Skip to content
Currently available — for the right work·France903+ Day French Streak·2026 Q2 calendar — open now
Legora — all roles
Application · Forward Deployed Engineer · London

Infrastructure that outlasts the visit.

Nine years writing production code inside client environments — the integration, the connector, the pipeline that keeps running after the engagement ends. Legal is a new domain; embedding with a client's stack under pressure is not.

Delivered into
LondonZurichOsloDubaiFloridaMontrealLaval

Deployment isn't a handoff. It's where the code gets written.

A legal team's stack doesn't bend to a vendor's demo environment. It bends to whoever is embedded enough to write the connector, debug the sync under pressure, and leave something that keeps running after the engagement ends. That is what a forward deployed engineer is actually for, and it is what has been happening since 2017 — most recently on a platform whose users, like lawyers, bill their time and had spent years reading documents by hand.

Hire me for the embedded engineering record and the reusable connector already built, and ramp me on SAML and the specific DMS connectors in the first month. The role's core — embedding with enterprise customers, writing production code against their stack, owning technical scoping end to end, and building tooling that outlasts the visit — is what nine years at has actually been: Frontgo's delivery pod, 's clinical platform, a four-year Canada engagement across three named clients. The reusable-connector ask is already answered: , on the backbone, is an Auth0-based SSO and RBAC identity layer built once from recurring client friction and reused by every platform since.

The integration surface

What this role touches on day one, and how much of it is already built rather than configured. One chip is the honest ramp.

, on the backbone, is the identity layer underneath — built once, consumed by every client platform since.

Every line from the posting

Every line from the posting, answered with a named engagement rather than an adjective. Where the answer is a ramp, it says so and gives the timeline.

01
Embed with enterprise customers during and after deployment, writing production-grade code to bridge Legora's platform with their existing legal tech stack

Frontgo is the clearest embed: ran the engineering side of a three-person delivery pod inside the client's own roadmap, shipping Vipps and financing integrations rather than working adjacent to the team. and the four-year , SkyTracks and SoftCollab engagement carried the same embedded, code-writing role well past the initial deployment.

Strong
02
Own the full technical scoping process: gather requirements, design integration architecture, and deliver working solutions end-to-end

Nine years of exactly this at — enterprise implementations for customers in London, Zurich, Oslo, Dubai, Florida, Montreal and Laval, scoped from the first requirements conversation through integration architecture to a working, delivered solution. Vimalgo's AI document platform was scoped, designed and shipped end-to-end, live in production since January 2025.

Strong
03
Build and maintain reusable connectors, automation scripts, and tooling that accelerate future customer deployments

is this exact pattern: recurring client-side authorization friction across engagements became one reusable Auth0-based SSO and RBAC backbone, built once and consumed by every client platform since, rather than a bespoke fix rebuilt per client. 's Claude-powered edit-to-deploy pipeline and 's ingestion and ETL tooling are the same instinct applied to content operations and data respectively.

Strong
04
Debug and resolve complex production issues at the intersection of customer environments and Legora's platform — often under time pressure

is a live clinical platform where a broken sync is a regulatory event, not a bug ticket — patient data, EHR interoperability and audit logging kept running across 64 doctors and 7 centers under that pressure. The , SkyTracks and SoftCollab engagement held real-time collaborative state synchronised over a custom WebSocket transport for four years, where a desync is visible to every user in the session.

Strong
05
Act as the technical voice of the customer internally — surface friction points, edge cases, and integration gaps directly to our product and engineering teams

exists because this loop was run repeatedly: recurring client-side authorization friction fed back until it became a reusable identity backbone rather than the same fix rebuilt per client. 's product direction came the same way, from friction observed on the clinic floor and carried back into what got built next.

Strong
06
Partner with Sales and Customer Success to scope new deals and expand existing accounts where technical complexity is a deciding factor

The Vimalgo engagement opened on a technical scoping conversation, not a sales deck — the working demo, built and led personally against the client's own material, is what converted a cautious three-person firm into an early commitment. At this was structural: carrying the technical relationship from the commercial conversation through delivery, including custom-branded proofs of concept and security-review mitigation paths sales needed to close.

Strong
07
Work closely with Engineering and Product to deliver successful integrations and improve general product offering

At a 22-person product engineering venture firm (52+ FT and contract), this was the daily operating mode rather than an occasional handoff — technical delivery, product direction and engineering execution sat under one accountable line, with as the clearest example of a delivery-driven friction becoming a shipped product capability.

Strong
08
A strong generalist engineer comfortable writing backend code and working across APIs, auth protocols, and data pipelines

Backend engineering through Principal Staff level: Auth0-based SSO with a layered proprietary RBAC model, REST and event-driven APIs (EventBridge, SQS/SNS, Lambda) with idempotent write paths, and data pipelines spanning 's PostgreSQL ingestion and ETL and 's patient-data pipeline and EHR interoperability.

Strong
09
Experienced in customer-facing technical roles — pre-sales engineering, solutions engineering, or embedded delivery — where you've had to own outcomes, not just hand off specs

Vimalgo for pre-sales — the demo that won the commitment was mine to build and present. Frontgo for embedded delivery — engineering practices, integration advice and hiring for a client pod, ending in a clean handover rather than a spec thrown over a wall. Nine years, co-founder through CIO, with the customer-facing technical role constant throughout.

Strong
10
Familiar with enterprise integration patterns: SSO (SAML, OIDC), REST and webhook-based APIs, and document management systems like iManage, SharePoint, or NetDocuments

Auth0-based SSO with org- and instance-level RBAC under a layered proprietary permission model is real, built infrastructure — , on the backbone, runs it in production with multi-tenant per-organisation isolation. REST and webhook-based APIs are the same surface used across every engagement, plus Microsoft 365 and SharePoint through the Azure API work already in the stack.

Ramp · SAML specifically, and iManage or NetDocuments, are the honest gap — none of the three connected. What transfers is the Auth0 protocol experience and the integration shape underneath any of them: auth handshake, permission mapping onto an existing directory structure, sync semantics, and half-failure recovery. Two to three weeks with sandbox credentials to be useful unsupervised; the first live integration is where it actually sets.

Ramping
11
Able to move fast without cutting corners — you know when to build something robust and when to ship something good enough to unblock a customer

Frontgo needed the robust version — engineering practices set for a client pod headed toward a clean handover. needed the other end of that judgment: rather than train a 25-year-old export house on Git or a heavyweight CMS, a Claude layer that turns a plain-English edit into a pull request was good enough to unblock them immediately, with every change still reviewable and revertible in Git.

Strong
12
A clear communicator who can hold a technical conversation with an IT administrator and a strategic one with a managing partner — sometimes in the same meeting

The Vimalgo demo carried both registers at once: a working AI matching flow a non-technical firm could try against their own material, backed by the architecture underneath it. Same pattern at , translating clinical constraints into product decisions with doctors in the room, and structurally at , carrying the technical relationship from the commercial conversation through to delivery.

Strong
13
Comfortable with ambiguity and energised by early-stage problems that don't have a playbook yet

Five verticals shipped 0→1 with no existing playbook: health-tech, payments, recruitment, music-tech, esports and hospitality. is the sharpest solo case — built fully alone, an ingestion, ETL and analysis platform that gave a fragmented esports community one canonical dataset where there had only been scattered, contradictory records, plus the first nationwide league run end to end through the platform.

Strong
Embedded delivery record

Seven embeds, seven different stacks to bridge.

The JD asks for someone embedded with complex enterprise clients, writing real code against their existing stack. This is that record — real integration surfaces, real production code, real end states. Every row links to its full case study.

Open any row for its outcome

Seven embeds, seven different stacks, seven different production environments. The code stayed after the visit ended.

The engagement ends. The infrastructure doesn't.

Anygum — built once, from recurring client friction, reused by every platform since.

What arrives already built

Four things this role needs that don’t need a ramp.

The reusable connector, already built

, on the backbone: Auth0-based SSO with org- and instance-level RBAC under a layered proprietary permission model, built once from recurring client-side authorization friction and reused by every client platform since — not a bespoke fix rebuilt per engagement. One organisation runs isolated instances of the same application without separate auth silos, which is the part most SSO rollouts actually fail on.

Fragmented sources into one canonical corpus, built solo

: an ingestion, ETL and analysis platform built fully alone that took a fragmented esports community's scattered, contradictory records and gave it one canonical, queryable dataset — 1,207 players and 47,091 matches — plus the first nationwide league run end to end through the platform, registration through local payments. The reusable-tooling instinct the JD asks for, applied solo at national scale.

A professional-services AI rollout, scoped and shipped solo

Vimalgo, for a Swiss professional-services firm in Möhlin: the pre-sales technical scoping, the build, and the demo that converted a cautious client into an early commitment were all mine. Launched January 2025, in production. Recruiters and lawyers share the relevant shape — billable time, high document volume, no tolerance for a confident wrong answer.

Production debugging where downtime is a regulatory event

runs as a live clinical platform — patient-data pipeline, EHR interoperability, HIPAA-compliant document management with time-stamped audit logging — scaled to 64 doctors, 3,242 patients and 7 centers, where a broken sync is not a warning log. The , SkyTracks and SoftCollab engagement held real-time collaborative state synchronised over a custom WebSocket transport for four years, visible to every user the moment it breaks.

The connector-building instinct, at national scale

DotaBD — solo-built ingestion, ETL and analysis platform for Bangladesh's Dota 2 esports scene

Many fragmented sources in. One canonical, queryable corpus out.
DotaBD — Bangladesh's national Dota 2 esports platform, built solo
IngestPull scattered, contradictory community records from multiple upstream sources.
ResolveETL and matching logic collapse duplicates into one canonical player identity.
ServeSearchable profiles and full match history, queryable for the first time.
OperateRun the first nationwide league end to end: registration, approvals, local payments.
Sustain1,207 players and 47,091 matches, live and solo-maintained.

A national esports community had years of match history scattered across incompatible, contradictory sources, with no single canonical record of who actually played whom. Rather than write a one-off script per source, the ingestion and ETL pipeline was built as reusable infrastructure — the same instinct this role asks for in a legal-tech context, applied here to a live community platform, solo, end to end.

  • Ingestion pipeline pulls from multiple upstream sources into one PostgreSQL warehouse.
  • ETL and analysis layer resolves duplicate and conflicting player records into one canonical profile.
  • Searchable player profiles surface a full match history that didn't exist as a single source before.
  • Multi-organisation registration with approvals and local payments ran the first nationwide league end to end.
  • 1,207 players and 47,091 matches, live and solo-maintained — built once, still running.

What arrives with me that the JD didn't ask for.

Legora says mission before ego, everyone contributes, no one coasts. Four things I'd bring that aren't on the requirement list.

Build capacity

Ships the connector, not a spec for someone else to build

Nine years as a hands-on engineer through Principal Staff level means when an embed needs a migration script, a permission-diff tool or a connector shim, it gets written on the spot. is a live, solo build at wiregent.com — the ledger and settlement layer for agentic due diligence. A forward deployed engineer who ships reduces the tax on your engineering team.

AI-native practice

Agentic delivery, run daily rather than described

Repeating integration workflows become reusable agent skills with explicit triggers; hooks and scoped tool permissions give deterministic control where prompts alone burn budget. Claude-led, Gemini second. For a company selling AI-native workflows, the engineer embedded with the client should be living in them.

Coaching

People leave my teams into better roles

Two alumni now lead teams in Norway, plus alumni now leading at two local Bangladeshi tech firms. Seven years managing while staying hands-on — useful once Legora's embedded engineering function grows past one person per account.

Consistency

900+ consecutive days, no misses

A daily French practice streak with grammar explainers published publicly. It's a small thing that predicts a large one: follow-through after the interesting part is over — the exact quality that matters once the integration is live and everyone else has moved on to the next customer.

The questions worth asking

The questions a hiring manager should actually ask about this application, answered directly.

You've never built SAML SSO or touched iManage, SharePoint's DMS layer, or NetDocuments — the JD names all three. Why should we trust you embedded in a client's integration stack?
You shouldn't trust me on those three specifically on day one — you should trust me on the shape underneath them. Every enterprise integration is the same four problems: the auth handshake, how the customer's existing permission structure maps onto ours, the sync semantics, and what happens when a sync half-fails under pressure. I've built Auth0-based SSO with a layered proprietary RBAC model from scratch, and shipped document permissioning and audit logging under HIPAA at , where a wrong permission is a regulatory event. Give me sandbox credentials and a real customer environment and I'm useful in two to three weeks; the first live integration is where it actually sets. What I wouldn't do is claim the SAML or DMS experience I don't have and let you find out mid-deployment.
You've been a co-founder and a CIO. Will writing code embedded inside someone else's stack actually hold your interest?
I stepped out of 's operating role in August 2026 after nine years, deliberately not looking for another executive seat. The part of that job I want more of is exactly what this role is made of: sitting inside a customer's environment, writing the connector, debugging the thing that's actually broken. Frontgo is the proof — I ran the engineering side of a delivery pod inside the client's own roadmap, shipping code rather than managing a plan for someone else to ship. The part I want less of is running a firm's hiring, P&L and org design. This isn't a step down, it's a step back toward the keyboard.
You have no legal-industry background. Your customers here are Cleary Gottlieb, Linklaters and White & Case.
True, and I wouldn't pretend otherwise — legal vocabulary and how a matter actually moves through a firm is a real first-weeks learning curve. What I'd push back on is that the domain is the hard part of this role. Five verticals shipped 0→1 taught me the discipline transfers and the domain gets learned fast when you're embedded in it daily. The nearest real transfer is regulated professional services: under HIPAA and Bangladesh Digital Health standards, and Vimalgo for a Swiss staffing firm where the users bill their time and had spent years reading documents by hand. The instinct that matters in legal — never assert a confident answer over a thin one — is built into , where the verdict cites its evidence and names what it couldn't score.
This role is based out of Stockholm HQ or London, on-site. You're not in either. How does that actually work?
London is the one I'm applying against, and it's on-site by preference, not a concession. It's already a delivery geography for me through multi-year client engagements, and my sister lives there, so the base is real rather than a relocation I'd be talking myself into. On the mechanics: the UK Global Talent route is the intended path regardless of this role and progresses independently of any single hire, with Skilled Worker sponsorship equally workable, whichever is cleaner on your side. Remote-first since 2020 across EU, UK and North American time zones means the coordination habits already transfer; I'd rather be physically embedded with the customer and the engineering team than optimise for flexibility this role doesn't need.
The JD wants someone energised by problems that don't have a playbook yet. What happens when there genuinely isn't one?
is the honest answer: no existing platform, no prior playbook, built solo from an ingestion pipeline through the first nationwide league run end to end — registration, approvals, local payments, sponsors. When there's no playbook the actual skill is deciding what to build robustly and what to ship good enough to unblock the next step, which is the same judgment needed when a heavyweight CMS was the wrong answer for a 25-year-old export house. I'd rather ship the imperfect version and learn from a real customer than wait for a spec that isn't coming.
You've mostly worked inside your own company. Can you operate embedded inside someone else's process, on someone else's timeline?
Frontgo is the cleanest evidence, and it's deliberately the opposite arrangement: the client's own project manager owned the roadmap and priorities, and I ran the engineering side underneath that — practices, integration advice, hiring for the pod, shipping to their cadence. It ended with a documented handover to their in-house team rather than me retaining anything. Vimalgo was the same pattern — the Swiss client set the direction after the demo landed. Nine years working inside other organisations' constraints, security reviews and procurement processes; was the vehicle, not the audience.

The stack behind the record

The stack behind the embedded delivery record — weighted to what this role touches.

Backend & integration engineering

  • Production backend code across the stack
  • Reusable connector & tooling design
  • Data pipelines & ETL (PostgreSQL)
  • Production debugging under time pressure
  • Embedded delivery inside client environments
  • Idempotent, retry-safe write paths

Enterprise identity & SSO

  • Auth0-based SSO (Cloudsight / Anygum)
  • Org- and instance-level RBAC
  • Layered proprietary permission model
  • Multi-tenant per-organisation isolation
  • Permission mapping onto customer directory structure
  • SAML — the honest ramp

Integrations & APIs

  • REST API integrations & webhooks
  • Event-driven architecture (EventBridge · SQS/SNS · Lambda)
  • Microsoft 365 & Azure APIs
  • Third-party payment/identity connections (Stripe, Vipps)
  • iManage & NetDocuments — the ramp
  • Custom WebSocket real-time sync

Security, compliance & trust

  • GDPR · HIPAA · WCAG 2 across 5 client orgs
  • HIPAA-compliant document management
  • Time-stamped audit logging
  • Security-review mitigation paths for procurement
  • Compliance decided at the schema

Customer-facing technical work

  • Pre-sales solution demos that opened engagements
  • Technical scoping: requirements → architecture → delivery
  • Dedicated technical point of contact
  • Requirements discovery & gap resolution
  • Confidential enterprise engagements

AI-native delivery

  • Document ingestion → structured extraction
  • AI parsing + ranked matching on an auditable human pipeline
  • Grounding evals as release gates
  • RAG & vector retrieval
  • Claude Code (Anthropic SDK) primary · Gemini second
  • Reusable agent skills, hooks & scoped tool permissions
Forward Deployed Engineer · London

Let's talk about the first embed.

London is on-site by preference, not concession. It's already a delivery geography through multi-year client engagements, and my sister lives there — see the London geography brief. On visas: the UK Global Talent route is the intended path regardless of this role and progresses independently, with Skilled Worker sponsorship equally workable, whichever is cleaner on your side.

Book 30 minutes
FAUZUL
Application fit page for Legora · Forward Deployed Engineer · London, United Kingdom (on-site)