Description
Role Overview
The Full-Stack Engineer builds and owns features end to end across Qashio's corporate card and spend management platform β from the interfaces our customers use every day, through the APIs, services and data models behind them.
Reporting directly to the Chief Technology Officer, this role carries real influence over how we build, not only what we build.
This is an AI-native engineering role.
We expect the person in this seat to work fluently with agentic coding tools as part of their normal delivery workflow, to build AI-powered capabilities into the product itself, and β critically β to bring the judgement required to ship AI-assisted code safely in a regulated financial environment.
Speed matters here; so does the discipline to verify what a model produces before it touches customer money.
Responsibilities
Product delivery
Design, build and own full-stack features end to end β from React and Next.js interfaces through Node.js and NestJS services, APIs and data models β and remain accountable for them in production.Build and maintain RESTful APIs and integrations across internal systems and third-party providers, including card issuing, banking, ERP and accounting platforms.Translate product and business requirements into technical designs, and technical trade-offs back into terms product, finance and operations stakeholders can act on.Write clean, well-documented and tested code, and keep changes small enough to be reviewed properly.Troubleshoot and resolve production issues, taking part in on-call and incident response for the services you own.Ensure everything you ship meets Qashio's security, privacy and compliance obligations, with particular care around authentication, authorisation, payment flows, cardholder data and PII.Contribute to the improvement of our development processes, tooling and CI/CD pipeline.
AI-assisted delivery
Deliver features using agentic coding tools (Claude Code, Cursor, GitHub Copilot or equivalent): decompose work into agent-sized tasks, write the specifications and tests that define correctness, and direct the tooling to implement against them.Review, test and harden AI-generated code before it reaches production.
Generated output is a draft to be verified, never a result to be accepted β you own every line in your pull request regardless of how it was produced.Maintain the context that makes AI tooling effective in our codebase: repository instruction files, reusable prompts and skills, MCP connections to internal systems, and architecture documentation that stays current.Raise the team's AI leverage β share the workflows that work, retire the ones that do not, and help set Qashio's internal standards for safe and effective AI-assisted development.
Building AI into the product
Build AI-powered product capabilities against providers such as OpenAI, Anthropic or AWS Bedrock, including retrieval, tool calling, evaluation harnesses, cost and latency budgets, and guardrails against prompt injection and data leakage.
Qualifications and Experience
Core engineering β essential
Bachelor's degree in Computer Science, Engineering or a related field, or equivalent practical experience.5+ years building and running production web applications as a full-stack engineer, with genuine depth on both sides of the stack.Front-end: React, Next.js, TypeScript, JavaScript.Back-end: Node.js, NestJS, TypeORM, TypeScript.Databases: PostgreSQL, plus working experience with at least one NoSQL store (MongoDB, DynamoDB, Cassandra).Cloud and delivery: AWS, containerised services, CI/CD pipelines, automated testing and production observability.Experience with RESTful APIs, microservices architecture and API gateways.Strong grasp of modern software design principles and common patterns, and of secure coding practices for systems handling financial and personal data.
Building with AI β essential
Demonstrable day-to-day use of at least one agentic coding tool β Claude Code, Cursor, Windsurf, GitHub Copilot or equivalent β in real production work rather than experimentation.
You should be able to walk us through a feature you shipped this way, including what the tool got wrong and how you caught it.Context engineering: able to give an agent the specification, constraints, examples and repository context needed to produce work you would put your name on β and able to recognise when a task is a poor fit for an agent and should be written by hand.Verification discipline: test-first workflows, small reviewable commits, checkpointing and fast rollback.
You can explain any line of generated code in your pull request and justify why it is there.Security judgement on generated code: familiar with the common failure modes β hallucinated or outdated dependencies, insecure defaults, missing authorisation checks, injection and cross-site scripting, secrets committed to code or pasted into prompts β and with the controls that catch them, including static analysis, dependency and secret scanning, and human review gates.Data-handling boundaries: a clear understanding of what may and may not be sent to third-party models, and why that matters for a company handling cardholder and customer financial data.
Building AI into the product β preferred
Production experience integrating LLM APIs (OpenAI, Anthropic, AWS Bedrock): streaming, retries and timeouts, token and cost control, caching, and graceful degradation.Retrieval-augmented generation and vector search, structured outputs and tool or function calling.Experience evaluating LLM features β building eval sets, detecting quality regressions, and defining acceptance criteria for non-deterministic systems.Working knowledge of the OWASP Top 10 for LLM Applications β prompt injection, insecure output handling, sensitive information disclosure β and the mitigations for each.Prior experience in fintech, payments or another regulated domain (PCI DSS, SOC 2, data residency requirements).
Essential Competencies
Judgement over output volume β knows when to accept, correct or discard AI-generated work, and when a problem needs to be thought through from first principles by a human.Review rigour at speed β comfortable being the reviewer as often as the author, without letting standards slip as volume rises.Security-first instinct β treats code as unverified until proven otherwise, particularly where money, credentials or customer data are involved.Learning velocity β adopts new tooling quickly, and abandons it just as readily when something better appears.Ownership and autonomy β operates well under ambiguity, decides without waiting to be told, and escalates early when a decision needs a different owner.Written clarity β specifications, tickets and pull request descriptions are the interface to both colleagues and agents; vague writing produces vague software.Understanding of user needs, and the ability to translate business requirements into technical solutions.Technical problem-solving, analytical rigour and data-based decision-making.Cross-functional collaboration across product, design, operations and compliance.
Additional Details
How we build at Qashio
AI is part of the standard toolchain here, not a side experiment.
Engineers are expected to use it, expected to review what it produces, and accountable for what ships.
We assess engineers on outcomes delivered and defects avoided, not on lines typed by hand.