All open roles Open role

CTO (m/f/d)

You get a codebase that works — and the mandate to make it hold. Including the decision about where it moves.

  • Location Remote — based in Wiesbaden
  • Hours 40 h/week — 20 h for students
  • Contract 12 months fixed term, extension intended
  • Start January 2027
Who we are

A very small team with a very specific question

What we build

Joyful helps people notice the feeling behind a habit and turn it into an action of two to five minutes. The app is built and in use: tester rounds, feedback from real usage, moderated usability tests. Not a deck.

What that means technically

We store how people are doing. That is the most sensitive category of data an app can hold, and it shapes every architectural decision — where data lives, how it is reached, how it is deleted, which region. Treating that as a side condition will not work here.

Role details

What this is about

The app is built in Flutter/Dart. Backend and hosting currently sit with managed services — the right choice to get to something usable, and the wrong one for the coming years. Two reasons: our host's pricing model gets considerably steeper past a certain point than our user numbers do, and we do not want data about how people feel sitting somewhere whose operation and access paths we do not fully control ourselves.

This is not a tidy-up we have already planned out and want to hand over. We know what we want to move away from. Where to is your call.

What is on the table

  • Migration onto our own infrastructure. Direction: AWS, serverless (Lambda), infrastructure as code, EU region. You make the actual cut.
  • Replacing the managed backend. Postgres may stay. What should go is the dependency: authentication, access rules and migrations as one vendor's closed island, plus being tied to their roadmap and price list.
  • Keep building the Flutter app. Today mostly a web build; the goal is the app stores, with everything iOS and Android releases bring along.
  • Data protection as an architecture question. Data minimisation, deletion concepts, processor agreements, EU hosting. Here that is not a chapter in an application, it is the default in the code.
  • Security as a standing item. There are external audits and a remaining list that should get shorter. You take it over and decide the order.

How we build — please read this before applying

We vibe-code. A large share of the code is written with AI agents, and that will not change; it is the reason a team this size runs an app this size at all.

So we do not expect you to type every line yourself. We expect you to spot immediately when an agent produces something that only works at first glance: a permission that reaches further than its description. A migration that loses data. An abstraction nobody needs. A "works for me" that only works from cache.

If "the AI writes the code" is a dealbreaker for you, you will be unhappy here. If you conclude from it that review is optional, likewise — and with this data that is the more expensive of the two mistakes.

What you should bring

  • You have not just built software but run it — including the night it was down.
  • Studies at a German university — completed or still ongoing. Not a formality: it is a condition of the EXIST funding that pays for this role.
  • Dart/Flutter — or a credible readiness to pick it up in a few weeks. Coming from Swift, Kotlin or TypeScript that is very doable; tell us why it will work for you.
  • AWS in practice: Lambda, IAM, a database service, infrastructure as code (CDK, Terraform or SAM).
  • Postgres beyond SELECT: indexes, migrations without downtime, backups — and a restore you have actually tested once.
  • Security as craft, not as attitude: permission and role models, secret handling, logging without personal data, a threat model for an app in the health space.
  • You can justify an architectural decision and later reverse it without taking it personally.
  • German or English as a working language. The product interface is German.

Nice, but not required

  • Experience with particularly sensitive data (health, minors)
  • Apps published in the App Store or Play Store
  • CI/CD for Flutter, automated store builds
  • Cloud cost optimisation — demonstrable, not aspirational
  • You have been through an audit or penetration test before
  • You have been the first engineer in a team before

What we offer

  • The engineering half, entirely No tickets from someone else's roadmap. Architecture, operations and security are yours — with the right to say no.
  • Equity, not just pay We are talking about real shares. Amount, vesting and salary we discuss openly in person — for us the two belong together.
  • A clear frame 12 months, financed through the funding. Extending is the stated goal and depends on the next funding phase — we will always tell you where we stand.
  • A migration from day one You rarely get a running product and a free hand on the target architecture. Here both are part of the role.
  • A funding context, not a blind flight EXIST, BMWE and ESF Plus bring structure, a network and a link to academia.
  • Short paths Few people, one decision. What you propose on Monday can be live on Wednesday.
Being honest

Four things you should know beforehand

  • This role hangs on an application. We submit the application for the next EXIST funding phase in September 2026; funding and the start of work are planned for January 2027. You will be named in the application as a team member, so the start depends on the funding decision. If you cannot carry that uncertainty, say so early — that is entirely fine.
  • Twelve months means twelve months. Extending is our goal, but not a promise. In return we promise never to gloss over how the funding stands.
  • You inherit decisions made without you. You will consider some of them wrong. That is precisely why we are hiring — but the first month is taking stock, not a greenfield.
  • The subject demands care. We accompany people in bad moments. Sometimes that means going slower, because a data flow is not defensible. If you only optimise for speed, this is not the right fit.

How to apply

  1. Send us an email. The button below opens your mail client with the right subject line.
  2. No templated cover letter. Three paragraphs are enough: what you have built and run, why this subject interests you, and what you would change about Joyful first.
  3. Instead of a CV, something concrete: a repository, an architecture decision you documented, a postmortem.
  4. Then 30 minutes on video and after that a small, real task from our backlog, around two hours. No unpaid megaproject, no live-coding tribunal. You get an answer within a week — even if it is a no, and then with reasons.

We care what you can do and how you think — not about gender, origin, age, religion, disability or way of life. If you recognise yourself in this role but cannot tick every box: apply anyway, and tell us where you are unsure.

Rather talk first? Book 30 minutes. How we handle application materials and when we delete them is set out in the privacy policy.

Supported through

The "exist – from science to business" programme and its projects are funded by the German Federal Ministry for Economic Affairs and Energy and the European Union via the European Social Fund Plus (ESF Plus).

Funded by:

Federal Ministry for Economic Affairs and Energy
Co-financed by the European Union
exist – from science to business

based on a resolution of the German Bundestag

Funding period EXIST-Women: 01.05.2026–31.12.2026