Overview
Technical skills
Timeline
Roles

Overview

A Solidity-focused dApp engineer at a middle level with practical experience building wallets, token utilities and security demos and a clear strength in implementing on-chain patterns and exploit demonstrations. The strongest proven skill is practical smart contract engineering evidenced by the HotWallet/UserWalletManager/Balance_Checker suite and the Reentrancy attack and solution examples. There is limited evidence of formal testing, CI, frontend integration, or production-grade protocol design and several contracts contain correctness issues that need audit and fixes.
Phone

Technical skills

Languages
8
Java
Python
Node JS
Solidity
TypeScript
JavaScript
Go
SQL
Node JS
4
Nest.JS
Express
Axios
Sequelize
Databases
3
PostgreSQL
Redis
RabbitMQ
DevOps
5
AWS
Rest API
Grafana
Prometheus
CI/CD
Web3
5
Web3.js
Ethers.js
Account Abstraction
OpenZeppelin
Chainlink
Other
21
Spring Boot
Django
Vault
HashiCorp Vault
Sentry
GraphQL
Brownie
Token Standards
MySQL
Amazon S3
Ethereum
Apache Kafka
Amazon EC2
GitHub
Hardhat
Docker
Git
CI/CD
Web3
QA
Smart Contracts

Timeline

York University (York U)
Master's Degree • Information Systems & Technology
2026 Toronto, Ontario
Technical Lead • Lead
Nobitex • Full-Time
Sep 2025 to Jun 2026 9 Months In office
Led backend and blockchain infrastructure architecture for a high-traffic financial platform. Guided engineers through design, implementation planning, reviews, debugging, and production incident response while staying hands-on on critical work. Converted complex product requirements into technical plans and improved engineering practices across the team.
Senior Blockchain Engineer • Senior
Bitazza • Full-Time
Dec 2024 to Mar 2026 1 Year 3 Months Partially remote
Owned architecture and development of backend and blockchain systems for client-facing NFT and crypto products. Built event-driven backend services for asynchronous processing using TypeScript, NestJS, AWS messaging, PostgreSQL, and Ethereum tooling. Designed NFT platform flows and on-chain/off-chain synchronization pipelines to keep state consistent across distributed components.
TypeScript
Nest.JS
PostgreSQL
AWS
Solidity
Ethers.js
Token Standards
Software Engineer • Middle
Nobitex • Full-Time
Feb 2023 to Sep 2025 2 Years 7 Months In office
Designed and developed scalable backend and distributed systems for a financial platform with large user scale. Built an event-driven monitoring platform and implemented resilient data-processing and integration services using REST, RPC, GraphQL, and third-party providers. Improved data workflows and delivered production observability and blockchain infrastructure using monitoring, alerting, deployment automation, and account abstraction features.
Python
Django
TypeScript
Go
PostgreSQL
Redis
RabbitMQ
Solidity
Web3.js
GraphQL
Rest API
Grafana
Prometheus
Sentry
CI/CD
Account Abstraction
Amirkabir University of Technology
Bachelor's Degree • Computer Engineering
2019–2023 Tehran, Iran
Backend & Blockchain Developer • Middle
Farazpardazan • Full-Time
Jan 2021 to Feb 2023 2 Years 1 Month In office
Built backend and blockchain infrastructure for a multi-asset cryptocurrency exchange, including wallet and transaction operations. Implemented secure wallet infrastructure using multi-signature cold wallet approaches with smart contracts and secret management. Developed REST APIs, authentication flows, and scheduled financial processing jobs, and optimized a critical batch pipeline to significantly reduce execution time.
Java
Spring Boot
Node JS
RabbitMQ
PostgreSQL
Solidity
HashiCorp Vault
Rest API
Middle Backend Developer Confidence: Medium API Engineer
Backend developer (Middle) focused on blockchain and on-chain transaction processing with practical integration experience. Proven strength is building and integrating blockchain transaction handlers and wallet flows as evidenced by TRX-and-TRC20-Transaction-Handler (index.js, trxTransaction.js, trc20Transaction.js). Public code shows limited production hardening for security, observability, graceful shutdown, and formal DB migrations.
API Design
3/10
How well APIs are designed
Basic REST API surface implemented with Express and express-async-handler; endpoints exist but lack versioning, idempotency, formal error contract, and authentication.
Evidence
TRX-and-TRC20-Transaction-Handler/index.js: multiple REST endpoints defined (GET/POST/DELETE) using express-async-handler
TRX-and-TRC20-Transaction-Handler/index.js: withdraw endpoints (/withdraw-trx, /withdraw-tokens) that accept requests without idempotency keys or auth checks
Data Layer & Database
3/10
Working with databases
Uses Sequelize ORM for data access with helper functions for CRUD; no visible migration history, transactional boundaries, or explicit handling of concurrent DB updates.
Evidence
TRX-and-TRC20-Transaction-Handler/database.js: addRowToDepositEvent, addRowToColdWalletWithdraw, updateColdWalletWithdraw
TRX-and-TRC20-Transaction-Handler/trxTransaction.js: multiple Sequelize model queries and updates (ColdWalletWithdraw, Setting) without explicit transactions
Scalability & Performance
2/10
Handling load and speed
Some awareness of pagination and batching for external APIs, but the main processing loop is an infinite loop without robust backoff, no queueing, and limited resilience/configurable rate limiting.
Evidence
TRX-and-TRC20-Transaction-Handler/trc20Transaction.js: paginated API calls using start/limit in getTrc20Transfers
TRX-and-TRC20-Transaction-Handler/index.js: long-running while(true) loop scanning blocks with simple sleep(3000) instead of robust backoff or queued processing
System Architecture
3/10
Overall system structure
Reasonable module separation (index, admin, trx/trc20 handlers, database, vault) and configuration via properties, but no evident service decomposition rationale, environment-based deployment patterns, or secret/config management beyond a vault abstraction (vault implementation not present).
Evidence
TRX-and-TRC20-Transaction-Handler/index.js: orchestrates modules trxTransaction.js, trc20Transaction.js, admin.js, database.js
TRX-and-TRC20-Transaction-Handler/admin.js: functions to load addresses and settings from DB and expose admin helpers
Security & Auth
2/10
Protecting data and access
Some sensitivity to secrets (calls to vault.getPrivate) and basic try/catch error handling, but no authentication/authorization on admin endpoints, limited input validation, and no visible dependency audit or hardened HTTP timeouts.
Evidence
TRX-and-TRC20-Transaction-Handler/admin.js: vaultFile.getPrivate(properties.get("hotWallet.public")) used to load private keys
TRX-and-TRC20-Transaction-Handler/index.js: admin endpoints exposed without authentication (e.g., /create-wallet, /change-cold-wallet-address)
Reliability & Observability
2/10
Stability and monitoring
Minimal observability and reliability patterns: pervasive console.log based logging, try/catch blocks, and sleeps, but no structured logging, metrics, graceful shutdown, or retry/backoff policies with jitter.
Evidence
TRX-and-TRC20-Transaction-Handler/index.js: use of console.log for operational messages and an infinite loop wrapping processing
TRX-and-TRC20-Transaction-Handler/trxTransaction.js and trc20Transaction.js: try/catch with console.log and use of sleep() for timing rather than retry/backoff frameworks
Expertise
Java• Middle
Node.js• Middle
Python• Junior
Industries
Blockchain & Crypto• Middle
Financial Services• Middle
Technologies
Node JS• since 2021 • Middle
Rest API• since 2021
Nest.JS• since 2024
GraphQL• since 2023
Express
Spring Boot• since 2021
RabbitMQ• since 2021
Django• since 2023
Apache Kafka
Sequelize
Axios
Recommendations
  • Implement production-grade resilience for the block scanner: replace infinite loop with a scheduler/worker queue, add exponential backoff, timeouts, retries with jitter, and graceful shutdown handling.
  • Harden APIs and admin endpoints: add authentication/authorization, validate inputs (addresses, amounts), and introduce idempotency keys for withdraw endpoints.
  • Add structured logging and metrics (correlation ids, request tracing) and introduce health checks and alerting so the service can be operated in production.
  • Introduce DB migration history and use explicit transactional boundaries for multi-step updates (withdraw creation + state change) to avoid race conditions.
  • Write integration tests and CI checks that exercise external API failure modes and vault/secret handling to prove operational correctness
Repositories
The developer's experience in this domain has been verified based on AI analysis of the following repositories:
Middle QA Engineer Confidence: Medium Generalist
Blockchain-focused software engineer (middle) specializing in unit-tested consensus simulation and transaction-processing backend code. The strongest proven skill is implementing and testing blockchain logic, demonstrated by comprehensive blockchain simulation unit tests and block/chain reorganization test coverage. Public code does not show CI-driven test automation, formal contract/schema testing, or dedicated performance/load testing artifacts.
Test Automation Frameworks
4/10
Building automated tests
Has JUnit-based unit tests with setup and assertions but lacks dedicated test fixtures, mock servers, or testcontainer-style integration harnesses.
Test Coverage & Strategy
5/10
What and how to test
Tests encode multiple negative and boundary scenarios for the blockchain simulation (orphans, forks, duplicate transactions), showing deliberate test cases rather than only happy-paths; no property-based tests or mutation testing were found.
API & Integration Testing
3/10
Testing how parts work together
Contains API endpoints and DB/tron-network integration code but lacks contract/schema testing, explicit retry/idempotency tests, or simulated external-service mocks.
Performance & Load Testing
1/10
Testing speed under load
No dedicated performance or load-testing artifacts; a CSV processor/time-slicing script exists but it is not a load or SLO driven test suite.
Bug Reporting & Analysis
1/10
Finding and describing bugs
No published bug reports, issue tracker entries, or documented root-cause analyses were present; test code contains thorough assertions but not linked bug investigations.
CI Test Integration
Running tests automatically
Not evidenced in public code
Expertise
SDET & Test Engineering• Middle
Unit & Component Testing• Middle
Industries
Blockchain & Crypto• Middle
Financial Services• Middle
Technologies
QA
CI/CD
Python• since 2021 • Middle
Go• since 2023 • Middle
JavaScript• since 2023 • Middle
Java• since 2021 • Middle
TypeScript• since 2023 • Senior
SQL
Prometheus• since 2023
CI/CD• since 2023
Git
AWS• since 2024
Docker
Grafana• since 2023
Sentry• since 2023
Amazon EC2
GitHub
Amazon S3
Recommendations
  • Develop and extend blockchain protocol simulators and consensus test harnesses with more property-based tests and mutation testing.
  • Build backend transaction-processing services for crypto custodial or exchange integrations, adding robust contract tests and idempotency validation.
  • Create CI pipelines that run unit and integration tests, capture artifacts, and quarantine flaky tests to improve release reliability.
  • Add contract/schema validation and simulated external-service mocks for the Tron integration to enable repeatable integration testing.
Repositories
The developer's experience in this domain has been verified based on AI analysis of the following repositories:
Middle Blockchain Developer Confidence: Medium DApp Engineer
A Solidity-focused dApp engineer at a middle level with practical experience building wallets, token utilities and security demos and a clear strength in implementing on-chain patterns and exploit demonstrations. The strongest proven skill is practical smart contract engineering evidenced by the HotWallet/UserWalletManager/Balance_Checker suite and the Reentrancy attack and solution examples. There is limited evidence of formal testing, CI, frontend integration, or production-grade protocol design and several contracts contain correctness issues that need audit and fixes.
Smart Contract Development
3/10
Writing smart contracts
Solid hands-on Solidity work across multiple contracts, with attention to gas and practical patterns, but largely single-repo examples without rigorous test/CI coverage or advanced protocol design.
Evidence
Smart-Contract-Wallet-Management-System/HotWallet.sol: custom batch transfer, transferGasLimit control and lockCall reentrancy guard
Smart-Contract-Wallet-Management-System/Balance_Checker.sol: tokenBalance with extcodesize and try/catch; getAllTokensBalances implementation
Smart-Contract-Wallet-Management-System/UserWalletManager.sol: createWallet and owner-management flows
Security & Audit
3/10
Checking contracts for flaws
Good awareness of common smart contract vulnerabilities with example exploits and mitigations, and use of patterns like ReentrancyGuard, but some fragile or buggy patterns remain and formal testing/CI evidence is limited.
Evidence
Smart-Contracts-Attacks/Reentrancy/Solution_2.sol: uses OpenZeppelin ReentrancyGuard and Address.sendValue for mitigation
Smart-Contracts-Attacks/Reentrancy/Attacker.sol: attacker contract demonstrates reentrancy mechanics and testing harness (hardhat/console.sol)
Smart-Contracts-Attacks/Self Destruct/Ether Game.sol: shows selfdestruct attack and defensive explanation
Blockchain Protocol Understanding
3/10
Knowing how blockchains work
Practical understanding of EVM-level details (extcodesize, assembly patterns via integrated clone factory, price feed integration), but limited evidence of deep protocol engineering like non-trivial on-chain invariants, L2 or MEV considerations.
Evidence
Smart-Contract-Wallet-Management-System/Balance_Checker.sol: assembly extcodesize used to detect contracts
Smart-Contract-Wallet-Management-System/UserWalletManager.sol: uses createClone pattern to deploy minimal proxies (integration with CloneFactory)
Solidity-Projects/brownie_fund_me/contracts/FundMe.sol: Chainlink AggregatorV3Interface usage and price conversion math
DApp & Web3 Integration
2/10
Connecting apps to blockchain
Integration with on-chain oracles and tooling (Brownie, Chainlink) is present but there is little or no frontend, subgraph, EIP-712, or advanced UX/transaction lifecycle handling showcased.
Evidence
Solidity-Projects/brownie_fund_me/contracts/FundMe.sol: AggregatorV3Interface usage and brownie-config.yaml for networks
Smart-Contracts-Attacks/Accessing Private Data/AccessingPrivateData.sol: comments showing use of web3 for storage inspection
Tokenomics & DeFi Logic
2/10
Token and finance logic
Basic DeFi/token economic logic implemented (entrance fee calculations, funder lists), but designs are simple and some edge cases and rounding/trust economics are not thoroughly handled or tested.
Evidence
Solidity-Projects/brownie_fund_me/contracts/FundMe.sol: getEntranceFee and getConversionRate math
Solidity-Projects/smartcontract-lottery/contracts/Lottery.sol: usdEntryFee and getEntranceFee logic
Decentralization & Trust Model
2/10
Designing trust without middlemen
Some role separation and multisig-like patterns are implemented (manager, owners, cold wallet), indicating attention to trust models, but there are correctness bugs and limited documented governance/upgrade lifecycle.
Evidence
Smart-Contract-Wallet-Management-System/UserWalletManager.sol: multi-owner setup, allowTochangeColdWalletAddress and changeOwner flows
Smart-Contract-Wallet-Management-System/HotWallet.sol: onlyAdmin and onlyWhenNotPause checks interacting with HotWalletManager
Verified artifacts
Expertise
DeFi & Decentralized Finance• Middle
Web3 Security & Smart Contract Audits• Middle
Industries
Blockchain & Crypto• Middle
Technologies
Web3
Solidity• since 2021 • Senior
Ethers.js• since 2024
Hardhat
Web3.js• since 2023
Chainlink
OpenZeppelin
Smart Contracts
Ethereum
Brownie
Vault• since 2021
Account Abstraction• since 2023
Token Standards• since 2024
Recommendations
  • Develop multi-contract integration work - production-grade wallet systems and manager flows with full unit/invariant tests and CI.
  • Implement thorough security testing: unit tests with attacker contracts, invariant/fuzz tests, and add CI checks (slither/echidna) for core contracts.
  • Harden governance and trust assumptions: document admin powers, add timelocks/multisig patterns, and fix logic bugs (e.g., owner/boolean resets).
  • Build a simple frontend or subgraph to exercise transaction lifecycles and show real dApp integration for wallet flows.
Repositories
The developer's experience in this domain has been verified based on AI analysis of the following repositories: