{"id":1347407,"url":"https://alion.io/job/ypo-sr-developer-api","title":"Sr. Developer, API","company":{"id":1769951,"name":"YPO","domain":"ypo.org","url":"https://alion.io/company/ypo-org","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":null},"role":"Backend","role_family":"Backend","seniority":"senior","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["United States"],"countries":["US"],"hiring_countries":["US"],"hiring_countries_total":1,"salary":{"min":119200,"max":155000,"currency":"USD","period":"year","gross":null,"usd_annual":155000},"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Adjust","optional":false},{"name":"AI Agents","optional":false},{"name":"Amazon EventBridge","optional":false},{"name":"Apache Kafka","optional":false},{"name":"API Gateway","optional":false},{"name":"Auth0","optional":false},{"name":"AWS","optional":false},{"name":"AWS CDK","optional":false},{"name":"AWS Lambda","optional":false},{"name":"AWS Step Functions","optional":false},{"name":"Azure","optional":false},{"name":"Azure DevOps","optional":false},{"name":"CI/CD","optional":false},{"name":"CloudFormation","optional":false},{"name":"Datadog","optional":false},{"name":"ElasticSearch","optional":false},{"name":"GCP","optional":false},{"name":"GDPR","optional":false},{"name":"Gemini","optional":false},{"name":"GitHub Actions","optional":false},{"name":"GitLab CI","optional":false},{"name":"GraphQL","optional":false},{"name":"Hallucination","optional":false},{"name":"IAM","optional":false},{"name":"ISO 27001","optional":false},{"name":"Jenkins","optional":false},{"name":"Kubernetes","optional":false},{"name":"Least Privilege","optional":false},{"name":"LLM","optional":false},{"name":"Okta","optional":false},{"name":"OpenAI","optional":false},{"name":"Python","optional":false},{"name":"RAG","optional":false},{"name":"SOC 2","optional":false},{"name":"Terraform","optional":false}],"status":"live","first_seen_at":"2026-09-09T00:00:00Z","employer_posted_date":"2026-09-09","last_verified_at":"2026-09-28T03:44:34Z","board_verified":true,"closed_at":null,"days_open":19,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":19},"description":"Position Title: Senior Developer, APIs\nDepartment: Technology - Engineering - Digital Experience (DEx)\nReports to (Title): Head of Engineering\nLevel/Sub-Level:Operations Level / Professional\nExempt Non-Exempt\nPOSITION PURPOSE\nThe Sr. Developer, APIs is responsible for designing, building, and maintaining the API platform that supports YPO's member ecosystem, chapter operations, and agentic AI platform.\nThis role owns the technical implementation of APIs that sit at the core of the digital experience and works closely with Product, Data Architecture, IT, and Security to deliver scalable, secure, and well-governed API solutions.\nThe role requires strong backend engineering expertise, a high standard for API quality, and the ability to translate complex integration requirements into maintainable, production-grade systems within an event-driven, domain-aligned, serverless-first architecture.\nYour API Portfolio: You will own the engineering implementation of three core API domains:\nMembers API\nStable, semantic endpoints exposing member profile, identity, peer discovery, and graph relationships. The foundation of member experience.\nChapters API\nAPIs powering chapter management, forum operations, event discovery, and role-based data access across YPO's global regional structure.\nAgentic Ecosystem APIs\nGoverned API contracts for AI agents (Peer Discovery, Event Discovery) built on OpenAI + RAG and Google Gemini. Agents consume only approved APIs. Agent reasoning must always be surfaceable.\nPRIMARY RESPONSIBILITIES\n1. API Design & Implementation\nDesign and implement production-grade RESTful and GraphQL APIs deployed via AWS API Gateway that are stable, semantic, and decoupled from vendor-specific backend schemas.\n\nEnsure all APIs conform to YPO's canonical ontology and global member graph. No endpoint may directly expose Salesforce object structures. APIs must map to govern entity definitions maintained in the enterprise data dictionary.\n\nDesign APIs to operate within an event-driven architecture leveraging CDC, pub/sub messaging (Kafka and AWS EventBridge), and idempotent patterns.\n\nApply Domain-Driven Design (DDD) principles bounded contexts, ubiquitous language, and domain events to ensure API boundaries reflect business domains, not implementation details.\n\nAdopt a serverless-first approach using AWS Lambda, Step Functions, and EventBridge where appropriate, selecting stateful services only when serverless patterns are genuinely insufficient.\n\nWrite clean, well-tested, and well-documented code across the Members, Chapters, and Agentic Ecosystem API domains.\n\nDefine and enforce data models, versioning standards, authentication flows (Auth0 / Okta / OAuth 2.0), and integration patterns from first principles.\n\nApply performance-aware design intentional pagination, caching strategies, query constraints, and rate-limiting so APIs scale safely under real-world load.\n\nEvery API decision must reinforce member trust through privacy-first architecture, consent enforcement, and transparent data usage.\n\nEnsure every API response includes provenance and explanation metadata, so agent reasoning is always surfaceable to the member.\n\n2. Agentic Ecosystem Engineering\nImplement the API governance layer that controls how YPO's AI agents (Peer Discovery, Event Discovery) interact with member data on OpenAI + custom RAG and Google Gemini.\n\nAll agent-facing APIs must support structured retrieval, citation-ready provenance fields, consent-aware filtering, and deterministic fallback.\n\nBuild and maintain kill-switch-capable API boundaries that prevent agents from ever consuming raw member data outside approved contracts.\n\nInstrument agent API integrations with feedback loop mechanisms hallucination rates, task success rates, and cost-per-outcome metrics must be observable and attributable to specific API behaviors.\n\nCollaborate with data science and ML teams to translate agentic data flow requirements into governed, tested API contracts.\n\n3. API Lifecycle, Versioning & Governance\nOwn the full API lifecycle: development, testing, documentation, versioning, deprecation, and migration planning. Every phase requires an explicit decision, no implied continuation.\n\nEstablish and maintain engineering standards for API versioning, backward compatibility, and breaking-change policy.\n\nBuild and maintain sandbox environments, integration test suites, and automated contract tests for every endpoint in the portfolio.\n\nWorking with Engineering leads to ensuring reliable CI/CD pipelines, deployment automation, observability via Datadog, alerting, and uptime SLAs. All infrastructure changes must be deployed via Infrastructure as Code (Terraform or AWS CDK) manual console changes in production are not permitted.\n\n4. Cloud Architecture, IAM & Security\nDesign and enforce IAM boundary design using least-privilege principles, permission boundaries, and Service Control Policies (SCPs) ensuring API-layer identities and Lambda execution roles cannot exceed governed data access boundaries.\n\nOperate within and contribute to YPO's multi-account AWS strategy (AWS Organizations, Control Tower) understanding how workload isolation, environment separation, and cross-account roles affect API deployment patterns and security boundaries.\n\nAll cloud infrastructure must be defined and maintained as code using Terraform or AWS CDK this is a hard requirement, not optional practice.\n\n5. Developer Experience & Enablement\nProduce and maintain clear API documentation, for example queries, and troubleshooting guides so internal teams can self serve without escalation.\n\nSupport technical onboarding for new product teams and integration partners, ensuring APIs are discoverable, stable, and easy to consume.\n\nIdentify and address developer friction proactively issues must never surface only via member complaints or downstream team escalations.\n\nAct as a technical resource for Engineering peers consuming the Members, Chapters, and Agentic APIs.\n\n6. Cross-Functional Collaboration\nWork closely with Data Architecture to ensure APIs maintain stable semantic meaning over evolving backend schemas frontend experience must be decoupled from vendor-specific fields.\n\nPartner with IT and Security to enforce role-based access, chapter-scoped data boundaries, and member consent policy (Auth0 / Okta, OneTrust, GDPR, CCPA).\n\nCollaborate with Product teams and the Sr. Product Manager, Technical to translate requirements and API specifications into production implementations.\n\nEvaluate and integrate third-party technologies (Elasticsearch, Kafka / AWS EventBridge, Search Orchestration Service) that enhance YPO's member ecosystem.\n\nHow We Measure Success\nAPI Reliability APIs meet defined uptime SLAs; issues detected proactively via Datadog not reported by members.\n\nCode Quality New endpoints ship with full test coverage; zero undocumented breaking changes; lifecycle plans in place for every endpoint.\n\nDeveloper Experience Internal teams can serve from documentation; integration timelines reduced; escalations minimized.\n\nDelivery Roadmap milestones delivered on time, with acceptance test coverage and passing CI/CD pipelines.\n\nAgent Safety Zero agentic API calls bypass the governance layer; kill-switch tested and functional for all agent endpoints.\n\nExplainability Every API response includes provenance and explanation metadata; no result feels like a black box.\n\nObservability All agent integrations emit hallucination rates, task success, and cost-per-outcome metrics traceable to specific API behaviors.\n\nIaC Compliance All infrastructure changes are deployed via Terraform or CDK; no manual console changes in production.\n\nSKILLS\nAbility to work collaboratively in a multi-cultural organization with international members, helping them achieve excellence in voluntary roles for YPO initiatives.\n\nExcellent interpersonal skills, including strong diplomacy skills with the ability to build meaningful relationships with all levels of associates, members and vendors. Adaptable, insightful, empathetic and reliable. Great sense of humor and humility.\n\nResourceful and able to work independently with initiative and common sense. Effective time management, organization and prioritization skills with the ability to focus on varied projects simultaneously.\n\nPossesses a distinct global mindset, sensitive to local and international customs and protocols.\n\nDemonstrate empathy through active listening and asking the right questions to find the source of an issue.\n\nAble to identify problems, research alternatives, provide solutions and/or resolve issues in a timely manner. Anticipates member/internal client needs and delivers with clarity.\n\nAnalytical thinker with ability influence and guide processes with appropriate approach and execution. Natural curiosity and desire to learn more; proficiency and interest in applying new technologies and tools.\n\nExcellent verbal and written communication skills, including proof reading, with a meticulous attention to detail. Adjust communication style appropriately to the audience.\n\nProfessional presence, appearance, and stature to interact easily with YPO members, C-level executives and peers at all levels within the organization.\n\nStrong ability to translate complex security risks into clear business decisions.\n\nDemonstrated ability to work collaboratively across product, engineering, and global teams.\n\nAnalytical thinker with strong architectural judgment and risk-based decision making.\n\nHigh degree of discretion and integrity in handling confidential information.\n\nAbility to operate independently in fast-moving, ambiguous environments.\n\nEXPERIENCE/BACKGROUND\n5+ years of hands-on experience in security engineering, with at least 3 years focused on cloud infrastructure security (AWS, Azure, and/or GCP).\n\nExperience integrating security tooling into CI/CD platforms (GitHub Actions, Azure DevOps, GitLab CI, Jenkins, etc.).\n\nExperience securing AI/ML infrastructure, including model APIs, data pipelines, vector databases, and inference endpoints.\n\nExperience with AI technologies, ability to monitor LLM usage, audit model access controls, etc.\n\nAPI abuse detection across the entire SDLC.\n\nStrong experience with IaC tools (Terraform, CloudFormation, ARM).\n\nFamiliarity with container security and Kubernetes environments.\n\nExperience with SAST, DAST, SCA, and dependency scanning tools.\n\nProficiency in Python or equivalent scripting language.\n\nStrong knowledge of IAM, encryption, OAuth/OIDC, RBAC, and secure cloud architecture principles.\n\nUnderstanding of compliance & security frameworks (SOC 2, ISO 27001, NIST).\n\nExposure to mobile application security on native iOS and/or Android platforms, including API security, token management, and mobile threat defense.\n\nEDUCATION/TRAINING/CERTIFICATION\nBachelor’s degree in computer science, Information Security, or related field (or equivalent experience).\n\nSecurity certifications are highly desirable (AWS, Azure, GCP, CISSP, CCSP, GIAC, etc.).\n\nPHYSICAL REQUIREMENTS\nAbility to work flexible and/or extended hours as needed to accommodate members and team members in multiple time zones.\n\nWillingness and ability to travel, domestically and internationally, without restrictions, approximately 5-10% per year.\n\nEOE\nYPO is an Equal Opportunity Employer. YPO takes pride in supporting a diverse workforce and demonstrates this through its policies and practices. YPO does not discriminate in recruiting, hiring, training, promotion or other employment practices for reasons of race, color, religion, gender, national origin, age, sexual orientation, marital or veteran status, disability or any other legally protected status.\nCOMPENSATION & PAY TRANSPARENCY\nCompensation at YPO is one part of a broader Total Rewards philosophy built to attract, motivate, and retain talented people in every country and function where we operate. We aim to be fair, consistent, and thoughtful stewards of our resources, and we ground pay decisions in m...","description_format":"text","description_chars":13093,"description_truncated":true,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Equity"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":[],"lifecycle":[{"event":"open","at":"2026-09-27T17:22:50Z"}],"liveness":{"score":58,"band":"ok","label":"Likely open","p_open":1,"p_active":0.647,"p_room":0.9,"age_days":19,"expected_fill_days":30,"reasons":["conf:1","win:mid"],"computed_at":"2026-09-28T05:41:14Z"},"pay":{"stated_usd_annual":155000,"is_top_pay":false},"html_url":"https://alion.io/job/ypo-sr-developer-api","json_url":"https://alion.io/job/ypo-sr-developer-api.json","meta":{"generated_at":"2026-09-28T05:41:14Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3853,"day_limit":5000,"remaining_today":1147,"minute_limit":60,"resets_at":"2026-09-29T00:00:00Z"}}}