Senior Full-Stack / Backend Engineer - Saas Production Readiness & Security
Budget: $15.0 - $50.0
HOURLY / FULL_TIME
⭐ 0.00 (0)
AUS
javascript, devops, git, react-js, postgresql
Preferred qualifications
- Experience: Expert
- English: Fluent
- Job Success: 90%+
- Rising Talent preferred
About the project
Cawnect is a workplace injury and return-to-work management SaaS platform designed to connect employers, healthcare providers, insurers and injured workers within a secure shared environment.
The application MVP has been built using Lovable, React/TypeScript and Supabase and is now largely functionally complete.
We are looking for an experienced senior engineer to help transition the application from an MVP/prototype environment into a secure, scalable, production-ready application.
The platform will handle sensitive healthcare, workplace injury and company information, so security, privacy, access control and data isolation are critical.
This is not a greenfield build. The initial engagement will involve reviewing the existing application and architecture, identifying issues and risks, recommending the appropriate production architecture, and implementing the agreed changes.
Technology
Current stack includes:
React / TypeScript
Lovable
Supabase
PostgreSQL
Supabase Auth
Row Level Security (RLS)
Database functions / RPCs
GitHub / version control
Experience working with Lovable-generated applications and Supabase would be highly regarded.
Initial Scope
1. Technical & Architecture Review
Review the existing:
Front-end architecture and codebase
Supabase/PostgreSQL database
Database schema and relationships
Authentication and user onboarding
Organisation and role architecture
RLS policies
Database functions and RPCs
SECURITY DEFINER functions
API/database access from the client
Storage configuration
Environment variables and secrets
Third-party integrations
Current deployment architecture
Provide recommendations on what should be retained, refactored or replaced before production.
2. Security Review
Perform a security-focused review including:
Authentication and authorisation
Role-based access controls
Cross-organisation data isolation
RLS policy coverage and bypass risks
IDOR / unauthorised object access
Privilege escalation
SECURITY DEFINER functions
Service-role key exposure
API security
Storage bucket permissions
Sensitive data exposure
Secrets management
Logging of sensitive information
Session/token management
A particularly important requirement is ensuring that users from one organisation cannot access patient, employer, provider or insurer information belonging to another organisation unless explicitly authorised through the application's case/care-team model.
3. Privacy & Sensitive Data Architecture
Review the technical architecture with consideration for the handling of sensitive healthcare and workplace information.
We would like the application architecture to support compliance with relevant Australian privacy and security requirements, including the Australian Privacy Principles.
We understand that technical review does not replace formal legal or compliance advice.
4. Supabase / Production Migration
Assist with establishing a clean production environment under company-controlled accounts.
This may include:
Supabase organisation/project setup
Development, staging and production environments
Database migration
Schema migration
RLS migration and testing
Authentication configuration
Storage configuration
Environment/secrets configuration
GitHub repository setup
Deployment configuration
Backup strategy
Recovery procedures
The business must retain ownership and administrative control of all production infrastructure, source-code repositories, domains and accounts.
5. Production Readiness
Review and implement appropriate:
Error monitoring
Application logging
Database monitoring
Backups
Recovery procedures
Performance monitoring
Security monitoring
Deployment processes
CI/CD where appropriate
Production/staging separation
6. Testing
Develop or implement testing for critical security and application workflows, particularly:
Organisation isolation
User permissions
Employer access
Healthcare provider access
Insurer access
Claims manager access
Injured worker access
Invitation/onboarding workflows
Case access
Document access
Messaging
File/storage access
We would also like recommendations regarding independent penetration testing prior to onboarding production customers.
Initial Deliverables
The first stage of the engagement should produce:
Technical architecture assessment
Security assessment
Prioritised list of identified issues
Recommended production architecture
Migration plan
Production-readiness checklist
Estimated implementation scope, timeline and cost
We would then expect the successful engineer to assist with implementing the agreed recommendations.
Required Experience
Strong experience with:
Supabase
PostgreSQL
Row Level Security
React
TypeScript
Authentication and authorisation
Multi-tenant SaaS applications
Backend/API security
Database migrations
Production SaaS deployments
Git/GitHub
Security best practices
Highly Regarded
Experience with:
Healthcare applications
Sensitive personal information
Australian privacy/security requirements
Lovable
Supabase Edge Functions
Security auditing
Penetration testing
SOC 2 / ISO 27001-aligned environments
Taking founder-built or low-code MVPs into production
Engagement
We are initially looking for a fixed-scope technical and security review, followed by an implementation engagement based on the findings.
There is potential for an ongoing relationship as the platform progresses through initial customer onboarding and commercial launch.
We are looking for someone who can operate at a senior technical level, challenge existing architectural decisions where necessary, explain technical issues clearly to a non-technical founder, and take ownership of delivering a robust production environment.
When Applying
Please provide:
Examples of Supabase applications you have worked on
Your experience designing/testing PostgreSQL RLS
Examples of multi-tenant SaaS platforms you have worked on
Experience with security-sensitive applications
Experience taking an MVP into production
Your proposed approach to the initial technical/security review
Availability
Hourly/day rate or proposed fixed price for the initial assessment
Open job
AI proposal draft
Generate a short cover letter to copy into the offer. Says you are interested and ready to work.
Sign in to generate an AI proposal draft.
Log in