Kontrora PSA is a professional services automation platform β a full-stack internal operations system used by agencies and consultancies to manage projects, time tracking, capacity planning, visual workflows, client portals, analytics, and role-based access control. The architecture is a Next.js 15 front end (App Router, React Server Components) communicating with a dedicated Express.js REST API server running on port 4000. That API layer handles all business logic, authentication, and database operations β it's not a Next.js API route setup, it's a proper standalone Express server that can run independently and be scaled separately from the front end. The database is Supabase (PostgreSQL) with Row Level Security enforced at the database level, not just in application code. Auth is handled via Supabase JWT tokens passed as cookies between the Next.js client and the Express API. You'll work across this entire system β designing schemas, writing RLS policies, building Express route handlers with Zod validation, and shipping polished React UIs. This is a high-ownership role on a small team: you take features from design to production with minimal hand-holding, and your work reaches real users immediately.
Responsibilities
- Build and maintain Express.js REST API endpoints on port 4000 β route handlers, middleware, request validation with Zod, and structured error responses
- Design PostgreSQL schemas in Supabase with proper indexing, foreign keys, and Row Level Security policies that enforce multi-tenant data isolation
- Implement authentication flows: Supabase JWT verification in Express middleware, cookie handling, session management, and role-based permission checks
- Build React components and pages in Next.js 15 using the App Router β understanding when to use Server Components vs. Client Components for performance
- Manage client-side state with Jotai and server state/caching with SWR, keeping the UI fast and consistent
- Integrate third-party services through the Express API layer: SMTP for transactional email, Supabase Storage for file uploads, and webhook endpoints
- Write clean, well-typed TypeScript across both the Next.js front end and the Express API β shared types, strict null checks
- Participate in architecture decisions β the Express/Next.js split, API versioning, caching strategy, and RLS policy design
- Debug production issues across the full stack: React rendering bugs, slow PostgreSQL queries, Express middleware ordering problems
Requirements
- 3+ years of professional full-stack experience with React/Next.js and Node.js/Express
- Strong TypeScript skills across both front end and back end
- Solid Express.js experience: routing, middleware, error handling, and building production-grade REST APIs
- Solid PostgreSQL knowledge: schema design, joins, indexes, transactions, and query optimization
- Understanding of JWT-based authentication, cookie security, and how auth flows work across a separate API server and front end
- Experience with Supabase or similar BaaS platforms, especially Row Level Security
- Comfortable working in a remote-first, async environment with high autonomy
Nice to Have
- Experience with Next.js App Router and React Server Components
- Experience building multi-tenant SaaS applications with database-level isolation
- Jotai or Zustand state management experience
- Open source contributions demonstrating full-stack ownership