Build our own products and AI-powered software for clients, starting with DeployReady, our open-source security scanner. Node.js, npm packages, and LLM integrations, built security-first.
Apply for this roleAbout the role
You'll build the software Belsoft sells and the AI features our clients need. That means our own products, starting with DeployReady, our open-source security scanner, plus new tools and platforms for the companies we partner with. Most of it is Node.js and TypeScript with LLMs at the core, using Claude, OpenAI, or local models. Whatever you build is security-first: every product has to be secure before we sell it to anyone.
What you'll do
- Build products and client software in TypeScript and Node.js, from first design to production
- Build AI features and LLM integrations with Claude, OpenAI, and local models: assistants, tool calling, structured output, and AI-driven workflows
- Design AI features safely: protect secrets and customer data, and treat user and third-party input as untrusted, including prompt injection
- Measure AI quality, speed, and cost, and pick the right model for each job
- Build and publish reusable npm packages, CLIs, and SDKs, with few dependencies, pinned and reviewed
- Threat-model features before building them, and write tests as part of the work
- Contribute to DeployReady and our other open-source work
What you bring
- 3+ years building production software with JavaScript/TypeScript and Node.js
- Hands-on experience integrating LLM APIs such as Claude or OpenAI into a product: prompts, tool calling, and structured output
- Experience publishing or maintaining npm packages, libraries, or CLI tools
- Security-first habits: input validation, least privilege, and safe handling of secrets, user data, and untrusted input
- A working understanding of npm supply-chain risks: typosquatting, malicious install scripts, dependency confusion, and hijacked packages
- Comfortable working with clients and explaining technical trade-offs clearly
Nice to have
- Agent frameworks, MCP, RAG, or embeddings
- Running local models with Ollama or llama.cpp
- LLM security: prompt injection, data leakage, and the OWASP Top 10 for LLM applications
- Static analysis or AST tooling such as Babel, ESLint rules, or the TypeScript compiler API
- Open-source maintainer experience
Apply
Sound like you?
Five minutes. No cover-letter theatre — just tell us what you've done and why this role.
