Senior Full-Stack Engineer

๐Ÿข Hairball.IO ยท all Hairball.IO jobs
๐Ÿ“ Worldwide
๐Ÿ“… Posted 2026-07-29 ยท via Himalayas
๐Ÿท Full-Stack-Engineer,Software-Engineer,SaaS-Engineer,Backend-Engineer,Frontend-Engineer,Senior-Full-Stack-Engineering,Senior-Fullstack-Developer,Senior-Full-Stack-Engineer-(React-Node.Js),Senior-Fullstack-+-DevOps-Engineer
Apply on original site โ†—

About Hairball

Hairball.io is an Inc. 5000 e-commerce integration consultancy with 550+ client relationships in

the Shopify, NetSuite, and Celigo ecosystem. We are building a new AI-powered SaaS product

for our market. Details about the product will be shared during the interview process.
The Role

We need a senior full-stack engineer to build the multi-tenant platform foundation for a new

SaaS product over a 6-month contract engagement. You will be the primary architect and

builder of the core infrastructure. A junior JavaScript developer on the team will work alongside

you, learning the stack and eventually owning day-to-day development after your engagement
ends.

This is a founding-level role. You are not joining a team โ€” you are building the platform that a

team will grow around. The architecture decisions you make in the first 8 weeks will shape this
product for years.
What You Will Build
Months 1-2: Platform Spine

- Multi-tenant database schema with PostgreSQL Row-Level Security (RLS) enforcement

on every tenant-scoped table

- Authentication integration with Clerk, including multi-organization switching (one user,

many tenants)

- Role-based access control for six user roles with JSONB-based extensible permissions

and ABAC extensions

- API call logging pipeline with full attribution chain (tenant โ†’ service โ†’ execution โ†’

result)
- Super Admin and Tenant Admin interfaces

Months 3-4: Billing & Integrations

- Stripe Billing integration: subscriptions, metered usage-based pricing, Customer Portal

- External API integration pipeline with encrypted credential storage per tenant

- Connection management UI for tenant-managed third-party credentials

- Configuration inheritance system: platform defaults โ†’ tenant overrides โ†’ user

preferences
- Feature flag and module entitlement system for gating product capabilities per plan

Months 5-6: Hardening & Handoff

- Security hardening: immutable audit trails, environment separation (sandbox +

production per tenant)

- Performance optimization and production readiness review

- Architecture Decision Records (ADRs) and documentation for the team inheriting the

codebase
- Code review and mentoring of the junior developer to ensure smooth transition

Technology Stack
Layer
Technology
Notes
Framework
Next.js 14 App Router + TypeScript
Hosted on Vercel
Database
PostgreSQL 16+ (Neon)
Drizzle ORM. RLS is non-negotiable.
Cache / Queue
Upstash Redis
Job queuing, rate limiting
Auth
Clerk
Multi-organization support required
AI
Anthropic Claude (primary)
Multi-LLM gateway planned
Billing
Stripe Billing
Subscriptions + usage-based
metering
CI/CD
GitHub + Vercel
Branch-based deploys, PR workflow
Required Experience

These are non-negotiable. If you have not done these things in production, this is not the right
role.

- Multi-tenant SaaS architecture: You have personally built (not just contributed to) a

multi-tenant application with tenant data isolation. You understand the difference

between application-level tenant filtering and database-level enforcement.

PostgreSQL Row-Level Security: You have implemented RLS policies in production.

You know how to set tenant context per transaction and test for cross-tenant data
leakage.

Next.js 14+ App Router: You are current with App Router (not Pages Router). You

understand server components, server actions, route handlers, and middleware.

TypeScript: You write TypeScript fluently, not JavaScript with type annotations bolted
on.

Stripe Billing integration: You have wired up subscriptions, handled webhooks with

signature verification, and implemented metered/usage-based billing.

Multi-org authentication: You have implemented multi-organization auth (Clerk, Auth0,

or similar) in a SaaS product. You understand session scoping per organization.
Strongly Preferred

Experience with Drizzle ORM (or Prisma with willingness to learn Drizzle)

AI/LLM application development

โ† All remote jobs