CL

Mid-Level Custom Systems Developer (Contractor Role)

Hiring from
South Africa
Work type
Remote
Posted
Is this job info correct?
Show job description

๐Ÿ“ Remote | Full-Time (Independent Contractor Role)

๐Ÿ“… Immediate or short-notice availability preferred


About the Role


We build and maintain bespoke software systems for clients across a range of industries. Our portfolio spans modern TypeScript-based platforms (NestJS APIs, Next.js portals, customer-facing web applications) alongside established vanilla JavaScript systems that still need ongoing development and feature extension. No two projects are identical. The work shifts between greenfield features, legacy maintenance, third-party integrations and platform operations.


We are looking for a mid-level developer who is comfortable across the full stack. You will own features end-to-end: designing the API contract, writing the backend service, building the UI, integrating third-party providers, writing tests and shipping. Security, code quality and production stability matter here as much as feature delivery.


This is a lean team. You will have real ownership and real impact, and equally real accountability. To us, mid-level means you have done this before, can work independently on well-scoped tasks, and know when to ask for direction instead of guessing.


Key Responsibilities

Backend Development:

  • Build and maintain REST API endpoints using NestJS on a Fastify runtime, following established module, service, and guard patterns
  • Write and update data models and coordinate schema changes against relational databases; experience with Prisma ORM is directly applicable though the underlying database engine varies by project
  • Design and implement scheduled cron jobs, webhook dispatch pipelines, and background processing tasks
  • Integrate with third-party REST and SOAP services, including identity verification bureaus, AML screening providers, document fraud detection services, payment gateways and transactional email platforms
  • Implement and maintain authentication and authorisation logic: JWT (EdDSA), OAuth2 with PKCE, API key management, TOTP and email-based MFA, and role-based access control
  • Generate PDF reports from templated HTML sources using a headless browser pipeline (Puppeteer + Handlebars)
  • Manage file uploads and downloads via cloud blob storage, enforcing correct access controls and path-ownership rules
  • Expose and maintain accurate Swagger/OpenAPI documentation as the authoritative API contract for consuming frontends


Frontend Development:

  • Build and maintain pages and components across React/Next.js applications using both the Pages Router and App Router; work within PrimeReact component systems without introducing new UI libraries or breaking established patterns
  • Contribute to vanilla JavaScript applications: extending features, fixing bugs and improving existing code without the aid of a frontend framework
  • Manage application state appropriately for the project at hand, whether that is Redux Toolkit, Zustand, or straightforward local state
  • Implement form-heavy workflows including multi-step wizards, document upload flows, and structured data review screens with proper validation
  • Connect frontend features to backend APIs, handling loading states, error boundaries and pagination correctly and consistently across different project architectures
  • Integrate real-time push updates via Socket.IO for system notifications and live data feeds where the project requires it
  • Handle document capture and upload flows requiring client-side image processing (file type conversion, cropping, drag-and-drop)


Security & Compliance:

  • Apply security best practices throughout: input validation and sanitisation, CSRF protection, CORS configuration, Content Security Policy with per-request nonces and rate limiting
  • Handle sensitive personal, identity and financial data with appropriate care: correct encryption in transit and at rest, and no logging of sensitive fields under any circumstances
  • Understand and maintain shared encryption contracts between services (symmetric token encryption, HMAC-signed session cookies) where they exist in a project
  • Review your own work for OWASP Top 10 vulnerabilities before submitting for code review; do not ship security decisions that you cannot explain
  • Identify and respect critical configuration and files that must not be arbitrarily modified. Business-critical constants and encryption artefacts carry production consequences across every environment


Testing & Code Quality:

  • Write unit tests (Jest / Vitest) for new services and components, and integration/e2e tests (Playwright, supertest) for critical user flows
  • Run builds in affected repos before submitting changes; resolve TypeScript and lint errors rather than suppressing them with comments
  • Participate in code review constructively on both sides: give useful feedback, receive it without defensiveness, and apply it consistently
  • Test the golden path and meaningful edge cases before marking any task done; do not hand off broken flows for QA to find


Infrastructure & Operations:

  • Understand and follow CI/CD pipelines (typically GitHub Actions) across multiple deployment environments; respect branch-to-environment mappings and do not promote changes carelessly
  • Work comfortably across multiple repositories and multiple active projects; coordinate changes that span more than one system and communicate API contract changes proactively
  • Monitor deployed behaviour after releases; investigate and resolve production issues independently where the scope is clear, and escalate promptly where it is not


Technical Requirements

Must Have:

  • TypeScript: 3+ years writing it daily, not just tolerating it
  • Vanilla JavaScriptโ€‹: able to work in and extend non-framework codebases without reaching for a bundler or library
  • Node.js backend development with a structured framework (NestJS strongly preferred)
  • React and Next.js: comfortable with both the Pages Router and App Router paradigms
  • Relational databases: SQL queries, schema design and at least one ORM; experience with multiple database engines is a plus
  • REST API design: request validation, error contracts and OpenAPI documentation
  • Authentication: JWT, OAuth2 flows and session management fundamentals
  • Git: meaningful commit history, branch strategy, pull requests and conflict resolution
  • Security basics: CORS, CSRF, input sanitisation and awareness of OWASP risks
  • Third-party API integration: REST and ideally SOAP/XML services
  • Reading and working confidently within an existing, unfamiliar codebase


Beneficial:

  • SQL Server, PostgreSQL or MySQL in a production context
  • Cloud deployment: Azure App Service, Blob Storage or equivalent AWS/GCP services
  • NestJS internals: modules, providers, guards, interceptors, custom decorators
  • Socket.IO: both server-side emission and client-side subscription
  • Headless browser tooling: Puppeteer or Playwright for PDF generation or testing
  • GitHub Actions: reading and maintaining CI/CD workflows
  • PrimeReact component library at production scale
  • Redux Toolkit or Zustand for non-trivial state management
  • Testing tools: Jest, Vitest, Playwright, supertest
  • Applied cryptography: symmetric encryption, HMAC etc.
  • Transactional email delivery (SendGrid or equivalent API)


Core Stack:

  • TypeScript
  • Vanilla JS
  • Node.js
  • NestJS
  • React / Next.js
  • Relational DB
  • Prisma
  • REST APIs
  • JWT / OAuth2
  • Git


Beneficial:

  • PrimeReact
  • Socket.IO
  • Zustand
  • Redux Toolkit
  • Azure / Cloud
  • GitHub Actions
  • Puppeteer
  • Jest / Vitest
  • Playwright
  • SendGrid


Non-Technical Expectations:

  • Ownership. If you committed the code, you own its behaviour in production, not only at the point of merge. You follow up on the issues you shipped and see them through.
  • Clear written communication. We are remote-first and async-first, so ambiguity gets expensive quickly. You write clearly, summarise context you have that others do not, and flag blockers before they turn into delays.
  • Self-directed scoping. Given a feature description, you can identify what is unclear, ask the right questions and estimate roughly how long something will take. Nobody should need to break the work down into hours for you.
  • Multi-project adaptability. You can context-switch between a modern TypeScript platform and a vanilla JavaScript application without losing productivity. Each project has its own conventions, and you work within them instead of imposing your own.
  • An interest in security. Across our projects, security is not optional. A specialisation is not required, but you should care about getting it right and apply OWASP principles as a matter of habit.
  • Integration confidence. You can read a Swagger spec, work with a poorly documented API, interpret a SOAP WSDL and integrate a third-party service without significant hand-holding.
  • Production respect. You treat production like a shared resource. You do not push speculative changes to live environments, and you understand that failures in business-critical systems have real consequences for our clients.
  • Timesheet updates. You are expected to maintain your timesheet entries weekly with details of tasks and features delivered


If you are interested in this role, please apply via LinkedIn or contact hr@cloudmaven.com directly.

Similar jobs

Apply on LinkedIn