Candidates locations: All except Russia
Неизвестный работодатель · На сервисе с: 16.07.26 11:10
116972 - указать при отклике
Backend Developer
#Node.js/ #TypeScript
Middle
"Customer location: USA
Candidates locations: All except Russia
Working hours: 10:00 AM–7:00 PM CET, with overlap with U.S. business hours
Language: English B2
Estimated start date: ••••••••
Duration: 6 month"
"Project Responsibilities
1. Mobile app re-signing rebuild:
Consolidate the current split — Python/fastlane signing scripts (macOS runners), a Node 18 Lambda + SQS + DynamoDB queue service, a TS/Koa upload service — into a single async signing orchestrator
Implement Android signing from scratch: keystore provisioning, apksigner
Add cert/keystore rotation and expiry monitoring; unified completion webhook
Reverse-engineering required — the flow is undocumented, the client admits limited knowledge of it
2. TestRail integration — plan sync:
Add TESTPLAN/TESTSUITE resource types to the mapper service; wire up the unused TestRail Plan APIs
Preserve plan → suite → section hierarchy (today only flat test cases are imported)
Modernize the service along the way: EOL Node 16, deprecated request-promise
Add missing test coverage, including integration tests
3. Secure file storage (gates the API launch):
Migrate attachments to S3 pre-signed URLs across issue, build, and result services
Enforce authorization scoped to the parent resource via auth-v2 statements: access to an attachment = access to its parent entity
A reference implementation exists in one service — replicate the pattern
Write authorization test suites; update OpenAPI specs
4. Granular token scopes (gates the API launch):
Extend token-service: user selects access level + allowed modules, scope embedded in JWT claims
Extend authorization-service-v2: token rights = intersection of user roles and token scope, DENY by default; a token can never grant more than its owner has
Add scope selection to the token-creation UI flow
5. Rocket.Chat notifications:
Implement RC notifications alongside SMS (~$10–15k/year savings target); pilot with user-behavior monitoring
Candidate's Portrait
- Self-directed senior comfortable in brownfield: EOL runtimes, deprecated dependencies, undocumented systems nobody fully understands
- Treats authorization and integration tests as part of the deliverable, not an afterthought
- Two positions with a deliberate split: one auth/security-leaning (tasks 3–4), one integrations-leaning with Python/signing exposure (tasks 1–2)
Must have:
5+ years of backend development with Node.js and TypeScript in production
Experience implementing authorisation logic in production (not just consuming auth libraries)
AWS: Lambda, SQS, DynamoDB, S3 (including pre-signed URLs)
JWT and authorization models: claims, scopes, policies, DENY-by-default evaluation
MySQL
Third-party API integrations: webhooks, callbacks, rate limits, idempotency
English B2+
Nice to have:
Python reading fluency; mobile code signing (fastlane, provisioning profiles, apksigner, keystores)
Koa; Serverless Framework
Kafka, GraphQL
Legacy modernization: Node EOL upgrades, request-promise → got/axios, aws-sdk v2→v3
Rocket.Chat, TestRail, Twilio integrations"
Писать ••••••••⚡️⚡️⚡️
HireSeeker собирает вакансии со всех площадок и присылает только релевантные. Бесплатно.