← Jobs

Full-Stack Engineer | Multi-Tenant Compliance SaaS | Next.js, TypeScript, Supabase

Budget: $5.0 - $15.0 HOURLY / PART_TIME ⭐ 0.00 (0) Australia

react-js, node.js, javascript, tailwind-css-framework, next.js, typescript, laravel-framework, web-design, web-application, software-development

Preferred qualifications

  • Experience: Intermediate
  • English: Conversational
We are building an existing multi-tenant B2B SaaS platform for Australian AML/CTF compliance. The platform is initially focused on regulated professional-services businesses, beginning with real estate, accounting and lawyers which fall under what AUSTRAC call Tranche 2 - in future, development will include tapping into Tranche 1 businesses such as Gaming, FinTechs, financial institutions, etc. The web app guides users through customer onboarding, KYC and KYB, identity verification, AML screening, risk assessment, enhanced due diligence, approvals, ongoing reviews and compliance evidence. This is not a greenfield prototype. A substantial application, database schema and security foundation already exist. AI-assisted development has allowed us to move quickly, but it has also introduced architectural and implementation inconsistencies across parts of the product. Some newer interface flows do not reliably reuse the authoritative backend, workflow logic and shared components already in place. We are looking for an experienced engineer who can understand the existing system, identify what should be retained or corrected, and help turn it into a coherent, secure and production-ready product. Current stack - Next.js - React - TypeScript - Vercel - Supabase - PostgreSQL - Supabase Auth - Row-Level Security - Database migrations - Tailwind CSS - Third-party APIs and webhooks - Vitest and Playwright - Product and architecture The platform includes or is intended to include: - multi-tenant organisations and offices; - role-based permissions; - customer and case management; - KYC and KYB workflows; - identity, biometric and liveness verification; - PEP, sanctions, watchlist and adverse-media screening; - beneficial-ownership and control information; - configurable risk-assessment templates; - explainable risk outcomes; - enhanced due-diligence workflows; - peer review and approval controls; - audit trails and compliance evidence; - ongoing customer reviews; - operational and regulatory reporting; - plan entitlements, usage allowances and billing; - provider-neutral third-party integrations. AI will be introduced as an assistive capability for explanations, drafting, document review, reporting and compliance guidance. It must not autonomously make regulated customer or compliance decisions. What we need help with The initial engagement would involve reviewing the existing application and helping us determine: 1. what should be retained, refactored or replaced; 2. where frontend workflows are disconnected from persisted backend state; 3. whether tenant isolation and RLS are implemented correctly; 4. where business logic has been duplicated; 5. how provider integrations and webhooks should be structured; 6. whether the current database and migration model is maintainable; 7. where shared components and design patterns are not being reused; 8. what should be prioritised for a controlled production release; 9. how future work should be divided into smaller, testable delivery slices. We are not looking for someone to immediately propose a full rewrite but may consider it. We want an engineer who can work within an existing brownfield product, understand the business and regulatory context, challenge unnecessary features, and take ownership of outcomes rather than simply completing isolated tickets. Strong candidates will have experience with - production Next.js and TypeScript applications; - Supabase and PostgreSQL; - complex RLS and multi-tenant data isolation; - authentication and role-based access control; - long-running or stateful workflows; - webhook processing, retries and idempotency; - audit logging and immutable evidence; - third-party API integrations; - background processing; - testing secure and regulated workflows; - improving an existing codebase without unnecessary rewrites; - product design or design-system implementation. Experience in RegTech, fintech, identity verification, compliance software or other regulated systems would be valuable but is not mandatory. How we would like to begin We expect to start with: 1. a discovery call; 2. a small paid technical and product audit; 3. a written assessment of the main risks and opportunities; 4. a proposed sequence of narrow implementation slices. Please include: 1. examples of relevant SaaS products you have shipped; 2. your experience with Supabase RLS and multi-tenant systems; 3. an example of an existing application you inherited or stabilised; 4. how you would approach the first audit; 5. your availability and preferred engagement structure. We value direct communication and honest product judgement. We would rather work with someone who tells us a feature is not worth building than someone who implements everything without questioning it. Thanks!
Open job

AI proposal draft

Generate a short cover letter to copy into the offer. Says you are interested and ready to work.

Sign in to generate an AI proposal draft.

Log in