
Full Stack Engineer with AWS Knowledge — People Pulse
- ₹8L – ₹15L • No equity
- |Remote (India •)
- |5 years of exp
- |Full Time
Remote only
Not Available
About the job
People Pulse is an HR SaaS software that helps companies manage their people operations — from performance workflows to org-wide reporting — securely and at scale. We're hiring a Full-Stack Engineer to join our core engineering team and own the application layer of our platform.
You'll take our working prototype to production: server-enforced authorization, encrypted sensitive fields, SSO, and a live API-backed SPA replacing client-only demo state.
Architecture You'll Work In
- Browser (React SPA) ↓ HTTPS / JWT session Express API (Node.js) ↓ per-request tenant context + transaction PostgreSQL (RLS-enforced, org-scoped) ↓ envelope encryption for sensitive fields KMS → AES-GCM sidecar storage
Auth: Okta OIDC (Auth Code + PKCE) → server-issued JWT
Deploy: GitLab CI/CD (OIDC) → Docker → ECR → ECS Fargate
Frontend host: S3 + CloudFront
Database: RDS PostgreSQL 15 + RDS Proxy (SSL)
Poly-repo layout: separate repositories for API, web SPA, SQL migrations, and infrastructure (Terraform). Release order: migrations → API → frontend → infra.
Multi-Tenancy & Authorization Model
Each HTTP request sets org context in a DB transaction; row-level security policies enforce access — the client cannot widen scope.
Server-enforced RBAC with role-scoped data (group assignment, management chain, field-level stripping for certain roles, aggregate-only views for executives). Separation of duties: no self-review or self-approval.
Tech Stack
- Node.js 20 (ES modules), Docker (node:20-alpine)
- Express 4, CORS, Morgan, dotenv
- PostgreSQL 15, pg driver, RLS, RDS Proxy, versioned SQL migrations
- JWT, bcryptjs, Okta OIDC (Auth Code + PKCE), group→role mapping
- AWS KMS, AES-GCM, per-tenant DEK wrapping, encrypted field sidecar tables
- React 18, Vite 5, JSX
- lucide-react, Recharts, xlsx export
- ECS Fargate, ALB, ECR, RDS, S3, CloudFront, KMS, Secrets Manager
- GitLab CI/CD with OIDC (no long-lived AWS keys)
- Terraform ≥ 1.5 (coordination with platform engineer, not primary ownership)
Responsibilities
- Design and implement the production REST API — routing, middleware, error handling, transaction management
- Build PostgreSQL schema and migrations — tables, indexes, RLS policies, tenant context functions
- Implement server-enforced RBAC — role-scoped queries, field-level visibility rules, management-chain derivation, audit logging
- Own authentication and sessions — OIDC callback flow, JWT issuance/validation, session rotation, JWKS verification
- Build field-level encryption — KMS envelope encryption, encrypt/decrypt service, sidecar storage pattern
- Develop the React SPA — complex forms, role-based navigation, client-server state sync, live API cutover from demo/local storage
- Implement domain lifecycle endpoints — create, submit, approve, calibrate (with reason + audit trail), export
- Maintain Docker images and coordinate ECS deployments via GitLab pipelines
- Write API documentation and contribute to security/compliance evidence (RBAC matrix, data-flow descriptions)
- Collaborate with integrations engineer on API surfaces for external sync and OAuth token storage
- Collaborate with platform engineer on RDS, KMS keys, secrets, and deploy health
Requirements — Must Have
- 5+ years building production web applications with meaningful backend and frontend ownership
- Strong Node.js / Express — REST design, middleware, DB transactions
- Deep PostgreSQL — migrations, RLS, connection pooling, query optimization
- Strong React — complex state, role-scoped UI, form workflows beyond simple CRUD
- Security-first approach — never trust client for authorization; encrypt sensitive data; audit mutations
- JWT + OIDC/OAuth 2.0 experience (Okta, Auth0, Entra ID, or equivalent)
- Docker, containerized deploys, CI/CD (GitLab or equivalent)
- Comfortable working independently in a poly-repo with minimal process
Requirements — Strongly Preferred
- AWS application development: ECS, RDS, KMS, Secrets Manager, S3/CloudFront
- Multi-tenant SaaS with org-scoped data isolation
- Envelope encryption / KMS-wrapped DEK patterns
- Enterprise SaaS with complex RBAC and separation of duties
- Terraform literacy
Nice to Have
- SOC 2 or enterprise security review experience
- HR/people-systems domain knowledge
- LLM API integration in production apps
You'll be a core member of our engineering team, working directly on the product — not a shared client project. We're a small team, so you'll have real ownership over the API, database, and frontend, and direct input into architecture decisions as we build out our security and compliance posture (including our ongoing SOC 2 work).
About the company

People Pulse
Similar Jobs





