Nomad is building the financial operating system for fleets: fuel cards, real-time transaction processing, invoicing, and working‑capital finance, increasingly automated by production AI. We are a small, fast‑moving team that cares deeply about doing right by our customers, which in our business means getting the numbers exactly right, every time.

About you

You are a passionate and resourceful Senior Full Stack Engineer who thrives in a fast‑paced, collaborative environment. You have a strong foundation in both front‑end and back‑end technologies and are excited about building impactful, scalable applications from the ground up. With a keen eye for detail and a commitment to delivering high‑quality, secure code, you enjoy solving complex problems and are always looking for ways to improve processes and performance. You treat client information with care and understand that strong documentation and disciplined controls are part of building software people can trust.

Key Responsibilities

  • Design, develop, and maintain secure REST APIs using Node.js.
  • Architect and implement cloud solutions using Google Cloud Platform (GCP) services, particularly Compute Engine, Cloud CDN, and Identity Platform.
  • Collaborate with front‑end teams to develop user‑centric applications using React.
  • Review code and provide technical guidance to team members.
  • Troubleshoot and resolve production issues.

Security & Data Protection

  • Implement and maintain security best practices across the application stack.
  • Handle client and customer information in accordance with Nomad’s information security and data protection policies, protecting the confidentiality, integrity, and availability of client data.
  • Apply the principle of least privilege when designing, granting, and reviewing access to systems, data, and production environments.
  • Manage application secrets, credentials, and encryption keys securely.
  • Identify, triage, and remediate security vulnerabilities, including timely patching and dependency updates.

Change Management

  • Manage CI/CD pipelines through Bitbucket and related DevOps tools.
  • Follow defined change management processes, including peer code review, testing, and documented approval before changes are released to production.
  • Maintain separation between development, testing, and production environments and ensure deployment controls are enforced.
  • Implement and maintain logging, monitoring, and alerting across applications and infrastructure.
  • Participate in incident detection, response, and post‑incident reviews, and escalation procedures in line with Nomad’s incident response policy.

Documentation

  • Create and maintain accurate, current technical documentation, including system architecture, data flows, API specifications, and security configurations.
  • Document all production changes, deployments, access grants, and security‑relevant decisions so that they can serve as audit evidence.
  • Maintain runbooks and operational procedures for the systems this role supports.
  • Adhere to and help maintain IT and engineering controls relevant to SOC 2, including change management, logical access control, secure SDLC, and vulnerability management.
  • Support SOC 2 and other audits by providing requested documentation and evidence within agreed timelines.
  • Escalate decisions that materially affect security posture or client data to the Chief Product Officer.

Required Qualifications & Skills

Programming & Development

  • 5–7+ years of professional software development experience.
  • Express.js or similar frameworks for API development.
  • Asynchronous programming patterns and event‑driven architecture.
  • Node.js clustering and PM2 for process management.
  • Proficiency in the npm ecosystem and package management.
  • TypeScript type system, interfaces, and generics.
  • Unit testing with Jest or Mocha.

Front‑end Development with React, including:

  • Building and maintaining single‑page applications using React.
  • React hooks, state management, and lifecycle methods.
  • Integration of RESTful APIs and real‑time data streams.
  • Component‑driven architecture and reusable UI components.

Demonstrated Google Cloud Platform (GCP) expertise, including:

Identity Platform

  • User management and authentication workflows.
  • Implementation of OAuth2 flows.
  • Custom authentication rules.
  • JWT token handling and validation.

Compute Engine

  • Instance groups and auto‑scaling.
  • VPC networking and firewall rules.
  • Custom image creation and management.
  • Cache optimization strategies.

Security & API Development

  • Deep understanding of web security, including OAuth 2.0 and OpenID Connect protocols.
  • JWT implementation and validation.
  • XSS, CSRF, and SQL injection prevention.
  • Rate limiting and DDoS protection.
  • Security headers and CORS configuration.
  • Request validation and sanitization.
  • Error handling and status codes.
  • API documentation (Open API/Swagger).

Security, compliance and documentation practices, including:

  • Familiarity with SOC 2, ISO 27001, or comparable compliance frameworks.
  • Experience working within formal change management and audit‑evidenced environments.
  • Producing and maintaining clear technical and operational documentation.

Bitbucket pipeline expertise, including:

  • Integration with third‑party tools.
  • Repository maintenance and organization.

Preferred Qualifications

  • Experience supporting SOC 2, ISO 27001, or similar compliance audits.
  • Experience with microservices architecture.
  • Knowledge of container technologies (Docker, Kubernetes).
  • Familiarity with infrastructure as code (Terraform, Cloud Deployment Manager).
  • Experience with monitoring and logging tools.
  • Background in agile development methodologies.

What We Offer

  • Flexible work schedule.
  • Growth and development opportunities.
  • Team outings and social events.
  • Excellent extended medical, dental, and vision benefits plan.

#J-18808-Ljbffr

Full Stack Engineer

Apply Now
Back to search page