Frontend Developer
5+ years exp
Node JS
TypeScript
SQL
JavaScript
Security & Auth: 7/10
API Design: 6/10
Data Layer & Database: 6/10
Active 4 days ago
Invite to interview
Download CVCV
Overview
Technical skills
Timeline
Roles
Overview
A Senior backend API engineer focused on building secure, well-tested Node.js/Express services with thoughtful API contracts. The strongest proven skill is designing and testing secure authentication and session flows, evidenced by apps/api/src/features/auth/google/google-oidc.routes.test.ts and apps/api/src/features/auth/session/session.routes.test.ts. There is limited public evidence of distributed systems work such as queues, message-driven architectures, wide-scale performance benchmarking, or operational telemetry pipelines.
Technical skills
Languages
4
Node JS
TypeScript
SQL
JavaScript
DevOps
3
AWS
Git
CI/CD
Frontend
7
React.js
Zod
React Query
Tailwind CSS
Radix UI
Zustand
React Hook Form
Other
16
PostgreSQL
Puppeteer
Express
Vitest
Rest API
Vite
Claude
GitHub
Material UI
React Router
Jest
CI/CD
Mocha
Docker
Claude Code
AI Agents
Timeline
Front-End Engineer
•
Middle
Amazon
•
Full-Time
Developed and maintained core features for Amazon Freight’s website, contributing to high-volume business workflows. Onboarded and supervised an SDE intern program, including task assignment and code review coordination. Participated in on-call rotations by triaging and resolving production incidents. Built integration tests and connected them to CI/CD for safer deployments, and authored design documentation for complex changes.
TypeScript
React.js
Node JS
Java
AWS
CI/CD
Git
Full-Stack Developer
•
Middle
Corcus
•
Full-Time
Developed and maintained multiple applications using a React and Node.js stack with PostgreSQL. Implemented user workflows such as bug fixes, an email campaign using automated sending, and a referral system with shared links. Created internal administration tooling for graphical statistics and used Puppeteer to automate tasks across websites. Also assisted with building a decentralized application (DApp).
React.js
Node JS
PostgreSQL
Puppeteer
SQL
Simon Fraser University (SFU)
Bachelor's Degree •
Computer Science
Senior Backend Developer
Confidence: High API Engineer
A Senior backend API engineer focused on building secure, well-tested Node.js/Express services with thoughtful API contracts. The strongest proven skill is designing and testing secure authentication and session flows, evidenced by apps/api/src/features/auth/google/google-oidc.routes.test.ts and apps/api/src/features/auth/session/session.routes.test.ts. There is limited public evidence of distributed systems work such as queues, message-driven architectures, wide-scale performance benchmarking, or operational telemetry pipelines.
API Design
6/10
How well APIs are designed
API design shows deliberate error contracts, schema validation, and consistent status handling with Zod-validated responses and focused route tests; versioning and advanced idempotency strategies are not evidenced. Good attention to client-friendly error shapes and central handling of authentication failures is present.
Evidence
apps/api/src/features/exercises/exercise.routes.test.ts: end-to-end route tests asserting status codes and request/response validation
apps/web/src/features/routines/api/routines.api.ts: frontend fetcher with explicit request cancellation and error class (RoutinesApiError)
apps/api/src/features/auth/session/session.routes.test.ts: tests showing CSRF token endpoint and idempotent logout behavior
Data Layer & Database
6/10
Working with databases
Data layer demonstrates transactional creation of related rows, owner-scoped queries, and schema-driven validation; there is clear DB-aware logic and migration/seed practices, but little evidence of advanced tuning (indexing strategy, explicit isolation-level handling, or raw-SQL optimizations).
Evidence
apps/api/src/features/routines/routine.service.ts: service signatures for createRoutineForUser and listRoutinesForUser indicating transactional routine creation
apps/api/src/app.test.ts: health check tests that mock database connectivity and expect safe failure responses
Scalability & Performance
4/10
Handling load and speed
Some scalability-conscious decisions exist: frontend query caching, request cancellation propagated via AbortSignal, and explicit JSON-request size limits; however there is no evidence of queue-based decoupling, systematic caching-invalidations for backend reads, load-testing artifacts, or rate-limiting policies.
Evidence
apps/web/src/features/routines/api/routines.api.ts: fetchRoutines implements AbortSignal forwarding and client-side caching considerations
apps/api/src/app.test.ts: tests for JSON body size limit and malformed JSON handling (413/400 cases)
System Architecture
5/10
Overall system structure
The codebase is organized by feature with a clear composition root and feature routers, reflecting deliberate module boundaries and deploy-likely structure; microservice decomposition or multi-service contracts are not present and config/secret management is standard but not novel.
Evidence
apps/api/src/: repository shows feature-based organization and a refactor to 'features' folders (refactor described in commit message and present in file tree)
docs/architecture.md: architecture guidance present and referenced by backend file structure
Security & Auth
7/10
Protecting data and access
Strong evidence of security-conscious design: OIDC with PKCE and nonce/state, session-bound CSRF protection, ownership checks on resource mutations, and tests asserting safe error responses. Secrets lifecycle, token revocation patterns, or advanced threat mitigations beyond OIDC/session/CSRF are not fully visible.
Evidence
apps/api/src/features/auth/google/google-oidc.routes.test.ts: tests validating PKCE, state, nonce, and safe callback handling
apps/api/src/features/auth/session/session.routes.test.ts: CSRF token binding, idempotent logout, and session destruction tests
Reliability & Observability
5/10
Stability and monitoring
Reliability practices include comprehensive tests, safe error handling for middleware failures, explicit JSON parsing limits, and some graceful shutdown hinting; observable production patterns (structured logs with correlation ids, metrics, alerting, retries with backoff) are not present in the public code.
Evidence
apps/api/src/app.test.ts: asserts safe middleware error handling and that implementation doesn't leak internal error details
apps/api/src/server.ts: contains a shutdown signature indicating attention to graceful termination
Expertise
Node.js• Middle
Microservices & API Architecture• Middle
Databases & Vector Storage• Middle
System Architecture• Middle
Technologies
Rest API
Recommendations
- Design and implement authenticated REST APIs and transactional Postgres services that require careful ownership checks and validation.
- Develop feature-scoped backend services in Node.js/Express with robust test coverage, OIDC integration, and session/CSRF protection.
- Implement backend-for-frontend APIs coordinating TanStack-Query clients, request cancellation, and safe error contracts.
- Lead backend work that requires schema migrations, consistent seed data, and database transactional integrity.
Repositories
The developer's experience in this domain has been verified based on AI analysis of the following repositories:
Senior Frontend Developer
Confidence: Medium Fullstack
Full-stack web engineer (approx senior level) focused on building production-quality TypeScript React applications with strong state and API design. The developer demonstrates the strongest proven skill in server-client state ownership and secure API integration, evidenced by centralized auth/fetch helpers and mapped UI-to-API mappers such as apps/web/src/features/routines/create/routine-draft.mapper.ts and the auth API helpers in apps/web/src/features/auth/auth.api.ts. There is limited public evidence of deep a11y engineering, dedicated performance measurement artifacts, or large-scale cross-service systems in the analyzed human-authored files.
UI Component Architecture
6/10
How interface parts are built
Reasonable component boundaries and reusable primitives are present, with deliberate composition patterns and small utilities that indicate a component-driven approach rather than one-off pages.
Evidence
apps/web/src/lib/utils.ts: cn utility for grouping long Tailwind class lists
apps/web/src/features/routines/create/editor/routine-exercise-order.ts: reorderRoutineExercises helper encapsulating list logic for DnD
apps/web/src/features/routines/create/routine-draft.mapper.ts: mapping of UI draft to API input indicating separation of view and API concerns
Responsive & Cross-browser
4/10
Works on all screens and browsers
Mobile-first and responsive layout considerations are present in the project tooling and in some UI code, but explicit advanced responsive techniques or broad cross-browser feature-detection code is limited in the analyzed files.
Evidence
apps/web/package.json: tailwindcss and @tailwindcss/vite present as core responsive tooling
apps/web/vite.config.ts: project build config that integrates Tailwind (file listed in repository index)
Performance Optimization
5/10
Speed of the interface
There is evidence of pragmatic performance-aware decisions such as using a query cache, request cancellation, and keeping heavy logic off the render path, but no deep measured optimization artifacts or bundle-analysis reports in the analyzed files.
Evidence
apps/web/src/features/routines/api/routines.api.ts: fetchRoutines signature (fetcher abstraction) indicating server-state handling
apps/web/package.json: dependency on @tanstack/react-query indicating use of server-state caching patterns
Accessibility & Semantics
4/10
Usable for everyone
Accessibility-aware choices are suggested by use of Radix, keyboard-preserving drag support, and accessible primitives in descriptions, however concrete ARIA handling, focus-management code or CI a11y tooling references were not present in the analyzed human-authored files.
Evidence
apps/web/package.json: radix-ui listed as a dependency supporting accessible primitives
apps/web/src/features/routines/create/editor/routine-schedule-editor.reducer.ts: reducer-based state management chosen to keep UI interactions deterministic (supports accessibility-friendly updates)
State Management & Data Flow
8/10
Managing data in the app
Strong evidence of deliberate server-client state ownership and flow control: React Hook Form for local drafts, TanStack Query for server state, Zod for shared contracts, and explicit cache invalidation and request cancellation patterns show mature state management.
Evidence
apps/web/src/features/routines/create/routine-draft.mapper.ts: explicit mapper splitting UI-only fields from API contract
apps/web/src/features/routines/create/editor/routine-schedule-editor.reducer.ts: reducer for complex modal editing logic
apps/web/src/features/auth/auth.api.ts: centralized fetchCurrentUser and request-with-CSRF helpers (server-state integration)
UX & Visual Polish
6/10
Look and feel quality
UX behavior is well considered with explicit handling of edge states, form validation, and small UX niceties such as stable UI-only IDs during drag; there is solid polish in interaction details though heavy visual/a11y artifacts were not included in the analyzed file set.
Evidence
apps/web/src/features/routines/create/editor/routine-exercise-order.ts: stable draftExerciseId approach to avoid drag flicker
apps/web/src/features/routines/create/editor/routine-schedule-editor.reducer.ts: rules to keep schedule editing atomic and predictable
event-scheduler/client/src/hooks/useTimezone.ts: user-facing timezone mismatch handling for better UX
Expertise
React• Middle
Frontend Architecture & Build Tools• Middle
Industries
Lifestyle• Middle
Technologies
JavaScript
Node JS• since 2021 • Senior
Zustand
Tailwind CSS
Express
Puppeteer• since 2021
CI/CD• since 2022
Git• since 2022
AWS• since 2022
Docker
React.js• since 2021
Vite
React Query
Radix UI
Material UI
Zod
React Hook Form
React Router
GitHub
Recommendations
- Lead development of full-stack features that require coordinated client-server state - e.g., routine creation flows, authenticated CRUD with cache invalidation and optimistic UI.
- Implement and own authentication, session, and security-sensitive features such as OIDC, CSRF, and secure session management.
- Build complex form-driven UIs with React Hook Form and TanStack Query, including DnD interactions and reducer-based modal editors.
- Improve observable performance and accessibility by adding measurable performance reports (bundle and RUM), and axe/E2E a11y checks in CI.
Repositories
The developer's experience in this domain has been verified based on AI analysis of the following repositories:
Senior QA Engineer
Confidence: High SDET
Senior SDET and full-stack test engineer (approx. senior level) specializing in secure API and contract testing. The strongest proven skill is secure authentication and API-error validation backed by end-to-end and negative-path tests such as apps/api/src/features/auth/google/google-oidc.routes.test.ts and apps/api/src/app.test.ts. There is limited or no public evidence of dedicated performance/load testing, CI workflow matrices or external bug-report/post-mortem artifacts.
Test Automation Frameworks
6/10
Building automated tests
Test automation and infrastructure present with reusable fixtures, test helpers, and service-level integration tests using Vitest and Supertest; shows deliberate fixture design and session mocking rather than only superficial UI tests.
Evidence
apps/api/src/features/auth/google/google-oidc.routes.test.ts
apps/api/src/features/auth/session/session.routes.test.ts
apps/api/src/features/exercises/exercise.routes.test.ts
Test Coverage & Strategy
6/10
What and how to test
Good negative-path and boundary testing, explicit assertions for error conditions, and idempotency checks; tests encode expected failure states rather than only happy-path assertions.
Evidence
apps/api/src/app.test.ts - malformed JSON and request size client-error tests
apps/api/src/features/auth/google/google-oidc.routes.test.ts - validateReturnTo and replay/expired flow tests
apps/api/src/features/auth/session/session.routes.test.ts - idempotent logout and CSRF negative-path tests
API & Integration Testing
6/10
Testing how parts work together
API and integration testing with contract validation and service-layer tests; Zod-based schemas and focused route/service tests exercise authorization, request validation, and error mapping.
Evidence
packages/contracts (Zod schemas referenced in apps/web and apps/api packages)
apps/api/src/features/exercises/exercise.routes.test.ts - route-level contract and auth tests
apps/api/src/features/routines/routine.service.ts - service signatures showing createRoutineForUser and transaction-aware behavior
Performance & Load Testing
Testing speed under load
Not evidenced in public code
Bug Reporting & Analysis
3/10
Finding and describing bugs
Some evidence of defensive failure handling and regression-focused tests that document and guard against regressions, but no public issue tracker artifacts or dedicated post-mortem reports.
Evidence
apps/api/src/features/auth/google/google-oidc.routes.test.ts - tests for provider error handling and safe error responses
apps/api/src/features/auth/session/session.routes.test.ts - tests verifying session destruction and idempotency
CI Test Integration
4/10
Running tests automatically
Repository includes build, test, lint and precheck scripts and pre-commit tooling (husky, lint-staged), but no explicit CI workflow matrices, artifact retention, or flaky-test quarantine mechanics are visible.
Evidence
package.json - root scripts (precheck, test, typecheck, lint, build) and husky prepare
apps/api/package.json - test and typecheck scripts using vitest and tsconfig
apps/web/package.json - test and typecheck scripts, dev proxies and tooling
Expertise
API Testing & Contract Validation• Middle
SDET & Test Engineering• Middle
Technologies
CI/CD
TypeScript• since 2022 • Senior
Jest
Mocha
Vitest
Recommendations
- Lead development of authenticated API features and contract-first API design, including Zod-based contracts and service-layer tests.
- Build and expand test infrastructure: add end-to-end pipelines, artifact retention, selective matrix runs, and quarantine mechanics for flaky tests.
- Design and implement contract-driven integration tests and consumer-driven contract verification between frontend and backend.
- Add performance and load testing (k6/locust) for key endpoints and SLO-driven alerts to complement functional coverage.
Repositories
The developer's experience in this domain has been verified based on AI analysis of the following repositories:
