We are seeking an Exploration Full-Stack Engineer to deliver feature and maintenance work across the explorer platform and live events product within the Exploration Pod. In this role, you will own API security hardening, dependency vulnerability remediation, and feature delivery across two products that share a common Next.js + NestJS + CMS architecture. The ideal candidate is a confident TypeScript engineer who can context-switch efficiently between products and takes security and reliability as seriously as feature delivery.
Responsibilities
-
Deliver feature work and bug fixes across the explorer platform and live events product
-
Maintain and extend NestJS API services, including data access layers and external service integrations
-
Contribute to CMS schema work and content model maintenance shared across both products
-
Implement rate limiting on the live events API to address identified DDoS risk
-
Harden webhook endpoints with HMAC authentication across both products
-
Triage and remediate the 1000+ dependency vulnerabilities identified in the live events product
-
Apply dead-letter queue and retry patterns to Lambda workers and async processors
-
Write and maintain unit, integration, and E2E tests to meet coverage gate targets
-
Participate in code reviews and contribute to engineering standards within the pod
-
Collaborate with the Integration Engineer on fan-out write patterns and Kafka consumer reliability
-
Work with the Business Analyst to refine stories before sprint planning
Requirements
-
2+ years of professional software engineering experience
-
Proficiency in Node.js, TypeScript, and NestJS
-
Skills in Next.js (App Router + Pages Router)
-
Background in AWS services, including ECS, Lambda, and SQS
-
Expertise in Confluent Kafka, PostgreSQL, and Terraform
-
Familiarity with Sanity Studio v5, Algolia, and Cloudinary
-
Understanding of API security practices, including rate limiting and HMAC authentication
-
Knowledge of async processing patterns such as dead-letter queues and retry mechanisms
-
Competency in writing unit, integration, and E2E tests to meet coverage targets
-
Experience using AI coding assistants for day-to-day feature development, security fix implementation, and dependency vulnerability triage
-
Ability to use AI tools to accelerate large-scale dependency remediation — automated upgrade scripts, breaking change analysis, and regression identification
-
Interest in AI-assisted code review — using LLM-based tools to catch security and quality issues before human review
-
Proficiency in English at an Upper-Intermediate level (B2) or higher
We offer
-
International projects with top brands
-
Work with global teams of highly skilled, diverse peers
-
Healthcare benefits
-
Employee financial programs
-
Paid time off and sick leave
-
Upskilling, reskilling and certification courses
-
Unlimited access to the LinkedIn Learning library and 22,000+ courses
-
Global career opportunities
-
Volunteer and community involvement opportunities
-
EPAM Employee Groups
-
Award-winning culture recognized by Glassdoor, Newsweek and LinkedIn
EPAM is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, protected veteran status, or any other characteristic protected by applicable law.