About the job Dioptra (an Icertis Company) — Senior Software Engineer
Dioptra (an Icertis Company) — Senior Software Engineer
Type: Full-time | On-site 5 days/week | New York, NY (Brooklyn office) or San Francisco, CA Compensation: $180K–$280K + competitive equity Hiring count: 1 for this req (part of a 6-role push for a similar profile — see note) Visa sponsorship: Open to relocation; will transfer existing visas (e.g., H-1B, OPT); will NOT sponsor brand-new visas Reports to: Pierre Hadrien Arnoux, Co-founder / VP of Agentic AI, Icertis Hiring manager (Paraform): Farah Gasmi | Interview coordination POC: Doug
About Dioptra (an Icertis Company)
Dioptra builds contract-reviewing AI agents for enterprise legal tech. Backed by Y Combinator, it was acquired by Icertis in November. Rather than absorb the team, the Icertis CEO is building an entire business unit around the Dioptra founding team — its own sales, marketing, engineering, product, and support — with the explicit goal of preserving velocity. In the CEO's words, "I would rather be disrupted by my own startup than an external startup." The team continues to operate in high-velocity startup mode with enterprise-scale distribution and resources behind it.
Founded: 2009 | Team size: 1,800 employees (Icertis) | Industry: AI, Enterprise, Law, Software Development Website: www.dioptra.ai Office: New York (Brooklyn) + San Francisco
Why Candidates Should Join
- Work directly with the founders: Report straight to Dioptra's founding team with a real seat at the table — no layers of management between you and the people shaping the product.
- Greenfield backend ownership: Architect and build core systems from scratch with full ownership over technical decisions — not inheriting someone else's mess.
- Security work that actually matters: Own security-critical features like BYOK encryption, key management, and access controls for some of the world's largest enterprises (Microsoft, J&J, Mercedes-Benz), plus the SOC 2 program. Not checkbox compliance.
- AI agent work at the frontier: Build and secure LLM-powered agents and the infrastructure they run on, redefining how enterprises handle contracts.
- Backed and acquired — best of both worlds: YC- and Engineering Capital-backed, now acquired by Icertis. Startup energy and ownership with enterprise-scale distribution and resources.
- Massive market at an inflection point: Enterprise legal tech is wide open, and you'd be building the product going after it with a team carrying 10+ years of hands-on AI and commercial-contracting experience.
Intake Call Summary
The intake was a shared session covering three roles: a Design Engineer, this Backend / Senior Software Engineer ("security") role, and a separate AI Engineer role. Design Engineer content (React/Figma/design-first) is a different req and is excluded from scoring here.
Company / mission
- YC-backed; acquired by Icertis in November. CEO is building the whole business unit around the Dioptra founding team to preserve startup velocity ("rather be disrupted by my own startup than an external startup").
- Operates like a pre-seed / Series A company on ownership, agency, and time commitment despite the larger parent.
What this role is
- "Really an AI and a backend engineer." Python required; AI means agentic experience specifically.
- Owns the security requirements the company takes on: the in-progress SOC 2 audit (implementations, controls, infra), customer BYOK requests (customers holding their own encryption keys), and securing AI-agent infrastructure (e.g., the infra patterns and MCP surfaces that agents run on).
- A fair amount of infrastructure work alongside backend — AWS or Azure, scaling, and some DevOps.
- Intake framing was backend-only: "I don't expect them to be doing front end or UI." (Conflicts with the role page, which lists production JS/TS and end-to-end agentic incl. a front-end component as Required — see flag.)
Must-haves (Farah, verbatim priority): Python, AI agents, security. Nice-to-haves (Farah): the right mindset (high ownership / high agency); enterprise experience; startup experience; prior founding-engineer experience. (Flag: the role page and the rejection history harden startup/founding experience into a de facto hard gate — see Scoring Calibration.)
Key calibration — NOT a pure security engineer. Doug course-corrected mid-call: he'd been sending pure security-engineer profiles, but the target is "really solid backend architecture and infrastructure thought process around data systems, with an eye for security and building secure systems." Farah agreed. Weight backend/infra architecture first, security mindset second.
Company-type bar. "If it's not a tech / product company, it doesn't count." Non-tech core businesses (banks, consulting) are much harder and generally disqualifying. McKinsey is a rare exception (very hard hiring bar filters for intelligence and hard workers). Microsoft is specifically disfavored ("very enterprisey, very slow" — a Microsoft-identity candidate was rejected on this alone); Meta-style "move fast" is fine.
Research-only concern. For the adjacent AI Engineer role, an MIT/Cambridge PhD was flagged as "very researchy — nothing tells me he's a production-level coder." Same reservation applies here: academic/research depth without production engineering is a concern.
Culture / hours. High ownership and agency; roughly 8:30am–7:30pm; explicitly not a 996 shop. Intake said "at the very least four days a week"; the role-page Must-have (updated) is 5 days — 5 days governs.
Comp / logistics. Salary put at $180K–$270K in the intake. Company relocates candidates; will transfer existing visas (H-1B, OPT) but will not sponsor brand-new visas.
Interview process. Same for both roles: 3-step — 15-min screening, technical evaluation, then a board or presentation review. Doug is the coordination point of contact. (Role page shows 4 steps — confirm whether a stage was added.)
The Role
A Senior Software Engineer to own AI/agentic backend and infrastructure work end-to-end in a fast-moving, early-stage environment, reporting directly to Dioptra's founders. The center of gravity is production backend + agentic infrastructure + security; the role page also asks for enough JS/TS to carry a feature through to a working front-end component (see backend-vs-full-stack flag).
What You'll Be Doing
- Architect and build core features from scratch with a focus on reliability, scalability, and security — greenfield work reporting directly to the founders.
- Own security requirements: SOC 2 controls and implementations, customer BYOK / key-encryption features, access controls and auth.
- Design and secure the infrastructure that AI agents run on; build and deploy AI-powered agents in Python to automate complex contract workflows.
- Build robust agent workflows integrating LLMs, APIs, databases, business systems, and external tools.
- Stand up and scale cloud infrastructure (AWS or Azure), including a meaningful DevOps component.
- Translate ambiguous enterprise security requirements into concrete systems and shipped features.
- Establish engineering best practices, tooling, and culture as an early member of a small, high-impact team.
Tech stack: Python (ML + agentic infrastructure), AWS or Azure + DevOps, JavaScript/TypeScript (production), LLM-powered agents, agentic harness / MCP + agent orchestration; enterprise contract-workflow domain.
Qualifications
Seniority
- 5+ years building and shipping production backend systems. [Required]
Work Experience
- Shipped production systems at a startup or high-ownership environment. [Must have]
- Designed or implemented security-sensitive systems (encryption, key management, auth). [Required]
- Built or deployed AI/ML or LLM-powered agents in production. [Required]
- Must have worked in a small startup (under 100 people) while there — as founder, founding engineer, or early hire. [Required]
Education
- No specific degree requirement stated in the role brief. (Intake, for the design role, noted non-CS/creative backgrounds as a plus; for this role, production engineering ability is what matters.)
Hard Skills
- Strong Python — production-level code for ML and agentic infrastructure. [Must have]
- Cloud infrastructure experience (AWS or Azure) including DevOps. [Required]
- Used JavaScript or TypeScript in a production environment. [Required — note intake's backend-only framing]
- Building agentic systems end-to-end; understands agentic harness / MCP and orchestration well enough to do a systems design around them. [Required]
Soft Skills
- High agency: self-directs, identifies and solves problems independently. [Must have]
- Comfortable translating ambiguous enterprise security requirements into concrete systems. [Required]
Miscellaneous
- Willing to work in-office in New York 5 days/week. [Must have]
- Now also accepting candidates in San Francisco, on-site 5 days/week. [Required]
Traits to Avoid
- Primarily non-tech / non-product company background (e.g., banks, consulting). McKinsey is the rare exception.
- Slow-moving enterprise mindset (e.g., long tenures at Microsoft-like cultures). Meta-style move-fast is fine.
- Frequent job hopping (every six months).
Role Details
- Salary: $180K–$280K (role page) / $180K–$270K (intake) — see comp flag
- Equity: Competitive equity
- On-site policy: 5 days/week on-site; NYC (Brooklyn office) or San Francisco. Intake said "at least 4 days," typical hours ~8:30am–7:30pm, explicitly not a 996 culture; the 5-day Must-have (updated) governs.
- Visa sponsorship: Open to relocating candidates; will transfer existing visas (e.g., H-1B, OPT transfers); will not sponsor brand-new visas.
- Employment type: Full-time
- Location: New York, NY (Brooklyn) or San Francisco, CA
Screening Questions
The official 4 candidate questions are still collapsed in the copied HTML ("View 4 questions"). Re-copy with that section expanded to capture the exact wording — these feed the outreach email per workflow.
Interim screening intent pulled from the intake (Doug/Farah), to confirm against the official four:
- How big was the team at your most recent startup/role, and what portion did you fully own?
- Describe production agentic systems you've built (MCP / agent orchestration) — scope and your specific contribution.
- Your security work: SOC 2, encryption / key management / auth, BYOK, securing agent infrastructure.
- Cloud/infra depth: AWS or Azure, scaling, DevOps.
- If a recent tenure is short, why are you leaving early?
Interview Process
Stage 1 — Screening (15 min): Initial pre-screen. Stage 2 — Technical evaluation. Stage 3 — Board or presentation review.
Role page indicates 4 steps; intake described this 3-step flow. Confirm whether a stage was added. Doug is the interview-coordination point of contact.
Ideal Companies & Backgrounds
No dedicated Ideal Companies section was present in the copied HTML. Signal from the strong-example profile and intake: backend/infra engineers with a security eye out of regulated or high-ownership tech environments (e.g., fintech), with a genuine startup/founding chapter and production AI/agentic work. Meta-style product companies read well; Microsoft and non-tech core businesses read poorly. Confirm with a dedicated Ideal Companies list from Paraform if one exists.
Ideal Candidate Profiles
For reference only — do not source these specific profiles.
Sam Riggs — LinkedIn Software Engineer @ Credit Genie | New York, United States
- Security engineer background at large regulated shops (Amazon, BlackRock) — rigorous, well-thought-out.
- Currently at Credit Genie (fintech startup) — comfort with high-ownership, fast-paced work; highly regulated domain (relevant to SOC 2 / enterprise security).
- Farah's read: the relevant security engineering role is what's compelling; regulated-industry exposure is a plus, not a requirement; the startup chapter is a positive.
- Areas for improvement flagged by client: no explicit AI/agentic experience visible; short Credit Genie tenure (~7 months — ask why leaving early); Python backend proficiency unclear (background skews security over backend dev).
Rejected Candidate Feedback
Formal client feedback (Rejected Candidate Feedback panel):
- Founding / startup experience: Only consider candidates with proven early-stage or founding engineering roles that owned end-to-end product features — not just big-tech backgrounds.
- Agentic product ownership: Must demonstrate hands-on experience building production-ready AI agent systems (MCP + agent orchestration) spanning both back-end and front-end.
- Relevant tech stack & location: Prioritize strong Python, TypeScript/React, and AWS, with full commitment to 5-day on-site in NYC or SF.
Per-candidate rejection signals (bad-fit cards):
- "Not enough agentic AI experience" is the single most common kill reason — non-negotiable "until we get bigger."
- "Zero small-company / startup experience" and "no start-up experience" kill even strong big-tech engineers.
- "At least 18 months in a startup" wanted — very short startup stints may not clear the bar.
- "Not in NYC" cited pre-SF opening — location commitment matters (now NYC or SF, 5 days).
- Communication/fit rejections: "poor communication," "overly complicated thinking, may not do well in a startup," "not responsive."
- "Advising non-tangible founders seems pretty thin" — advisory/fractional roles don't substitute for hands-on founding/early-engineer work.
- One strong candidate rejected for wanting "one experience with a larger established company" — the large-company balance factor cuts both ways.
Live-call rejections from this intake (calibration):
- Meta ML/ads engineer (Kril, via Para AI): rejected — no clear security work in recent roles despite strong ML.
- Microsoft identity-platform engineer: had genuine auth/access-control work, but rejected purely on the Microsoft "enterprisey and slow" concern.
Scoring Calibration (from intake — read before scoring)
- Startup experience is effectively a hard gate. Farah called it a "nice-to-have" for the backend role in the abstract, but the role page (updated) marks it Required and the rejection history kills big-tech-only profiles repeatedly. Score a missing genuine startup/founding chapter as a Must-have miss.
- Backend/infra architecture first, security second. Per Doug's course-correction, do not over-index on pure security-engineer titles; prioritize strong backend + infrastructure + data-systems architecture with a security eye.
- Agentic production experience is non-negotiable. Internal dev tooling for coding does not count — must be agentic systems built for a product, with MCP/orchestration understanding.
- Company pedigree filter: tech/product companies count; non-tech core (banks, consulting) generally doesn't (McKinsey excepted). Microsoft strongly disfavored; Meta-style favored.
- Backend-only vs full-stack conflict: intake said no front-end/UI; role page requires production JS/TS + end-to-end agentic incl. a front-end component. Treat the role page as governing but surface for HM confirmation.