> Markdown version of [/jobs/ext/2600374-senior-software-engineer-mcp-ai-platform](https://www.wearedevelopers.com/jobs/ext/2600374-senior-software-engineer-mcp-ai-platform). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Engineer - MCP & AI Platform - **Company:** InApp Inc. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Audit Trail, Cyber Security, Elasticsearch, Python (Programming Language), Key Management, PostgreSQL, Node.Js, OAuth, Redis, Swagger, SAP (Applications), Software Engineering, Systems Integration, TypeScript, Management of Software Versions, Openapi, Data Logging, Large Language Models, Spring-boot, Amazon Virtual Private Cloud (VPC), Backend, Event Driven Architecture, HR Software, AI Platforms, Fieldglass, Functional Programming, Cloudwatch, Api Gateway, Restful APIs, Amazon Simple Queue Service (SQS), Api Management, Workday, Servicenow - **Published:** August 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b99016920ce34c61 ## About the Role * 4+ years of professional software engineering experience building production backend systems. * Direct experience designing and implementing MCP servers - you have shipped at least one MCP integration that is in production or active use. * Strong proficiency in Node.js or TypeScript; familiarity with Python or Java is a plus. * Experience with AWS Lambda, API Gateway, VPC networking, Secrets Manager, and CloudWatch. * Solid understanding of REST API design, OpenAPI/Swagger specifications, and API versioning strategies. * Experience with OAuth 2.0 flows (client credentials, on-behalf-of) and API Key management. * Clear understanding of how LLMs consume tool definitions and how tool description quality affects agent behavior. * Strong security instincts: you know the difference between authentication and authorization, and you think about credential exposure before writing the first line. Preferred: * Experience building integrations with Microsoft Bot Framework or Slack Bolt SDK. * Familiarity with enterprise SaaS platforms (Workday, SAP Fieldglass, ServiceNow, or similar VMS/HCM systems). * Experience with the approval outbox pattern or event-driven architectures using SNS/SQS. * Exposure to Redis caching and ElasticSearch in a production context. * Background in workforce management, procurement, or enterprise HR technology. Tech Stack * MCP: Model Context Protocol (Anthropic spec) * Runtime: Node.js / TypeScript (MCP server layer) * Cloud: AWS (Lambda, API Gateway, VPC, Secrets Manager, CloudWatch, SNS/SQS, Direct Connect) * Backend: Java / Spring Boot / PostgreSQL (on-prem VMS - you integrate with it, not build it) * Auth: OAuth 2.0, API Key * Observability: Amazon CloudWatch * Channels: Microsoft Teams (Bot Framework), Slack (Bolt SDK) ## Description * Design and implement the Client Pulse MCP server exposing tools for approvals, billing, and workforce events, mapped to our existing REST API (/v1/approvals, /v1/billings, /v1/events). * Define tool schemas, descriptions, and input/output contracts that are precise enough for LLMs to invoke correctly without hallucination. * Implement the auth layer: API Key injection, OAuth 2.0 client credentials flow, and per-tenant credential isolation using AWS Secrets Manager. * Build the confirmation and safety guardrail layer for write tools to prevent unsafe AI-triggered mutations. * Implement response normalization so complex, paginated API payloads are reshaped into LLM-friendly summaries without exceeding context window limits. * Design and own the tool versioning strategy so breaking API changes never break deployed agents. * Integrate MCP server logging with Amazon CloudWatch and ensure every tool invocation produces a durable, queryable audit trail. Implement circuit breaker and retry logic for the VMS call path (API Gateway Lambda AWS Direct Connect * on-prem VMS). * Collaborate with InfoSec to ensure the MCP server meets enterprise security requirements including WAF compliance, private VPC deployment, and PEN test remediations. * Participate in architecture reviews and contribute to the evolution of the Client Pulse API Platform., * You own the layer. MCP architecture is finalized. You are not joining a committee - you are shipping the server. * Real enterprise scale. Client manages billions in workforce spend. The tools you build will be used by managers at Fortune 500 companies to approve real workforce actions. * Early in a fast-moving space. MCP is months old as a production standard. You will be defining best practices, not following them. * Strong technical foundation. The API Platform, auth model, observability stack, and security architecture are already production-grade. You are adding a layer on top of something that works. ## Related Videos - [API, MCP or MCP App? Choosing the right surface for AI agents](https://www.wearedevelopers.com/videos/100305-api-mcp-or-mcp-app-choosing-the-right-surface-for-ai-agents) - [Reducing LLM Calls with Vector Search Patterns - Raphael De Lio (Redis)](https://www.wearedevelopers.com/videos/1714-reducing-llm-calls-with-vector-search-patterns-raphael-de-lio-redis) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [For the REST of us: API First and Conway’s Law](https://www.wearedevelopers.com/videos/1932-for-the-rest-of-us-api-first-and-conway-s-law) - [Are Your APIs Ready for AI Agents](https://www.wearedevelopers.com/videos/2004-are-your-apis-ready-for-ai-agents) - [Accelerating Authentication Architecture: Taking Passwordless to the Next Level](https://www.wearedevelopers.com/videos/733-accelerating-authentication-architecture-taking-passwordless-to-the-next-level) ## Related Articles - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)