Hey, I'm Pete

I'm a passionate and vibrant yoga instructor. Breaking free from convention, I took a leap of faith and opened my own yoga studio, where I share my profound love for mindfulness and holistic well-being. I also extend my reach through my journal of thoughts, yoga practices, and how to make the world a better place.

Subscribe

Build Your Career With Us
Join a team where your ideas, talent and ambition can make a real difference.

Be part of a growing team, work on exciting projects and build a career with opportunities to learn, grow and succeed.

Senior Full Stack Software Engineer

Role description and candidate brief

Location UK-based, remote-first. Brighton or commutable preferred -- see How we work together
Type Permanent, full-time
Salary £60,000
Holiday 31 days including bank holidays
Reports to Chief Technology Officer
Checks Right to work in the UK, criminal record self-declaration, online screening, and post-offer pre-employment checks (including an Official Enhanced DBS with Barred List Check) -- see Why UK-only.

About us

Gaia Learning runs Bloom, a live online education platform for young people with SEND and EHCPs. It's used by teachers, learners and school administrators, with guardian access coming.

Lessons are taught live in the browser -- video, a shared whiteboard, resources, attendance and an end-of-lesson review -- backed by learner profiles, objectives, safeguarding records and AI-assisted summarisation of documents and lesson outcomes.

We're past MVP and into production, working with schools and local authorities, iterating in sprints. The platform is small, modern and unusually well documented for its age. It now needs a senior engineer alongside the CTO to own it properly.

The role in one line

You'll be the senior engineer on a production platform -- writing most of the code across the frontend, the API and the cloud infrastructure that runs them, and owning the quality bar for a product holding children's special category data.

This is a hands-on, high-ownership role, not a management one. You'd take primary day-to-day ownership of the codebase and pipeline, and set the standards the rest of the work is held to.

If you want to be the person who knows the whole system end to end and is trusted to make architectural calls, this is that job. If you want a narrow ticket queue inside a large team, it isn't.

What you'll own

The product code. Full-stack feature work across a React and TypeScript single-page app and a PHP API. Most features touch both sides, so you'd design the API and build the interface that consumes it.

The infrastructure. Our cloud environments and the infrastructure-as-code that provisions them, with the security and data-residency controls a platform holding children's data requires.

The pipeline. Test-gated builds and deployments, and the alerting around them.

The quality bar. Testing, type safety, accessibility and security standards across the codebase. You'd set them, raise them where they need raising, and hold the rest of the work to them.

The stack

React and TypeScript on the front end, PHP on the back, MySQL, all running on Google Cloud in a UK region and managed as infrastructure-as-code. There's real-time collaboration and AI-assisted summarisation in the product.

You won't be expert in all of it on day one -- nobody is. We care that you can become expert in the parts you aren't, and we'll go through the architecture in detail at the technical stage.

How we build: agentic coding

We build with Claude Code, and this role requires you to be genuinely on board with that. Our repository is set up for it -- guardrails, written architecture rules, an explicit definition of done -- and a meaningful share of our output comes through agentic workflows. It's not a side experiment; it's how a team this size ships at the pace we do.

We're not looking for someone who'll tolerate it. We're looking for someone with their own workflow, real opinions about where these tools help and where they don't, and the discipline to review AI-written code as rigorously as a colleague's -- more so, because the failure modes are easier to miss.

We're looking for someone who has

Essential

  • Substantial experience building and running production web applications, with real depth on both sides -- not a frontend engineer who has seen an API, or a backend engineer who can force a React component into existence
  • Strong TypeScript and React: component architecture, state, forms, performance, and the discipline to keep a feature-based codebase from decaying into a shared-folder swamp
  • Strong server-side experience in PHP
  • Relational data modelling: design a schema, write a safe migration against live data, reason about a query under load
  • Cloud infrastructure ownership and infrastructure-as-code. Comfortable being called when production is unhappy, and comfortable saying the fix is in Terraform rather than clicking around a console
  • Security as a habit rather than a phase -- every endpoint authenticated and authorised, input validated server-side, secrets out of the client, least privilege by default
  • Fluent, considered use of agentic coding tools -- Claude Code specifically, or clearly transferable experience
  • Clear written communication. You'll work with a small non-engineering team, external suppliers, and schools

Desirable

  • WebRTC or real-time collaboration
  • Accessibility remediation or formal audit experience
  • UK GDPR in practice -- special category data, DPIAs, data residency, retention
  • LLM integration beyond a demo: evaluation, injection defence, cost and latency, and a clear head about what these systems shouldn't be trusted with
  • EdTech, SEND, safeguarding, or another regulated domain

Not required

A degree, a particular set of prior employers, or a specific number of years. Show us you can build the thing well.

How we work

Small team, low ceremony, high standards. Sprints, a ClickUp backlog, PRs reviewed before merge, and a written Definition of Done: typecheck and build clean, backend tests green, style clean, authorisation covered, manual keyboard and accessibility pass on any changed UI.

Architecture rules are written down and enforced. You're welcome to argue with any of them, in writing, and change them. Documentation is part of the change, not a follow-up ticket.

How we work together

Remote-first, UK-based. We'd like you within reach of Brighton, where you'd co-work with the CTO one or two days a week. Early-stage architecture benefits enormously from a whiteboard and a coffee, and this is the stage where that pays off most. If you're commutable rather than local, let's talk.

Compliance, security and accessibility

Bloom is built for schools and local authorities, so we're assessed before we're bought. Compliance isn't a separate function here -- it lands in the codebase and the infrastructure, and it would be part of this role.

We handle special category data about children under UK GDPR. Data residency, encryption, access control and auditability are enforced by policy rather than convention, and DPIAs, retention and lawful basis are live engineering constraints rather than paperwork. Our security work is shaped by ISO 27001 and Cyber Essentials.

Accessibility matters here more than in most places -- our learners are the reason WCAG exists. An accessibility pass is part of our definition of done, and holding the platform to WCAG 2.2 AA is part of this role.

None of this is box-ticking. It's the reason schools let us near their learners.

Why UK-only, and the background check

Bloom holds special category data about children with SEND -- EHCPs, health information, safeguarding records. Everything is UK-hosted and pinned there by policy, and production access is tightly scoped.

This role involves production access, so it carries strict UK residency and right to work in the UK.

  • Shortlisting and Pre-Interview Screening: Shortlisted candidates will be asked to complete a criminal record self-declaration and undergo online background and social media screening in line with KCSIE statutory guidance prior to interview.
  • Conditional Post-Offer Vetting: Formal offers of employment are subject to the satisfactory completion of post-offer pre-employment checks, including:
    • Inspection of an Official Enhanced DBS with Barred List Check (original paper certificate)
    • Overseas Criminal Record Checks / Certificates of Good Conduct for candidates who have lived or worked outside the UK for 6 months or more (continuously or in total) within the last 10 years
    • Medical Fitness Verification for the post
    • Verification of essential qualifications and two satisfactory professional references

If any of these fundamental eligibility or safeguarding checks are a blocker for you, we'd rather know now than at offer stage.

It also sets the honest framing for the job: the consequence of sloppy work here isn't a bad sprint. We want someone who finds that motivating rather than intimidating.

Process

  1. Intro call -- 30 minutes, with the CTO.
  2. Interview 1: Technical conversation -- 60 to 90 minutes. A walk through the real architecture, the decisions we've actually made, and what you'd have done differently. A look at some code of your own choosing, or a system you've built if your work is all proprietary.
  3. Interview 2: Non-tech / Cultural conversation -- 30--60 mins. Meet with the CTO + another member of the team to discuss life at Gaia Learning, Bloom and the wider team.
  4. Final conversation -- terms, offer.

We'll come back to everyone who applies.

To apply

Email Zaq Mughal (CTO): zaq@gaialearning.co.uk

Tell us one thing alongside your CV: how you actually use agentic coding tools day to day. Not the theory -- your workflow, and where you've found the limits.

Gaia Learning is committed to building a team that reflects the communities Bloom serves. We welcome applications from everyone, and we're happy to make adjustments at any stage of the process -- just ask.