Job Description
Company Description
Hamhey Corp is revolutionizing the relocation experience by building the world’s first fully AI-powered platform designed for international students and expats. Unlike traditional platforms, Hamhey manages the entire relocation process—from housing and paperwork to banking and legal assistance—all within a single, secure platform. By leveraging AI, the platform automates complex processes while providing personalized, hands-on support. The company's mission is to empower individuals to move abroad confidently by removing uncertainty, complexity, and risks from the relocation journey.
Role Description
Technology Stack & RequirementsRequired Technical Skills- 5+ years software development
- Strong TypeScript/JavaScript
- Next.js and React
- Node.js backend development
- Secure coding practices
- API security (authentication, authorization, encryption)
- Third-party API integration
- Code review and quality standards
- Performance optimization
- Production deployment experience
- WhatsApp Business API integration
- Other messaging APIs (SMS, email, push)
- Payment gateway integrations (Stripe)
- OAuth and authentication flows
- Webhook implementation
- Rate limiting and throttling
- Security auditing
- Code quality tools (ESLint, SonarQube, etc.)
- CI/CD pipelines
- Monitoring and logging
- Write performant, maintainable code
- Optimize algorithms and data structures
- Implement caching strategies
- Optimize database queries
- Reduce bundle sizes
- Implement lazy loading and code splitting
- Memory leak prevention
- Performance profiling and optimization
- Minimize API response times
- Optimize rendering performance
Code quality standards:
- Follow SOLID principles
- DRY (Don't Repeat Yourself)
- KISS (Keep It Simple, Stupid)
- Clean code practices
- Meaningful variable and function names
- Proper code documentation
- Apply security best practices
- Input validation and sanitization
- SQL injection prevention (Prisma ORM parameterized queries)
- XSS protection
- CSRF protection
- Authentication and authorization
- Secure password hashing (bcrypt)
- JWT token security
- API key management
- Secrets management (environment variables)
- Rate limiting implementation
- HTTPS enforcement
- Secure file uploads
- Data encryption at rest and in transit
- OWASP Top 10 compliance
Security practices:
- Regular security audits
- Dependency vulnerability scanning
- Security code reviews
- Penetration testing support
- GDPR compliance
- Data privacy protection
- Secure session management
- Component-based architecture
- Reusable modules and utilities
- Separation of concerns
- Single Responsibility Principle
- Dependency injection patterns
- Service layer architecture
- Repository pattern (where applicable)
- Factory patterns
- Plugin architecture for integrations
Modularity standards:
- Reusable UI components
- Shared business logic libraries
- API middleware modules
- Integration abstraction layers
- Configuration management modules
- Error handling utilities
- Validation schemas (Zod)
- Type definitions and interfaces
- Conduct thorough code reviews
- Ensure code quality standards
- Security review
- Performance impact assessment
- Architecture alignment
- Best practice compliance
- Testing requirements
- Documentation completeness
- Accessibility checks
- Mobile responsiveness
Code review checklist:
- Code quality and maintainability
- Security vulnerabilities
- Performance implications
- Test coverage
- Documentation quality
- Error handling
- Edge case handling
- Accessibility compliance
- Browser compatibility
- Mobile responsiveness
- Design and implement secure RESTful APIs
- Authentication mechanisms (NextAuth.js, JWT, OAuth)
- Role-based access control (RBAC)
- API rate limiting and throttling
- Request/response validation (Zod schemas)
- Error handling and logging
- API versioning
- CORS configuration
- API security headers
- Input validation
- Output sanitization
- API documentation (OpenAPI/Swagger)
API security features:
- Token-based authentication
- Session management
- Webhook security (signature verification)
- API key rotation
- Request signing
- Encryption for sensitive data
- Audit logging
- Access logging
Communication Integrations:
- WhatsApp Business API integration
- Send/receive messages
- Message templates
- Media sharing
- Webhook handling
- Status updates
- Notification delivery
- SMS service integrations (Twilio, Vonage, etc.)
- Email service integrations (Resend, SendGrid, AWS SES)
- Push notification services (Firebase, OneSignal, etc.)
Payment Integrations:
- Stripe integration (payments, subscriptions, Connect)
- Webhook handling for payment events
- Multi-currency support
- Payment method management
Other Integrations:
- Google Maps API (geocoding, autocomplete)
- AWS S3 (file storage, presigned URLs)
- Browser automation (Stagehand)
- PDF generation services
- QR code generation
- Document signing (SignWell, DocuSign, etc.)
- Analytics platforms
- Monitoring services (Sentry, LogRocket, etc.)
Integration requirements:
- Reliable error handling
- Retry mechanisms with exponential backoff
- Webhook security verification
- Rate limit handling
- Data synchronization
- Status tracking
- Logging and monitoring
- Fallback mechanisms
- Design scalable architecture
- Implement design patterns (Singleton, Factory, Observer, Strategy)
- Microservices architecture (where applicable)
- Event-driven architecture
- Clean architecture principles
- Domain-driven design (DDD)
- API gateway patterns
- Service layer patterns
Architecture responsibilities:
- System design
- Database schema design
- API design
- Integration architecture
- Scalability planning
- Performance optimization
- Security architecture
- Unit testing (Jest, Vitest)
- Integration testing
- API endpoint testing
- E2E testing support
- Test coverage maintenance
- Security testing
- Performance testing
- Load testing
- Error scenario testing
Testing standards:
- Minimum 80% code coverage
- Test-driven development (TDD) where applicable
- Integration test coverage
- API contract testing
- Security test cases
- Performance benchmarks
- Code documentation (JSDoc, TypeDoc)
- API documentation
- Integration guides
- Architecture documentation
- Security guidelines
- Best practices documentation
- Onboarding documentation
- Next.js 15 (App Router)
- React 19
- TypeScript 5.0+
- TailwindCSS
- shadcn/ui components
- React Hook Form + Zod validation
- Zustand for state management
- Next.js API Routes
- Node.js 18+
- TypeScript
- PostgreSQL 15+
- Prisma 6.0+
- NextAuth.js 4.24+
- Stripe (payments)
- AWS S3 (storage)
- Email services (Resend/Nodemailer)
- Socket.io (real-time)
- Google OAuth
- Various third-party APIs
- WhatsApp Business API setup and configuration
- Message sending (templates and free-form)
- Message receiving via webhooks
- Media message handling
- Message status tracking
- Template management
- Notification delivery
- Error handling and retry logic
- Rate limit management
- Secure webhook verification
Similar Jobs
Explore other opportunities that match your interests