Experience level filter
Job type filter
Client history filter
Project length filter
Hours per week filter
  • Hourly: $70.00 - $85.00
  • Expert
  • Est. time: Less than 1 month, Less than 30 hrs/week

We have a healthcare platform that is already in use and are looking for a senior Full Stack Developer to help us review and improve a specific area of the product. This initial task is expected to take around 1–2 hours for an experienced developer and will focus on understanding the current setup, identifying the root cause of an issue and making the right improvement without unnecessary changes. If the collaboration goes well, there will be opportunities to continue supporting the platform as new features, improvements and technical challenges come up. As the platform grows, we are seeing the kind of real-world challenges that come after launch: workflows that need refinement, areas where data flow can be improved, integrations that need attention and new features that require changes across the frontend, backend and database. We are looking for someone who can understand the full system, build thoughtful solutions with technologies like React, TypeScript, Node.js, PostgreSQL and APIs and help us make reliable improvements without creating unnecessary complexity. Experience with healthcare applications, patient portals, SaaS platforms or workflow-based systems is a strong plus. We are also exploring AI-powered improvements such as medical document processing, intelligent search, patient data organization, workflow automation and LLM-based features that can reduce manual work and improve the overall healthcare experience. Experience integrating AI APIs or building AI-assisted products would be valuable.

  • Hourly: $70.00 - $110.00
  • Expert
  • Est. time: 1 to 3 months, Less than 30 hrs/week

What this hire is. A senior full-stack engineer to take a fully specified, largely pre-built multi-tenant B2B SaaS application from documented spec to a hardened, deployed production system. The work is integration, security, third-party wiring, and deployment — not greenfield design, not product decisions, not building core feature logic from scratch. Architectural judgment and precision against a spec matter far more than raw output speed.

  • Hourly: $95.00 - $135.00
  • Expert
  • Est. time: 3 to 6 months, Less than 30 hrs/week

Looking for a developer to help build Premium Haztrak, a blockchain-enhanced environmental compliance platform focused on hazardous-waste tracking, digital manifest workflows, regulatory audit trails, and legal chain-of-custody verification. The product is designed to help organizations manage hazardous-waste records, shipment events, signatures, corrections, supporting documents, and compliance history in a secure and legally defensible way. The key innovation is a blockchain-based proof layer that verifies record integrity without storing sensitive environmental or regulatory data directly on-chain. The initial work will focus on building a prototype/MVP that includes manifest management, document/event hashing, hash-linked chain-of-custody timelines, blockchain proof anchoring, and a verification page where users can confirm whether a record or document has been changed. # Project Overview Premium Haztrak is a modern environmental compliance platform designed to help organizations manage hazardous-waste tracking, electronic manifest workflows, and regulatory compliance records in a more secure, transparent, and legally defensible way, specifially designed for Office of Chief Counsel, PA Department of Environmental Protection, USA. The platform is built around hazardous-waste cradle-to-grave tracking, allowing generators, transporters, facilities, compliance teams, and legal professionals to manage key records, shipment events, supporting documents, signatures, corrections, and audit history in one structured system. The next phase of the project will introduce blockchain-based verification to strengthen record integrity, chain of custody, and regulatory audit readiness without exposing sensitive compliance data on-chain. # Current Version Status The current version provides the foundation for electronic hazardous-waste tracking and demonstrates how a digital system can support EPA e-Manifest and RCRAInfo-related workflows. At this stage, the platform focuses on core hazardous-waste record management, including manifest-related workflows, shipment tracking concepts, compliance documentation, and integration patterns for working with official environmental systems. The current system should be treated as the base layer for a more advanced compliance product. The goal now is to expand it into a premium version with stronger legal, audit, and verification capabilities. # New Integration Goals The main enhancement will be a blockchain-powered compliance verification layer. This blockchain layer will not store private hazardous-waste records directly on-chain. Instead, the system will generate cryptographic proofs for important documents and events, then anchor those proofs to blockchain so records can be independently verified later. # Key integration points include: Blockchain-based proof of manifest records Tamper-evident chain-of-custody tracking Hashing of documents, signatures, corrections, and shipment events Verifiable audit logs for regulatory and legal review Evidence packet generation for disputes, audits, or investigations Secure off-chain storage for sensitive data On-chain proof references for record integrity verification Compliance dashboard for high-risk, incomplete, or disputed records Core Product Features Premium Haztrak should include: Manifest and shipment management Organization and user role management Document upload and record storage Signature and approval tracking Correction and dispute history Chain-of-custody timeline Blockchain proof generation Verification page for documents and records Audit-ready PDF export Legal evidence packet generation Compliance activity dashboard Blockchain Integration Concept The blockchain component will work as a proof layer. When a critical event happens, such as a manifest being created, signed, corrected, received, or finalized, the system will generate a hash of that event or document. These hashes can be grouped and anchored to blockchain through a smart contract or verification registry. This allows a user, auditor, attorney, or regulator to later confirm whether a record matches the original verified version. The private data stays protected in the application database or secure storage. The blockchain only stores verification proofs.

  • Fixed price
  • Intermediate
  • Est. budget: $750.00

Need Re-architect a static interactive web tool so its content lives behind login on a server, not in the browser. Next.js + Supabase. US-Only. No Subcontracting.

  • Hourly: $25.00 - $47.00
  • Intermediate
  • Est. time: 3 to 6 months, Less than 30 hrs/week

PLEASE NOTE: ALL DIRECT CALLS AND EMAILS WILL BE BLOCKED, AND SENDERS WILL BE DISMISSED FROM CONSIDERATION, EVEN ON UPWORK. WE WILL NOT WORK WITH ANYONE WHO CONTACTS US OUTSIDE OF UPWORK. ZERO EXCEPTIONS. We are seeking a full-stack developer for both the ongoing maintenance of current products as well as the development of new products. We are a sports media company that creates applications that help fans be more effective when it comes to attending live sporting events. EXISTING PRODUCT DEVELOPMENT: Our first product launched two months ago: calendar.thestadiuminsiders.com, a custom calendar which incorporates team sports calendars (NFL, NBA, NHL, MLB, etc.) plus concerts/special events into a single view for each city. This required the integration of calendars from multiple sources in multiple formats, consolidated into a single view. Lots of moving pieces. The calendar has been developed, successfully launched, and is very stable. But there is ongoing maintenance to do, as well as continued enhancements to make. Our calendar was built in React, Next.js, and Firebase (this was not an AI developed product: it was built the old fashioned way). It also incorporates ICS feed parsing, which is critical. You need to understand these elements, as well as complex data architectures and data management. (Our advice: please don't approach your proposal by telling us about all of the pitfalls and traps waiting for us. We've had great developers and product managers working extremely hard to build a great product, and we haven't overlooked the complexities and nuances. We need someone to take a really well-built product and build on top of it, not tell us how they're going to save it from assured collapse. We're happy to hear that you understand some of those traps and nuances and complexities. Just please don't assume we haven't thought of them. Better to focus on why your experience is a good fit, rather than explaining coding to us). NEW PRODUCT DEVELOPMENT: Separate from the above product, we have a pipeline of products that are on deck that are being developed via vibe coding (specifically in Lovable), but we need a developer who can push them the last 10 yards before launch. Porting these projects from Lovable into Claude is completely fine (we know Claude is the stronger dev platform), but our front-end team is working in Lovable because it is an easier interface. But I expect we will move the projects over to Claude once we have the right person in place to assist with that. General Requirements: --NextJS --React --Firebase Functions and Firestore --NoSQL design --ICS calendar formats --CSV uploading --Vercel --Vibe coding (specifically taking products built with Lovable and making them production-ready) An understanding of sports is helpful, as it makes it easier to understand the relationship between teams, venues, leagues, and cities. You don't need in-depth specific understanding of stats or players or such, but an understanding of sports leagues will make it easier to understand the tasks at hand. In terms of approach, we will first want to make a bunch of quick fixes/improvements to the calendar app, followed by two more substantive upgrades. After that we will turn our attention to new products. Thanks -- we appreciate your interest, and we look forward to finding someone great. This is a fun product and an interesting company, especially for someone who likes sports.

  • Hourly
  • Expert
  • Est. time: 1 to 3 months, Less than 30 hrs/week

# Job Title **Full-Stack Developer Needed for Travel Deal + Group Trip Planning Platform MVP — Trip’d** ## About the Project I’m building **Trip’d**, a travel discovery and group trip planning platform designed to help people: **Find it. Plan it. Split it. Go.** The goal is to combine the excitement of discovering unusually cheap travel deals with the tools people actually need once they decide to take the trip. Trip’d should help users go from: **“Wow, that flight is cheap.”** to: **“Okay, we can actually make this trip happen.”** The platform will focus on affordable travel discovery, flexible trip planning, group coordination, estimated trip costs, and automatic expense splitting. I already have a front-end prototype, brand direction, feature concepts, and a clear product vision. I’m looking for a full-stack developer who can help turn this into a real, functional MVP. This is not simply a static website build. ## Core Product Idea Trip’d has three main parts: ### FIND Discover cheap flights and affordable travel opportunities. ### PLAN Turn a deal into a real trip and plan it with friends. ### SPLIT Automatically calculate trip costs, per-person shares, and who owes who. The overall experience should feel modern, social, affordable, visual, and easy to use. It should not feel like Expedia, Kayak, or a traditional airline website. --- # MVP FEATURES ## 1. User Accounts Users should be able to: * Create an account * Log in * Set home/departure airports * Set a typical flight budget * Select travel preferences * Save destinations * Save flight deals * Create trips * Join trips through an invite link Preferred authentication can be handled through Supabase Auth or a similar service. --- ## 2. Cheap Travel Deal Discovery Trip’d should surface affordable flight opportunities instead of relying only on traditional destination-first search. Users should be able to browse deals based on: * Departure airport * Maximum flight budget * Flexible dates * Domestic / international * Trip duration * Weekend trips * Last-minute trips * Destination * Travel vibe Examples: **New York → Puerto Rico** $128 round trip Usually $287 Save $159 Or: **How far can $200 take me?** Budget-based discovery should be a major part of the platform. Deal cards may include: * Destination * Country * Origin airport * Flight price * Typical price * Amount saved * Travel dates * Trip duration * Airline * Nonstop / connecting * Destination photo * External booking link * Estimated total trip cost Users should be able to save deals and turn a deal into a trip. --- ## 3. Flexible Travel Filters Users should be able to filter deals by: * Origin airport * Budget * Destination * Travel dates * Flexible dates * Trip length * Domestic / international * Nonstop * Airline * Weekend * Long weekend * Last-minute * Beach * Party * City * Relaxing * Adventure * International Prominent discovery options could include: **Everything under $200** **Weekend trips under $250** **International deals under $500** --- ## 4. Trip Creation A user should be able to select a deal or destination and create a trip. Example: ### CANCÚN 2027 🌴 May 20–25 6 travelers A trip should have: * Destination * Dates * Travelers * Flight information * Stay information * Estimated budget * Saved activities * Notes * Expenses * Trip members Users should be able to invite friends through a unique link. --- ## 5. Group Trip Planning Trip’d should make it easier for groups to actually organize travel. For the MVP, group planning could include: * Invite friends * Join trip * Shared destination * Shared dates * Saved flight options * Saved accommodations * Shared notes * Estimated cost per person * Polls for destinations * Polls for dates * Polls for accommodations Full real-time group chat is NOT required for V1. A simple comments or notes feature may be enough initially. --- ## 6. Automatic Trip Cost Splitting This is an important feature. Users should be able to add trip expenses and Trip’d should automatically calculate how much each traveler owes. Example: ### Airbnb Total: $1,260 Travelers: 6 Trip’d calculates: **$210/person** Another example: ### Airport Uber Total: $84 Participants: * Derek * Maya * Chris * Jordan Trip’d calculates: **$21/person** Expenses should support: * Expense name * Expense category * Total amount * Who paid * Who participated * Split equally * Custom split * Per-person amount * Payment status Trip’d should also calculate balances. Example: **Maya owes Derek $46.50** **Chris owes Jordan $18** **Derek is owed $64.50 total** For the first MVP, Trip’d does NOT need to process money. Users can simply: * Mark an expense as paid * Mark a balance as settled Payment integrations can be considered later. --- ## 7. Estimated Total Trip Cost Trip’d should help users understand the full cost of a trip, not just airfare. Example: ### 4 Days in Puerto Rico Flight: $128 Stay: ~$185/person Transportation: ~$45 Activities: ~$90 Estimated total: **$448/person** Trip costs may include: * Flight * Accommodation * Transportation * Food estimate * Activities * Other group expenses Clearly label estimates as approximate. The goal is to answer: **“Can we actually afford this trip?”** --- ## 8. My Trips Dashboard Users should have a dashboard showing: * Upcoming trips * Saved trips * Deals they are watching * Group trips * Amount they owe * Amount they are owed * Trip budgets * Saved destinations Example: ### Puerto Rico 🌴 Oct 9–13 5 travelers Flight: $128 Estimated trip total: $462/person Your balance: **You are owed $54** --- ## 9. Destination Pages Each destination should have a visual page containing: * Current deals * Typical airfare * Suggested trip length * Estimated cost * Travel vibe * Things to do * Saved trips * Outfit inspiration * Vacation playlist The initial content can be manually entered through an admin dashboard. --- ## 10. Outfit Inspiration I want Trip’d to include a lifestyle component. Users should be able to select a destination or country and see outfit inspiration for the trip. Examples: * Beach look * Daytime look * Dinner look * Night-out look * Color palette * Packing inspiration This can initially use manually curated content and images. --- ## 11. Vacation Playlists Destinations should also have a vacation playlist section. Examples: ### Jamaica 🇯🇲 Trip’d Jamaica Playlist ### Spain 🇪🇸 Trip’d Spain Playlist ### Puerto Rico 🇵🇷 Trip’d Puerto Rico Playlist For the MVP, playlists can simply display curated song information or link to Spotify / Apple Music playlists. A more advanced music integration is not required initially. --- ## 12. Social Sharing Trip’d should make trips and deals easy to share. Examples: **“Who’s coming with me? 👀”** **“$128 round trip is crazy.”** Users should be able to share: * Flight deals * Trips * Trip invite links * Destination cards * Estimated trip costs Possible sharing options: * Text * Copy Link * GroupMe * Instagram-friendly share card * Other native mobile sharing options where possible --- ## 13. Admin Dashboard I need an admin area where I can manage platform content. Admin functions should include: * Add flight deals * Edit flight deals * Delete flight deals * Add destinations * Manage destination content * Add outfit inspiration * Add playlist information * Add estimated trip costs * Manage users if necessary * Manage featured deals * Manage travel categories Initially, manually curated flight deals are acceptable. The system should be built so automation can be added later. --- # FLIGHT DATA The project should be structured so a legitimate flight data provider can be connected. Potential providers may include: * Duffel * Amadeus * Skyscanner Partners * Other legitimate flight APIs Please do not use illegal scraping methods. Users do NOT need to purchase airline tickets directly through Trip’d in the first MVP. Trip’d can surface the opportunity and then send users to an airline or trusted booking provider to complete the reservation. I am open to technical recommendations regarding the best flight data solution. --- # PREFERRED TECHNOLOGY I am open to recommendations, but my current preferred stack is: * Next.js * React * TypeScript * Supabase * PostgreSQL * Supabase Auth * Vercel * Responsive / mobile-first development The project should use reusable components and a clean architecture. The code should be documented and organized so other developers can work on it later. --- # DESIGN DIRECTION The brand is called: # TRIP’D Tagline: **Find it. Plan it. Split it. Go.** Trip’d should feel like a combination of: * Modern travel startup * Social travel app * Group trip planner * Lifestyle travel brand The visual experience should feel: * Youthful * Modern * Clean * Social * Fun * Affordable * Trustworthy * Visual * Mobile-friendly It should feel Gen Z-friendly without being childish or overly trendy. The platform should prioritize visual travel discovery. Users should want to browse Trip’d even when they do not already know where they want to travel. I already have a prototype that will be provided as the primary design reference. --- # WHAT I NEED FROM THE DEVELOPER I’m looking for someone who can handle both frontend and backend development. You should be comfortable with: * React * Next.js * TypeScript * Supabase * PostgreSQL * Authentication * Database architecture * Responsive UI development * API integration * User-specific data * Group/member permissions * Financial calculations * Deployment * Production web applications Experience building any of the following is a plus: * Travel platforms * Expense splitting applications * SaaS products * Consumer apps * Social products * Group planning tools * Marketplaces * Recommendation/discovery platforms --- # PROPOSED MVP MILESTONES I prefer a milestone-based fixed-price project instead of paying the full project price upfront. ### Milestone 1 Project architecture, database setup, authentication, hosting, and deployment ### Milestone 2 User profile, departure airports, travel preferences, and deal discovery ### Milestone 3 Flight deal database, filters, budget discovery, and saved deals ### Milestone 4 Trip creation, group invitations, trip members, and shared planning ### Milestone 5 Expense tracking, automatic splitting, balances, and settlement tracking ### Milestone 6 Destination pages, estimated trip costs, outfit inspiration, and vacation playlists ### Milestone 7 Admin dashboard and content management ### Milestone 8 Flight API integration or preparation for future integration ### Milestone 9 Testing, mobile optimization, bug fixes, analytics, and production launch I am open to changing this structure based on the developer’s recommendations. --- # OWNERSHIP I need full ownership of the finished product. All final source code, databases, custom components, documentation, and intellectual property created for Trip’d as part of the contract must be transferred to me upon payment. Whenever possible, the project should be built inside accounts that I own or control, including: * GitHub * Supabase * Vercel * Domain * Analytics * API accounts Please do not build the entire product inside accounts that only the developer controls. --- # WHEN APPLYING Please include: 1. Examples of web applications you personally built 2. Your experience with Next.js and React 3. Your experience with Supabase and/or PostgreSQL 4. Examples of third-party APIs you have integrated 5. Whether you handle both frontend and backend development 6. Any experience with group expense splitting or financial calculations 7. Your proposed approach to building this MVP 8. Which features you would prioritize for the first launch 9. Which features you would recommend postponing 10. Your estimated fixed project price or hourly rate 11. Your availability Please begin your proposal with: **TRIP’D** so I know you read the entire project description. I’m looking for someone who can help turn an existing product concept and prototype into a legitimate functional MVP — not simply convert a design into static HTML.

  • Hourly
  • Expert
  • Est. time: 1 to 3 months, Less than 30 hrs/week

We're looking for a senior full-stack developer with a strong security background to extend and harden a large, mature application. You'll navigate an existing codebase with real history and real constraints, implement security controls, optimize performance, and keep the system scalable and reliable. You should have deep, self-earned coding fundamentals and know how to use AI as a force multiplier. This is not a role for developers who depend on AI to write code they couldn't write themselves. You should be able to reason through a large legacy codebase unaided — your engineering foundation is what separates AI producing noise from AI producing shippable work. About the Role The stack is TypeScript end to end: a Next.js frontend and AWS-backed services. AI tooling is a deliberate part of the workflow — generating implementation plans, stress-testing those plans against our architecture and business requirements, reviewing generated code for correctness, and shipping with confidence. When AI hits the limits of a complex legacy system, and it will, you're the one who knows how to guide it through. What You'll Do Own the full lifecycle of AI-assisted development: draft plans, pressure-test them against real architectural constraints, and validate that generated code is production-worthy Ensure solutions respect existing codebase structure, clean architecture principles, and layered design patterns Validate that all code — generated or hand-written — ships with appropriate unit and end-to-end tests and thoughtful edge case coverage Apply and enforce security best practices aligned to the NIST Special Publication series on federal security controls: access control, audit logging, system integrity, and secure configuration management across frontend and backend Act as a rapid-response resource for user-facing issues — diagnose, prototype, and deploy fixes fast when production is on the line What We're Looking For Five or more years of proven TypeScript development, with a body of work predating widespread AI coding tools — you know the language, not just the prompts Deep proficiency in React and Next.js Strong working knowledge of AWS (Lambda, SQS, DynamoDB, IAM, and similar) The ability to critically read generated code and catch architectural drift, security gaps, and subtle logic errors the model won't flag itself Familiarity with the NIST federal security control framework or comparable standards, and the judgment to translate controls into practical engineering decisions Comfort using AI tools (Claude Code, Copilot, and similar) as a development partner, with the depth to steer them in unfamiliar or complex codebases Strong debugging instincts and the ability to move fast under pressure without cutting corners on security or quality Bachelor's degree in Computer Science or a related field Nice to Have Mobile platform experience (iOS/Android), infrastructure-as-code, or CI/CD pipeline work. Familiarity with FedRAMP, SOC Type II, or other compliance regimes that map to the NIST control catalog.

  • Hourly
  • Expert
  • Est. time: 3 to 6 months, Less than 30 hrs/week

*** DO NOT APPLY IF YOU CAN NOT DO AT LEAST 95% OF THE JOB DESCRIPTION*** We're looking for a battle-tested engineer with deep, self-earned coding fundamentals who also knows how to leverage AI as a force multiplier. This is not a role for developers who have grown dependent on AI to write code they couldn't write themselves. You should be able to navigate a large, complex brownfield codebase on your own — and when you do bring AI into the work, your engineering foundation is what makes the difference between AI generating noise and AI generating production-ready solutions. This role is deliberately vertical. You'll write product code, and you'll own the AWS environment it runs on. Those aren't two jobs handed to one person to save a headcount — they're one job, because the interesting failures happen at the seam between them. ## About the Role You'll work across a TypeScript codebase with a Next.js frontend and AWS-backed services supporting consumer mobile applications at meaningful scale. AI tools are a deliberate part of the workflow: prompting for implementation plans, critically evaluating those plans against our architecture and business requirements, reviewing generated code for correctness and quality, and shipping with confidence. When AI hits the limits of a complex legacy system — and it will — you'll be the one who knows how to guide it through. On the platform side, you'll own infrastructure defined in code, the network boundaries around our data services, our cloud security posture, and the vulnerability backlog. The systems you'll inherit include an event-driven ingestion pipeline (managed queues and a key-value store behind an API gateway), a columnar analytics warehouse feeding BI dashboards, object storage with a query layer over it, a document database, and webhook integrations with third-party attribution and app-store billing systems. That's real scope, and we're stating it plainly so you can decide whether you want it. If you'd rather not touch infrastructure, this isn't the role. If you've been looking for a job where you own the whole vertical instead of filing tickets across a boundary, it is. ## What You'll Do ### Product engineering - Own the full lifecycle of AI-assisted development: generating plans, stress-testing them against real architectural constraints, and validating that generated code is production-worthy - Write correct concurrent code: reason clearly about async/await, the event loop, promise scheduling and cancellation, and the difference between concurrency and parallelism — and keep blocking work off the request path so a slow upstream API never stalls the thread serving users - Make and defend architectural decisions: know where layered, clean, and hexagonal (ports-and-adapters) designs each earn their complexity, enforce separation of concerns, and keep AI-generated solutions inside the boundaries the codebase already established rather than letting them drift toward whatever pattern the model saw most often in training - Practice test-driven development in earnest — write the failing test first, make it pass, then refactor — and use TDD as the mechanism that keeps AI-generated code honest rather than a box to check afterward - Drive tests past the happy path: use AI to enumerate boundary values, error branches, race conditions, malformed input, and failure modes of dependencies, then verify the generated tests actually assert behavior instead of restating the implementation back at itself - Contain the blast radius of AI-assisted work: small reviewable diffs, plans before code, incremental commits, contract and regression coverage on anything touching shared surfaces, and a bias toward changes you can reason about end to end - Build and maintain the backend services behind our mobile applications, including event ingestion, third-party webhook consumers, and the integrations that feed reporting ### Platform and infrastructure - Define and change infrastructure as code: extend and review Terraform modules, manage state, read a plan critically before applying it, and recover when state and reality disagree - Own cloud networking: private and public subnets, security group and NACL design, and the access patterns for data services that sit inside the network — with a clear view of when putting compute in a VPC is the right call and when it just buys cold starts and NAT charges - Design read and write paths for scale, cost, and exposure: when something is hammering an object store or an API, diagnose whether it's legitimate traffic or an unsecured origin being scanned, and reach for the fix that matches — edge caching, cache-control and conditional requests, presigned URLs with sane TTLs, request collapsing, batching and backpressure on one side; blocking public access, origin access control, bucket policy and IAM scoping, WAF rate limiting, and keeping repository metadata and build artifacts out of served paths on the other - Treat a surprising cloud bill as a security signal, not just a cost problem — know which request outcomes you're billed for, what shows up in access and audit logs, and when the right response is rotating credentials rather than adding a cache - Own and tune cloud security posture management (AWS Security Hub, GuardDuty, Config, or equivalents): configure the standards, suppress the noise so real signal survives, and drive findings to closed - Apply and enforce security best practices aligned with NIST controls, including access control, audit logging, system integrity, and secure configuration management — using automated config checks to continuously verify those controls rather than attesting to them in a document nobody re-reads - Manage IAM as a design problem: least-privilege roles, scoped policies, credential rotation, and no long-lived keys where a role will do - Own CI/CD: pipelines that gate on tests, coverage, and security scans, with deploys that are reproducible and reversible ### Vulnerability management - Remediate CVEs, don't just report them. Take findings from discovery through to a shipped fix, including the unglamorous part where the patched version is a major bump and you absorb the breaking changes across the application - Triage with judgment: knowing whether a finding is reachable in code paths we actually execute or buried in a transitive dependency that never runs is what keeps you from breaking production over a theoretical risk. But the deliverable is a closed finding, not an assessment - Maintain dependency hygiene across a large Node/TypeScript tree, where the vulnerability surface is mostly transitive and the fixes are mostly version bumps with consequences - Remediate infrastructure and configuration findings, not just application dependencies — misconfigured storage, over-permissive policies, unencrypted resources, missing logging ### Operations - Serve as a rapid-response resource for user-facing issues — diagnosing, prototyping, and deploying fixes fast when production is on the line - Leave the environment legible to someone else: documented infrastructure, runbooks for the things that page you, and reproducible deploys. Sole ownership only works if it isn't sole knowledge ## What We're Looking For - 5+ years of proven TypeScript development experience, with work you can walk us through line by line and explain the reasoning behind — you know the language, not just the prompts - Deep proficiency in React and Next.js - Fluency in the JavaScript concurrency model, and enough exposure to how other ecosystems solve the same problem (C# tasks, Python asyncio, Kotlin coroutines, Rust futures, Go goroutines) to explain what async/await actually buys you and where it doesn't help - Demonstrated experience with TDD and a clear point of view on what it's good for and where it isn't worth it - The ability to reason about architectural tradeoffs out loud — not just name patterns, but say what each one costs and when you'd skip it - Strong working knowledge of AWS across compute, managed queues, key-value and relational stores, object storage, CDN, WAF, and IAM — including request-pattern and caching design under load and hardening of publicly reachable origins - Hands-on Terraform experience: writing and reviewing modules, managing state, and recovering from drift. Other IaC backgrounds (CDK, CloudFormation, Pulumi) transfer if the depth is there - Practical cloud networking: VPCs, subnet architecture, security groups, NACLs, and private connectivity to managed data services - Experience running a cloud security posture tool in anger — configuring standards, tuning findings, mapping automated checks to a control framework, and closing items rather than accumulating them - A demonstrated CVE remediation history: specific vulnerabilities you personally fixed, in both application dependencies and infrastructure configuration, including at least one where the fix required meaningful refactoring - Working fluency with SCA tooling (AWS Security Hub, Prowler, Dependabot, Snyk, npm audit, or similar) and a defensible process for prioritizing what gets fixed - The ability to critically read and evaluate AI-generated code — catching architectural drift, security gaps, and subtle logic errors that AI won't flag itself - A specific, experience-backed account of where AI coding tools fail: missing system-wide context, no real model of your codebase's complexity or layering, confidently wrong abstractions, tests that validate the bug, and volume that outpaces review capacity — plus the practices you use to keep that in check - Familiarity with AWS Security Hub, CIS Benchmarks, NIST or comparable security frameworks and the ability to translate controls into practical engineering decisions - Comfort using AI tools (Claude, Copilot, etc.) as a development partner, with the technical depth to steer them effectively in unfamiliar or complex codebases - Strong debugging instincts and the ability to move fast under pressure without cutting corners on security or quality - CI/CD pipeline ownership experience, including gating deploys on tests, coverage, and security scans ## Nice to Have Experience with mobile platforms (iOS/Android). Familiarity with FedRAMP, SOC 2, or other compliance frameworks that map to NIST. Experience with data warehousing or BI tooling. Container or serverless packaging experience. A CS degree or equivalent depth in fundamentals — data structures, concurrency, systems — however you came by it.

  • Hourly: $30.00 - $50.00
  • Expert
  • Est. time: 1 to 3 months, Less than 30 hrs/week

We’re looking for an experienced Next.js + Supabase developer to help us build and improve an existing web application. The project already has a foundation in place, so we’re not looking for a full rebuild. We need someone who can quickly understand the current codebase, complete features, fix issues, and help get the product production-ready. The work may include: Building and updating pages in Next.js Supabase database integration Supabase Auth and user account flows Row Level Security (RLS) policies CRUD functionality and API integrations Dashboard and account features File uploads and storage Responsive/mobile UI fixes Debugging existing frontend and backend issues Deployment and production QA Required experience: Strong Next.js and React experience TypeScript Supabase / PostgreSQL Supabase Auth, RLS, Storage, and database functions REST APIs / third-party integrations Git/GitHub Experience working with existing codebases We’re looking for someone who can work independently, communicate clearly, and make practical decisions without overcomplicating the project. When applying, please include: A few Next.js + Supabase projects you’ve worked on Your availability Your hourly rate A brief explanation of your experience with Supabase RLS and authentication This can turn into ongoing work if the first project goes well.

  • Hourly: $25.00 - $75.00
  • Intermediate
  • Est. time: 1 to 3 months, Less than 30 hrs/week

We’re looking for a strong UX engineer to improve the design, usability, and polish of an existing therapist directory / marketplace product. The product is built in Next.js / React / Tailwind / Supabase. It is already functional, but needs a sharper, more trustworthy, more modern user experience across the public directory, therapist profile pages, search/browse flows, and provider dashboard/admin areas. This is not a greenfield design-only project. I’m looking for someone who can both think through UX and make high-quality frontend changes directly in the codebase. What you’ll work on • Improve the overall visual design and UX of the site • Redesign key pages: homepage/directory, search results, therapist profile pages, provider dashboard • Improve spacing, typography, mobile responsiveness, CTA hierarchy, and trust signals • Make the site feel polished, professional, and conversion-focused • Work in a staging environment with production-like data • Submit clean GitHub commits / PRs Ideal candidate • Strong product/design taste • Excellent React / Next.js / Tailwind skills • Comfortable improving an existing codebase • Can make practical UX decisions without needing everything spelled out • Good eye for healthcare / professional services design • Reliable communicator Tech stack • Next.js • React • Tailwind CSS • Supabase • Vercel • GitHub Deliverables • UX/design improvements implemented in the staging codebase • Responsive desktop/mobile polish • Clear commits or PRs • Brief notes explaining major design decisions

Jobs Per Page: