CRACI · On-site, Helsinki (Kamppi) · Full-time
CRACI is a cybersecurity startup building cloud-native software supply-chain security. We run hostless, managed CI/CD runners on Kubernetes and dedicated bare metal, using confidential computing so proprietary code never touches shared infrastructure. The result: engineering teams' builds get faster, cheaper, and safer at the same time.
That matters right now, as supply-chain attacks have every CISO asking what touches their build environment. We have paying customers running millions of build minutes a month. This is an early seat to a rocket, and the team has grown to 15 people in 10 months.
You'll build the product itself: the systems that make builds fast, isolated, and safe, and the control plane and APIs customers integrate with. This is deep systems work close to the metal, covering performance, security, and a real threat model, not CRUD over a framework.
As a senior engineer you'll own things end to end. You design, ship, run in production, and feel the consequences directly. You'll have real latitude to shape architecture and set the engineering standards a growing team inherits, and real accountability for how it runs.
Design, build, and operate core pieces of the platform: runners, the per-build sandbox/isolation layer, scheduling, caching, and the control-plane APIs.
Chase performance seriously. Build times are the product; profile, measure, and cut them.
Treat security as a first-class design constraint: isolation boundaries, supply-chain integrity, and least privilege are part of every design.
Own what you ship into production, with on-call for your own systems, honest post-mortems, and real reliability.
Help set the engineering bar through code review, testing, and the standards a growing team inherits.
Must-haves
Production track record: you've run real systems in production, broken them, and made them better. You've got the judgement that comes from having done it.
Strong systems engineer, comfortable below the framework line: Linux, processes, networking, containers, and how they actually work.
Cloud-native & data at scale: deep knowledge of cloud-native architecture (Kubernetes) and big-data platforms.
Go: you write production Go, or you're a strong systems engineer in a neighbouring language (Rust, C, C++) who can ramp fast. Our stack is Go.
Security-minded: you reason about threat models and trust boundaries by default, and you care about getting isolation right.
Bonus (genuine differentiators, not requirements)
CI/CD internals: you've worked on build systems, runners, or developer infrastructure.
Nix: you use it, or you're keen to. We build reproducibly with Nix.
Observability: you've built monitoring/observability into systems (OpenTelemetry, metrics, tracing), not bolted it on after.
Agentic coding tools: you reach for them to move faster. Not required, but it signals the productivity-focused mindset we like.
Low-level / performance: kernel, virtualization, confidential computing, or serious performance-tuning experience.
Domain adjacency: prior cybersecurity or supply-chain-security exposure shortens your ramp. Nice to have, not required.
0→1 builder: you're comfortable owning ambiguous problems in an early-stage team.
A real early-stage seat with room to build, not just execute.
A small team of sharp, like-minded engineers with deep expertise, all in one room.
Hard, meaningful problems across performance, isolation, and security, at the layer most engineers never get to touch.
Paying customers and production traffic from day one.
Compensation: base plus equity.
On-site, not remote. We're early, and we're building a tight-knit team in one room. Our office is in a prime spot in Kamppi, central Helsinki.
Our process includes an initial call, a startup fit interview, and a live, on-site technical exercise on a real problem from our domain, because the job is to design and build real systems under real constraints, so we watch you do exactly that. No abstract algorithm trivia.
This job comes with several perks and benefits
