freelancer will work with an existing codebase and technical team.

Scope of Work

1. Onboarding & Application Boundary

* Review the existing onboarding and application flow.
* Restructure the boundary between onboarding and the main application.
* Ensure authentication and authorisation are correctly enforced.
* Prevent unauthorised access to application resources.
* Establish appropriate user and organisation context.

2. Separate AI Agents from Main Application

* Review the existing AI/LLM architecture.
* Decouple AI agents from the main application.
* Move AI processing into clearly separated backend services.
* Establish a scalable structure for additional AI agents.
* Ensure sensitive AI operations cannot be accessed directly from the frontend.

3. Agent / Service API Communication

* Build secure APIs between the application backend and AI services.
* Implement service authentication and authorisation.
* Establish structured request/response formats.
* Implement validation, timeouts and error handling.
* Secure endpoints against unauthorised access.

4. Backend Architecture & Refactoring

* Review and refactor the existing backend architecture.
* Establish clear separation between frontend, business logic, AI services and data-access layers.
* Reduce unnecessary coupling.
* Improve maintainability, reliability and scalability.
* Prepare the architecture for future enterprise integrations.

5. User Authentication & Sessions

* Implement or strengthen user authentication.
* Secure session management.
* Login/logout functionality.
* Session expiration.
* Protected routes and APIs.
* Establish authentication architecture suitable for a multi-user SaaS platform.

The architecture should also support future enterprise SSO integration.

6. User Profiles, Roles & RBAC

Implement Role-Based Access Control (RBAC), including:

* Users and user profiles.
* Organisations.
* Roles and permissions.
* Application-level access.
* Document and data-access permissions.
* Multi-tenant data isolation.

Users from one organisation must not be able to access another organisation’s data.

7. Admin Controls

Implement appropriate administration functionality, including:

* User management.
* Role and permission management.
* Account activation/deactivation.
* Organisation management.
* Administrative access restrictions.

8. Database & Access Security

* Review the existing database architecture.
* Secure database connections.
* Implement appropriate access controls.
* Ensure tenant and user data isolation.
* Protect sensitive information.
* Review database queries and API access patterns.
* Prevent users from bypassing application-level permissions.

9. AWS / Vercel Deployment Architecture

Review and implement an appropriate cloud deployment architecture.

Expected architecture will broadly follow:

Frontend → Authenticated API → Backend Services → AI Agent Services → Database / Document Storage / External Integrations

The freelancer should be comfortable working across AWS and Vercel and recommending the appropriate environment for each component.

10. Security Hardening, Logging & Error Handling

* Application and API security review.
* Secrets and environment-variable management.
* Input validation.
* Rate limiting where appropriate.
* Application logging.
* Security and audit logging.
* Monitoring.
* Error handling.
* Protection of sensitive information within logs.
* Review and remediation of common web application vulnerabilities.

The platform is intended to handle commercially sensitive enterprise information, so security and data protection are important requirements.

11. Integration & Regression Testing

* Authentication testing.
* RBAC and permission testing.
* AI service integration testing.
* API testing.
* Database-access testing.
* Regression testing of existing functionality.
* Resolve defects introduced through the architectural refactor.

Expected Deliverables

At completion, we expect:

* Restructured onboarding/application boundary.
* AI agents separated from the main application.
* Secure backend-to-agent API architecture.
* Refactored backend architecture.
* Authentication and secure session management.
* RBAC and user permissions.
* Admin controls.
* Secure database and data-access configuration.
* AWS/Vercel deployment architecture.
* Security hardening.
* Logging, monitoring and error handling.
* Integration and regression testing.
* Technical architecture and deployment documentation.
* Clean and documented code committed to the existing repository.

Technical Experience Required

Strong experience with:

* Next.js
* React
* TypeScript
* Node.js
* Backend/API architecture
* REST APIs
* PostgreSQL or similar relational databases
* AWS
* Vercel
* Git/GitHub
* Authentication
* OAuth/OIDC
* RBAC
* Multi-tenant SaaS architecture
* Application and API security

Experience with AI/LLM systems is highly desirable, particularly:

* OpenAI API or similar LLM APIs.
* AI agent architecture.
* Tool/function calling.
* Structured outputs.
* RAG/document processing.
* Secure separation of AI services from web applications.

Experience with Microsoft Entra ID, Microsoft 365, SharePoint or enterprise system integrations would be advantageous.

Who We’re Looking For

We are looking for a senior-level engineer who can take ownership of the technical problem rather than simply execute predefined development tickets.

You should be comfortable reviewing an existing codebase, identifying architectural and security weaknesses, recommending solutions and implementing those solutions with minimal oversight.

You will work directly alongside our Co-Founder / Technical Lead and existing engineering team.

Initial Engagement

The first stage of the engagement will be to review the existing application and architecture.

Following the review, we expect you to provide:

1. Recommended target architecture.
2. Confirmed scope of work.
3. Estimated engineering hours and delivery timeframe.
4. Proposed milestones.
5. Fixed-price and/or hourly-rate proposal.
6. Identification of major architectural or security risks.

There is potential for ongoing development work following successful completion of the initial engagement.

When Applying

Please include:

* Relevant SaaS platforms you have built or architected.
* Examples of backend or platform architecture work.
* Experience with Next.js and Node.js.
* Experience with AI/LLM application architecture.
* Experience implementing authentication and RBAC.
* AWS/Vercel experience.
* Your hourly or daily rate.
* Current availability.
* Your approach to reviewing and refactoring an existing production codebase.
node.js postgresql software development oauth backend development security github next.js vercel ai agents
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.