Atlas FinTech | Paris | Forfaitier / Project Mode | 15K EUR all-inMost "AI engineer" jobs right now are prompt-wrapping an OpenAI endpoint. This is not that job.We are building a treasury platform where the AI is structurally forbidden from executing anything. It proposes. A human approves. The system records every action in an append-only audit ledger. If the AI cannot ground an answer, it abstains (returns null, not a hallucination). If data tries to cross the EU boundary, a fail-closed gate kills it. Tenant isolation is enforced at the PostgreSQL level with FORCE ROW LEVEL SECURITY, not by a hopeful WHERE clause in the app layer.This is the governance spine. It is the moat. You will own the half of it that breathes: the LangGraph agents, the LLM gateway, the abstention envelope, the agent memory partitioned by tenant under RLS.About AtlasAtlas FinTech is a pre-seed startup based in Paris. We build treasury tooling for mid-market groups running multiple entities, bank accounts, and ERPs. The thesis is simple: connect, do not replace. We overlay existing systems (SAP, Sage, PSD2 bank APIs, ISO 20022 messaging) and add a governed AI layer on top.Why now: the EU AI Act is landing, data residency is becoming a requirement not a feature, and the mid-market treasury tools space is dominated by US platforms that cannot guarantee EU data sovereignty. The window is open.What you will doYou will build the agentic AI layer (atlas-agents) and the LLM gateway on top of an existing governance spine. The spine is already built and enforced in atlas-core: forced RLS on 35 tables, abstention envelope as a constructor-level type, HITL propose/execute (no execute verb exists, enforced by absence), append-only audit ledger, fail-closed egress gate validator. Your job is to build the agent tier as a governed client of this spine, never a path around it.You will work in a 7-repo polyrepo architecture: Angular 22 SPA, NestJS BFF, FastAPI core, FastAPI AI, FastAPI connectors, OpenAPI contracts as source of truth, Terraform infra. The target substrate is OVH VPS with Docker Compose, LangGraph agents, LiteLLM gateway, pgvector, EU sovereignty.You will not be told what to type. You will be given architecture decisions (ADRs) and expected to implement them with judgment. The CTO writes ADRs and reviews governance spine code. You write the code that makes them real.What you will buildFour milestones over roughly 3-4 months:Architecture spike: OpenAPI contracts, RLS schema, skeleton PRs. KNN reviews that contracts match the governance spine. This is the kill-switch milestone: if it does not land in about 2 weeks, the mission ends here.Core vertical slice: one treasury flow end-to-end, from propose to HITL to execute to audit ledger entry.Full MVP feature set per SOW.Hardening: tests, egress gate proof, docs, handover. 30-day warranty starts.Specifically, you own:LangGraph StateGraph with checkpointers and interrupt for HITL pause-inspect-resume, Postgres-backed checkpointerPer-tenant RLS-partitioned agent memory with pgvector, RLS inheritance provenLiteLLM gateway: self-hosted, OpenAI-compatible, model-tier routing behind the egress gateHITL propose-not-execute as a structural pattern (no execute verb exists, enforced by absence)Abstention envelope: abstain means data is None, as a constructor-level typeFail-closed egress gate: recursive forbidden-field scan, deny by constructionLangfuse self-hosted: best-effort observability, never on the audit critical pathWhat you need to haveThese are veto-level. If you do not have them, we will find out in the first 30 minutes of the screening call. We check honestly, and we respect honesty about what is new to you.LangGraph: StateGraph, checkpointers, interrupt for HITL, Postgres-backed checkpointerPostgreSQL RLS: ENABLE + FORCE ROW LEVEL SECURITY, NOBYPASSRLS, SET LOCAL app.tenant_id in transaction, fail-closed proofFastAPI async discipline: no blocking calls in async def, httpx/asyncpg, threadpool offloadpgvector for agent memory under RLS inheritanceLiteLLM gateway: self-hosted, OpenAI-compatible, model-tier routing behind egress gateHITL propose-not-execute as a structural pattern (no execute verb exists, enforced by absence)Abstention envelope as a constructor-level type (abstain means data is None)Fail-closed egress gate: recursive forbidden-field scan, deny by constructionLangfuse self-hosted: best-effort observability, never on audit critical pathEU sovereignty as a machine-enforced property, not a policy statementYou have 5 to 8 years of engineering experience post-graduation. You have shipped at least one production system personally. Range A engineering schools are a plus, not a requirement. GitHub repos with concrete projects are a plus, strongly weighted.You use an AI coding assistant daily (Claude, Cursor, Copilot, Codex), and you can name one time it was wrong and what you did about it. You know where it breaks the governance spine (it fabricates, it hallucinates fields, it bypasses guardrails if you let it), and you design around that.You have leadership potential. In 6 months we may hire a brilliant 3-year engineer who is sharper than you on LangGraph. You should be excited about that, not threatened. You want to grow into Tech Lead, then Head of. You can mentor without ego.You are honest. If you have not done something, you say so, and then you describe how you would approach it. Bluffing the governance spine questions is an automatic veto.What is nice to haveLangChain connector/retriever libraryNATS JetStream or RabbitMQ for async transportAlembic expand-contract migration disciplineDecimal/string money modeling (never float)Idempotent ingestion with dedup keysDocker-first authoring, no GCP-only dependencyWho you areWhat we offer15,000 EUR total, all-in. Forfaitier (project mode contract, not CDI). Delivery is 10,000 to 12,000 EUR phased across 4 milestones. Quality assurance is 3,000 EUR, released after a 30-day warranty closes clean. AI tooling up to 1,000 EUR reimbursed against invoices, within the 15K total. You pick the assistant. We reimburse the receipt.BSA equity: amount decided by the CEO. Vesting on MVP delivery and continuation.300 EUR challenge stipend if you reach the challenge gate and submit complete work (separate recruiting cost, not part of the 15K).A CTO who writes ADRs, not tickets. A CEO who does not pretend to be technical. No standup theater. Written async standups, one weekly sync, architecture reviews on demand.Who you work withKNN, CTO (Executive Advisor, roughly 40h/month). Writes architecture decisions, reviews governance spine code, unblocks. Does not write feature code. Co-authors the kernel.CEO (non-technical). Owns commercial, hiring budget, equity. KNN owns the technical interface. The CEO does not come to you directly with technical questions.One other freelancer (Fullstack, Frontend-Strong). You cross-review each other's PRs. You build full-stack context by reading each other's code.Growth pathThis is a freelance mission with a real continuation.Freelancer (MVP, months 1-4): execute against KNN briefs, own atlas-agents and the LLM gateway.Tech Lead AI Backend (conversion, months 5-8): CDI or new forfaitier at higher rate. Own a domain, review others, write briefs for juniors. BSA moves to 0.4-0.6 percent.Head of (months 16-18, if ready): 3+ reports, 4-track leadership program complete (architecture ownership, people leadership, hiring, spine stewardship). Gated on KNN sign-off, not time served.Promotion is not tenure-based. It is gated on completing concrete challenges.Interview processThree gates. Transparent. No surprises.Gate 0: Application filter (async, 15 min). We check: 5-8 years experience, at least one shipped production system, GitHub with 2+ repos with over 20 commits by you, evidence of AI-assisted workflow in your repos, SIRET or portage salarial, cumulative workload under 60 percent capacity.Gate 1: Screening (45-60 min, CEO + CTO). CEO block: motivation, communication,
Sourced from LinkedIn. Relocantly aggregates public job postings; apply on the original site.