Summary
✨ AI‑Generated
A Senior Backend Cloud Engineer will help transform an established networking platform from prototype into a supportable production service. The role spans C++ microservices, Python multi-tenant services, Kafka messaging, PostgreSQL, versioned REST APIs, identity and access control, device provisioning, configuration automation, and cloud infrastructure. Strong ownership and systems-level problem solving are central to the position.
Highlights
Senior backend/cloud role focused on taking a working platform into production and expanding its capabilities. The position offers substantial ownership across cloud services, APIs, multi-tenant architecture, automation, networking infrastructure, and production reliability.
Description
This is not a greenfield project.
We already run a working platform: the TIP OpenWiFi (uCentral) cloud SDK plus an in-house multi-tenant layer above it (Organisation -> Site -> Device model, canonical device catalogue, Keycloak/OIDC role-based access control, audit trail) and a React operator console.
Real access points, switches and site gateways are provisioned end to end in our lab today.
You are joining to take that from a working prototype to a supportable production service, and to extend it onto hardware and customers it does not yet support.
The work has two halves.
The southbound half is the upstream TIP uCentral microservice set - security, gateway, firmware management, provisioning and analytics services communicating over Kafka with PostgreSQL behind them, written in C++.
The northbound half is ours: a multi-tenant service layer in Python, a versioned REST API that the operator console and external automation consume, and the configuration pipeline that turns operator intent into device configuration.
We are hiring two engineers against this description.
You are not expected to be strong in both halves.
Tell us in your application which half you are closer to; we will set emphasis at offer.
Both hires are expected to be able to review across the boundary, because the worst bugs on this platform live exactly on it.
A standing requirement in both halves is that our changes stay rebaseable onto upstream TIP releases rather than forking into a dead end.
Key Responsibilities:
Platform layer.
Extend and maintain the in-house multi-tenant layer above the TIP SDK: tenancy model, device catalogue, role-based access control, audit.
Keep the upstream delta small, reviewed and documented.Northbound API.
Secure, versioned REST for the operator console and for external automation and integration.Configuration pipeline.
Turn operator intent into device configuration - uCentral configuration documents for access points and gateways, vendor command-line rendering for switches - with preview before apply, and with verification that the device is running what we think it is running.
Silent divergence between intended and applied configuration is the failure mode this platform must not have.Southbound scale.
Persistent WebSocket session handling for thousands of concurrent devices, state document ingestion, Kafka topic and partition design, consumer lag control.Data tier and retention.
This platform is telemetry-heavy: at target scale the raw state stream is measured in gigabytes per hour before compression.
You own the retention, downsampling and aggregation model, and the PostgreSQL schema and indexing that survives mass provisioning events without lock contention.Tenant isolation.
Enforce and prove data isolation between tenants, with an audit trail that stands up to a customer security review.
Required experience:
Strong production experience in at least one of C++, Go or Python in distributed systems.
The TIP services are C++; our layer is Python.
We are hiring for depth in one, not a checklist of all three.PostgreSQL at depth: indexing, connection pooling, lock contention, query plans under concurrent write load.Kafka or comparable streaming: partitioning strategy, consumer groups, backpressure, lag as an operational signal.WebSocket or other long-lived-connection services at scale, including TLS and mutual TLS termination.OAuth2 / OpenID Connect and API gateway security.Fork discipline against a fast-moving upstream open source project - you have rebased real work onto a moving target and can describe how you kept it survivable.
Valuable but not required:
Direct experience with the TIP OpenWiFi cloud repositories or the Poco C++ framework.Keycloak, or multi-tenant SaaS and managed service platforms.Network device configuration modelling: UCI, NETCONF and YANG, or vendor command-line rendering.Time-series storage and telemetry downsampling.
What success looks like in the first 90 days:
A documented and implemented telemetry retention model with measured storage cost per device per month.A simulator-driven scale test that establishes a defensible concurrent-device ceiling and names the first bottleneck.Upstream delta catalogued, with a repeatable rebase procedure.One configuration path shipped with applied-state verification, so the controller can prove what a device is actually running rather than what it was told to run.
What We Offer
At GuestTek, you won’t just have a job, you will have the opportunity to build your career while working with innovative technology and a global team.
Competitive compensation and comprehensive benefitsHybrid Work EnvironmentOpportunities for career growth and professional developmentExposure to innovative technology, AI, cybersecurity, and global projectsCollaborative and supportive work environmentOpportunities to work with teams and customers around the worldChallenging projects that make a real impactA culture that values innovation, teamwork, and employee contributions