Description
Summary We're looking for a senior full-stack developer with a strong security background to extend and harden a large, mature application. You'll navigate an existing codebase with real history and real constraints, implement security controls, optimize performance, and keep the system scalable and reliable. You should have deep, self-earned coding fundamentals and know how to use AI as a force multiplier. This is not a role for developers who depend on AI to write code they couldn't write themselves. You should be able to reason through a large legacy codebase unaided — your engineering foundation is what separates AI producing noise from AI producing shippable work. About the Role The stack is TypeScript end to end: a Next.js frontend and AWS-backed services. AI tooling is a deliberate part of the workflow — generating implementation plans, stress-testing those plans against our architecture and business requirements, reviewing generated code for correctness, and shipping with confidence. When AI hits the limits of a complex legacy system, and it will, you're the one who knows how to guide it through. What You'll Do Own the full lifecycle of AI-assisted development: draft plans, pressure-test them against real architectural constraints, and validate that generated code is production-worthy Ensure solutions respect existing codebase structure, clean architecture principles, and layered design patterns Validate that all code — generated or hand-written — ships with appropriate unit and end-to-end tests and thoughtful edge case coverage Apply and enforce security best practices aligned to the NIST Special Publication series on federal security controls: access control, audit logging, system integrity, and secure configuration management across frontend and backend Act as a rapid-response resource for user-facing issues — diagnose, prototype, and deploy fixes fast when production is on the line What We're Looking For Five or more years of proven TypeScript development, with a body of work predating widespread AI coding tools — you know the language, not just the prompts Deep proficiency in React and Next.js Strong working knowledge of AWS (Lambda, SQS, DynamoDB, IAM, and similar) The ability to critically read generated code and catch architectural drift, security gaps, and subtle logic errors the model won't flag itself Familiarity with the NIST federal security control framework or comparable standards, and the judgment to translate controls into practical engineering decisions Comfort using AI tools (Claude Code, Copilot, and similar) as a development partner, with the depth to steer them in unfamiliar or complex codebases Strong debugging instincts and the ability to move fast under pressure without cutting corners on security or quality Bachelor's degree in Computer Science or a related field Nice to Have Mobile platform experience (iOS/Android), infrastructure-as-code, or CI/CD pipeline work. Familiarity with FedRAMP, SOC Type II, or other compliance regimes that map to the NIST control catalog.