🌐 Remote💼 Full-time🗓 2026-06-25
Rewrite
## About the Role
Full-time · Contract-to-Hire · Remote · US strongly preferred
Level: Mid-to-Senior — 5-7 years, depth over breadth
Industry: Health tech
Start: Immediate
*Approach: *AI-forward, non negotiable
## THE OPPORTUNITY
You're joining at the ground floor of a category-defining moment.
1 in 8 American adults have now taken peptides — and it's going mainstream fast. CollectiveOS is the Thrive Market for peptides: a platform offering access to clinician-guided, medical grade peptide protocols at 50% below retail pricing, sourced from licensed US pharmacies.
Built by a team that has helped build three unicorns, including Thrive Market and Function Health.
This is a regulated platform operating across 30 states with real obligations to real patients. Users trust us with health information, payment data, and clinical relationships. The backend has to be bulletproof — not because of theoretical risk, but because of those real obligations. This role is the person who makes sure that's true, and who builds the things on top of it.
## COMPENSATION & TIMELINE
STRUCTURE: Paid trial to start.
Competitive cash compensation from day one. Contract-to-hire — fastest way to find the right long-term fit and let you see us up close.
UPSIDE: Ground-floor equity.
Real equity in a funded D2C peptide startup, riding a category curve that's about to go vertical. The team has helped build three unicorns. You'd be early.
TIMELINE: Immediate start.
We are moving fast. The right person can start within weeks. We will not draw out the process for the sake of process.
## THE ROLE
AI-forward — uses AI to multiply leverage, not to skip thinking
This is a backend-primary role with real range. You own the API, the data model, the integration layer, the AWS infrastructure, and the security posture. You also own the API integration with the front-end — the contracts, the testing infrastructure, the connective code that keeps both sides honest. When the mobile app comes, you own the API layer it talks to.
## ARCHITECTURALLY
- NestJS modular monolith on ECS Fargate
- RDS PostgreSQL with KMS-backed encryption
- ElastiCache Redis for rate limiting
- S3 + KMS for document storage
- Self-built auth (bcrypt + JWT with refresh rotation + TOTP MFA + RBAC)
- Immutable audit log schema with INSERT-only application access
- Shared Zod schemas in a Turborepo monorepo
## TEST LAYERS
- Jest (unit, integration, smoke, regression)
- Playwright E2E across desktop and mobile viewports
- Chromatic for visual regression
- CloudWatch alarms with auto-rollback on error rate and latency thresholds
- CloudTrail for infra-level access
- Custom audit middleware for app-level PHI access
- PHI-tagged fields enforced by ESLint rule
## TECHNOLOGIES
- NestJS
- TypeScript
- PostgreSQL
- Zod
- Turborepo
- AWS (ECS Fargate, RDS, KMS, S3, ElastiCache, CloudTrail, Secrets Manager)
- GitHub Actions
- Jest
Sourced via wellfound · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.