Senior Software Engineer
About the role
- About the project
Ultraly is developing a standalone service for submitting regulatory transaction reports to FINTRAC, Canada's financial intelligence unit.
The microservice will receive transaction and party/customer data through a versioned API, validate and normalize that data, transform it into FINTRAC's required JSON structures, submit authorized reports through FINTRAC's Report Ingest API, and return normalized and raw acknowledgements to the calling platform.
The service must be independently deployable and capable of being integrated into our main platform later through APIs and events. It will handle sensitive financial and identity data, so security, auditability, idempotency, and operational reliability are core product requirements.
We have prepared a detailed technical requirements and acceptance document based on FINTRAC's current API documentation, JSON schemas, validation rules, portal guides, Postman examples, and sample reports. Qualified candidates will receive this document before preparing a final estimate.
- What you will be responsible for
- Review the supplied FINTRAC documentation and validate the proposed architecture and scope.
- Design a stable canonical input model for transactions, people, entities, accounts, locations, and report context.
- Design and document the public REST API.
- Build versioned transformation adapters for the FINTRAC report types included in the contract.
- Validate generated reports against the current FINTRAC JSON schemas and agreed business-rule coverage.
- Return clear field-level errors, warnings, remediation guidance, and auditable proposed corrections.
- Implement FINTRAC authentication and single-report create, change, and delete workflows.
- Implement idempotency, durable job processing, retry classification, and reconciliation so ambiguous network failures do not create duplicate regulatory filings.
- Implement asynchronous bulk submission and result polling if bulk is included in the agreed release.
- Preserve FINTRAC acknowledgements, validation results, report identifiers, amendments, and audit history securely.
- Ensure sensitive report and customer data never appears in application logs.
- Provide automated unit, contract, mapping, integration, resilience, security, and tenant-isolation tests.
- Prove each contracted report type in FINTRAC's external-test environment using fictitious data.
- Deliver deployment, monitoring, incident, backup/restore, reconciliation, and secret-rotation documentation.
- Complete a technical handover to our engineering team.
- Required experience
- Senior-level backend engineering experience delivering production APIs.
- Strong REST and OpenAPI design skills.
- Experience with complex JSON data models and JSON Schema validation.
- Experience integrating with OAuth/token-based external APIs.
- Strong knowledge of idempotency, durable jobs, retries, reconciliation, and distributed-system failure modes.
- Experience with PostgreSQL or an equivalent transactional database.
- Experience packaging and operating services with Docker.
- Experience protecting sensitive financial, identity, or otherwise regulated data.
- Strong automated testing and documentation practices.
- Ability to turn regulatory or third-party specifications into testable technical requirements.
- Clear written and spoken English.
- Preferred experience
- Java 21 and Spring Boot 3 experience, which aligns with our current platform.
- Bulk file submission, presigned upload URLs, asynchronous polling, and partial-batch result handling.
- Audit/event models, threat modeling, secrets management, observability, and cloud deployment.
- Experience working with compliance officers or legal/domain specialists without treating software as a replacement for their decisions.
- Direct FINTRAC Report Ingest API or FINTRAC Web Reporting experience.
- Canadian AML/ATF, PCMLTFA, regulatory reporting, banking, payments, money-services, or casino reporting experience.
Direct FINTRAC experience is valuable but not mandatory if the candidate has strong regulated-integration experience and can demonstrate careful use of authoritative schemas and rules.
- Expected deliverables
- Production-ready source code and reproducible build.
- Dockerized standalone service and local FINTRAC simulator/stub.
- PostgreSQL schema and migrations.
- OpenAPI specification and client integration guide.
- Canonical data dictionary and per-report field mapping matrices.
- Versioned FINTRAC schema/rule registry and update process.
- Complete automated test suite and fictitious test fixtures.
- FINTRAC external-test evidence for each contracted report type and operation.
- Security threat model, scan results, and software bill of materials.
- Operational dashboards, alerts, and runbooks.
- Architecture decisions, known limitations, and engineering handover.
- Definition of success
The project is not complete merely because an HTTP request reaches FINTRAC. Completion requires:
- correct mapping for every supported report type;
- actionable handling of local and FINTRAC warnings/rejects;
- external-test acceptance evidence;
- no duplicate filings under request replay or ambiguous failures;
- secure handling of identity and financial data;
- durable audit and submission history;
- successful amendment and controlled-deletion workflows;
- agreed performance and recovery tests; and
- complete deployment and support documentation.
The detailed acceptance matrix is included in the technical requirements attachment.
- Engagement model
- Contract engagement.
- Milestone-based delivery.
About Ultraly
We help businesses verify individuals and companies with integrated KYC, KYB, and KYE solutions.
Similar Jobs
Senior Software Engineer
About the role
- About the project
Ultraly is developing a standalone service for submitting regulatory transaction reports to FINTRAC, Canada's financial intelligence unit.
The microservice will receive transaction and party/customer data through a versioned API, validate and normalize that data, transform it into FINTRAC's required JSON structures, submit authorized reports through FINTRAC's Report Ingest API, and return normalized and raw acknowledgements to the calling platform.
The service must be independently deployable and capable of being integrated into our main platform later through APIs and events. It will handle sensitive financial and identity data, so security, auditability, idempotency, and operational reliability are core product requirements.
We have prepared a detailed technical requirements and acceptance document based on FINTRAC's current API documentation, JSON schemas, validation rules, portal guides, Postman examples, and sample reports. Qualified candidates will receive this document before preparing a final estimate.
- What you will be responsible for
- Review the supplied FINTRAC documentation and validate the proposed architecture and scope.
- Design a stable canonical input model for transactions, people, entities, accounts, locations, and report context.
- Design and document the public REST API.
- Build versioned transformation adapters for the FINTRAC report types included in the contract.
- Validate generated reports against the current FINTRAC JSON schemas and agreed business-rule coverage.
- Return clear field-level errors, warnings, remediation guidance, and auditable proposed corrections.
- Implement FINTRAC authentication and single-report create, change, and delete workflows.
- Implement idempotency, durable job processing, retry classification, and reconciliation so ambiguous network failures do not create duplicate regulatory filings.
- Implement asynchronous bulk submission and result polling if bulk is included in the agreed release.
- Preserve FINTRAC acknowledgements, validation results, report identifiers, amendments, and audit history securely.
- Ensure sensitive report and customer data never appears in application logs.
- Provide automated unit, contract, mapping, integration, resilience, security, and tenant-isolation tests.
- Prove each contracted report type in FINTRAC's external-test environment using fictitious data.
- Deliver deployment, monitoring, incident, backup/restore, reconciliation, and secret-rotation documentation.
- Complete a technical handover to our engineering team.
- Required experience
- Senior-level backend engineering experience delivering production APIs.
- Strong REST and OpenAPI design skills.
- Experience with complex JSON data models and JSON Schema validation.
- Experience integrating with OAuth/token-based external APIs.
- Strong knowledge of idempotency, durable jobs, retries, reconciliation, and distributed-system failure modes.
- Experience with PostgreSQL or an equivalent transactional database.
- Experience packaging and operating services with Docker.
- Experience protecting sensitive financial, identity, or otherwise regulated data.
- Strong automated testing and documentation practices.
- Ability to turn regulatory or third-party specifications into testable technical requirements.
- Clear written and spoken English.
- Preferred experience
- Java 21 and Spring Boot 3 experience, which aligns with our current platform.
- Bulk file submission, presigned upload URLs, asynchronous polling, and partial-batch result handling.
- Audit/event models, threat modeling, secrets management, observability, and cloud deployment.
- Experience working with compliance officers or legal/domain specialists without treating software as a replacement for their decisions.
- Direct FINTRAC Report Ingest API or FINTRAC Web Reporting experience.
- Canadian AML/ATF, PCMLTFA, regulatory reporting, banking, payments, money-services, or casino reporting experience.
Direct FINTRAC experience is valuable but not mandatory if the candidate has strong regulated-integration experience and can demonstrate careful use of authoritative schemas and rules.
- Expected deliverables
- Production-ready source code and reproducible build.
- Dockerized standalone service and local FINTRAC simulator/stub.
- PostgreSQL schema and migrations.
- OpenAPI specification and client integration guide.
- Canonical data dictionary and per-report field mapping matrices.
- Versioned FINTRAC schema/rule registry and update process.
- Complete automated test suite and fictitious test fixtures.
- FINTRAC external-test evidence for each contracted report type and operation.
- Security threat model, scan results, and software bill of materials.
- Operational dashboards, alerts, and runbooks.
- Architecture decisions, known limitations, and engineering handover.
- Definition of success
The project is not complete merely because an HTTP request reaches FINTRAC. Completion requires:
- correct mapping for every supported report type;
- actionable handling of local and FINTRAC warnings/rejects;
- external-test acceptance evidence;
- no duplicate filings under request replay or ambiguous failures;
- secure handling of identity and financial data;
- durable audit and submission history;
- successful amendment and controlled-deletion workflows;
- agreed performance and recovery tests; and
- complete deployment and support documentation.
The detailed acceptance matrix is included in the technical requirements attachment.
- Engagement model
- Contract engagement.
- Milestone-based delivery.
About Ultraly
We help businesses verify individuals and companies with integrated KYC, KYB, and KYE solutions.