You'll work on Node.js microservice monorepos with 15+ services — Express (CommonJS) and NestJS (TypeScript) — behind a custom API gateway, running on Docker/Kubernetes with GitLab CI pipelines.
As the senior developer you own service architecture end-to-end: you design, write production code daily, review, unblock others, and carry technical decisions through ADRs. You will also mentor a mid-level developer joining the team at the same time.
What You'll Do
- Design and build backend services (Express and NestJS): API gateway routing, auth (JWT + TOTP MFA), workflow/state-machine services, file handling, notifications, audit history
- Lead the ongoing migration of legacy Express/Sequelize services to NestJS/TypeORM with zero-downtime (strangler-fig) rollouts
- Own data architecture across PostgreSQL (Sequelize + TypeORM, schema-per-service), MongoDB (Mongoose), and Redis (caching, sessions, rate limiting)
- Design and harden event-driven flows on RabbitMQ: exchanges and routing, dead-letter queues, retry strategies, idempotent consumers
- Raise the bar on testing (Mocha/Chai/Sinon, Jest, Supertest) and observability (structured logging with correlation IDs, Elastic APM)
- Debug production incidents across the full chain: gateway → auth → service → RabbitMQ → consumers
- Write and review ADRs; mentor the mid-level developer through code review and pairing
Must-Have
- 5+ years backend development with deep, recent Node.js experience (event loop, streams and backpressure, cluster vs worker_threads, memory profiling)
- Production experience with Express and a structured framework (NestJS strongly preferred); solid TypeScript
- Strong PostgreSQL experience: transactions, pessimistic/optimistic locking, migration strategy; working MongoDB and Redis knowledge
- Message-broker experience in production (RabbitMQ preferred; strong Kafka/NATS with the ability to transfer concepts is acceptable)
- Real testing discipline: unit + integration tests, mocking/stubbing, a clear view of what coverage numbers do and don't tell you
- Security awareness: JWT pitfalls, MFA flows, rate limiting, secret handling, OWASP basics
- Docker (multi-stage builds) and CI/CD pipelines (GitLab CI or equivalent); comfortable with Kubernetes deployments
- Able to explain and defend architectural trade-offs in writing (ADRs) and in review
Nice-to-Have
- Microservice patterns: circuit breakers, saga, service registry, distributed tracing (OpenTelemetry / Elastic APM)
- Zero-downtime migration experience (canary, blue-green, shadow traffic)
- Security tooling in CI: Gitleaks, Snyk, Trivy
Interested candidates can apply by clicking the link provided in the "Apply" button.