
Closed
Posted
**CLIQ** · Remote (US) · 10–20 hrs/week · Contract with equity --- ## The short version CLIQ helps older adults keep control of their financial lives while giving the people who love them a way to help — without spying on them, and without taking their independence away. That "without" is the entire product, and it lives in the backend. We're looking for one experienced engineer, part-time, to own the security and backend surface of a product where getting authorization wrong is not a bug — it's a betrayal of the person we exist to protect. ## Why this role exists Our founder is non-technical by training and has built the product to this point with a rigorous AI-assisted engineering system: a normative backend specification where every rule carries an ID, contract tests keyed to those IDs, merge gates, and independent review passes. It has taken us further than it has any right to. What it cannot do is replace an engineer who has personally been on the wrong end of a security incident and thinks differently because of it. That's the gap. That's you. You will not be handed a vague mandate. You'll be handed a written spec with numbered rules and asked, first, to tell us where it's wrong. ## What you'd own **The authorization model.** CLIQ's rules about who can see and do what *are* the product, and their correctness is the job. You'd own that model in code: the pure policy functions, the explicit serializer field whitelists, the audit wrapper on every mutation. **Authentication.** We hand-rolled it, deliberately — sessions, magic-link email sign-in, staff password + TOTP, WebAuthn passkeys — on Node's built-in `crypto` with `@simplewebauthn` as the only third-party dependency in the path. It's built to a documented set of non-negotiables covering secret handling, enumeration, rate limiting, and auditing. You'd own it, review changes to it, and tell us honestly which parts of hand-rolling it were a mistake. **The credential-handling design.** Our highest-sensitivity workstream — masked rendering and credential storage — is deliberately gated behind a cryptographic design document that has not been signed off. Nothing ships there until the design is right. Being the person who writes and defends that document is the most consequential part of this job. **Data and schema.** Postgres via Drizzle, migrations, constraints that encode the rules rather than trusting the application layer to remember them. **The review bar.** Every change to a sensitive path gets your eyes. Realistically this becomes a meaningful share of your hours, and it should. **Optionally, mentorship.** We may sponsor a university capstone team on clearly separated, non-critical-path work. If mentoring is something you enjoy, there's room for it and we'd value it. If it isn't, that's completely fine — this role is technical ownership first. We would rather have your judgment than your management. ## Our stack - **TypeScript** end to end - **[login to view URL] 15** (App Router, route handlers — thin, no business logic in them) + **React 19** - **Drizzle ORM** + **Neon Postgres** - **Vitest**, including contract tests named after the spec rule they enforce - **Vercel** for deploys - Auth on `node:crypto` + `@simplewebauthn`. No Auth0, no NextAuth/Auth.js. - A Chrome extension (Manifest V3) as a second client surface House pattern, so you know what you're walking into: route handler parses and rate-limits → service function → pure policy function decides → explicit DTO serializer → mutation wrapped in an audit transaction. Business logic never lives in a route handler. Nothing is serialized by spreading a database row. ## What we need you to have **Required** - **5+ years building production backends**, with real ownership of something where a security failure had consequences — fintech, health, payments, identity, or similar. We care much more about the weight of what you've protected than the logo you protected it at. - **Deep, practiced application-security judgment.** Not "I've read the OWASP Top 10" — you've designed an authorization model, found the hole in someone else's, and can explain why a given design is wrong in terms of what an attacker actually does. - **Hands-on with authentication internals.** Session management, token design, password and secret handling, TOTP, and ideally WebAuthn/passkeys. - **Strong SQL and relational data modeling.** You reach for a database constraint before you reach for an application-layer check. - **Production TypeScript** and comfort in a modern [login to view URL] codebase. Deep [login to view URL] *specialization* isn't required — a strong backend engineer picks up the App Router quickly. Security judgment is the part we can't teach. - **You write.** Design documents, threat models, honest post-incident write-ups. Much of this role is producing artifacts a non-technical founder can act on. - **You write your disagreements down and you argue them.** A specification you think is wrong is a document you respond to, not a constraint you quietly work around. **Strongly preferred** - Applied cryptography: envelope encryption, key management and rotation, secure storage of third-party credentials. This maps directly to our gated workstream. - Experience with regulated or audited data — GLBA, SOC 2, HIPAA-adjacent, PCI. Not because we need a compliance officer, but because it shapes how you think about audit trails and data minimization. - Threat modeling as a practice you've actually run, not just read about. - Prior early-stage experience. You know what "good enough for now" means and, more importantly, where it must never apply. - Mentoring or code-review leadership with junior engineers or students. **Nice to have** - Drizzle specifically; Neon or another serverless Postgres - Chrome extension security (MV3 permissions, content-script isolation, message passing) - Prior work in eldercare, senior living, accessibility, or financial services for older adults **Explicitly not required** - A CISSP, OSCP, or any certification. We'll read your work, not your acronyms. - Frontend or design skills. - Willingness to manage people. - Full-time availability. This role is part-time by design and we mean it. ## Who this is right for You've spent years being the person in the room who asks "wait, who's authorized to do that?" — and you've been tired of being outvoted. Here, that question *is* the roadmap. Our hardest work is already gated behind a design document that doesn't exist yet, deliberately, because nobody has been able to write it well enough. You want scope disproportionate to your hours. You'd rather own a small, genuinely important surface completely than be one of nine engineers on a platform team. You care that the people this protects are, in many cases, not the people who chose to install it. That asymmetry should sit uncomfortably with you. It does with us — it's why the authorization model is written the way it is. ## Who this is wrong for - You want full-time work and are treating this as a bridge. Say so and we'll talk in a few months instead. - You need a large team, a mature platform, or someone else on call. - You'd rather ship fast than be right about permissions. Genuinely valuable instinct. Wrong product. - You want to build the AI assistant. That's a different role, later, deliberately. ## The honest part about money and stage We're pre-close on a **$750K seed round**. Cash is tight and we're not going to pretend otherwise. - **Rate:** `{{$XXX}}–{{$XXX}}/hr`, commensurate with experience. - **Hours:** starting at **10–12 hrs/week**, expanding to 16–20 on close if it's working for both of us. - **Equity:** meaningful, and negotiated openly — this is a founding-team-shaped role at a founding-team-shaped stage. - **Structure:** independent contractor engagement, papered before the first invoice, with a clear path to a larger role on close. - **Location:** fully remote, US. `{{Overlap expectation}}`. If the round closes on plan, this role expands. If you want the security co-founder conversation, we should have it — but we'd both rather have it after working together than before. ## How the process works Deliberately short. We know you have a job. 1. **Apply** — details below. No cover letter. 2. **45-minute conversation** with the founder. Product, stage, what you'd want to own, what you think is naive about our approach. 3. **Spec review (paid, ~2 hours, `{{$XXX}}` flat).** We send you a real excerpt of our backend specification under NDA. You tell us in writing what's wrong with it. This is the core of our process and we pay for it, because asking for free work is a bad way to start. 4. **90-minute technical conversation** walking through your critique and one design problem we're actually facing. 5. **Reference conversations**, then offer. Target: **under four weeks** from first conversation to offer. ## To apply Email **`{{email}}`** with the subject line **"Security & Backend — [your name]"** and include: 1. Your GitHub, LinkedIn, or a paragraph on what you've built — whichever tells the truth best. 2. **One paragraph** on a system you secured where getting it wrong would have hurt someone. What was the hardest authorization decision, and what did you decide? 3. Your hourly rate and realistic weekly availability. 4. Optional, and we'll read it first: something you've written about security — a post, a threat model, an incident retro, a strongly worded code review. No cover letter. Please don't send one. --- *CLIQ is an equal opportunity employer. We're building for people who are routinely underestimated, and we're aware of the irony if we ran hiring the same way. If you're excited about this and unsure whether you're qualified, tell us what you'd need to learn and apply anyway.*
Project ID: 40621740
69 proposals
Remote project
Active 1 day ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
69 freelancers are bidding on average $18 USD/hour for this job

Hi, Your focus on security, authorization, and long-term architecture immediately caught my attention. While my background is centered on building secure, scalable web applications rather than dedicated security engineering, I have 10+ years of backend development experience designing role-based access, authentication, API integrations, audit-friendly workflows, and production systems where data integrity and user permissions are critical. I've developed applications with complex authorization models, secure authentication, database constraints, and well-structured backend services. I value clean architecture, thorough code reviews, and documenting technical decisions, and I'm comfortable collaborating in specification-driven environments. I also appreciate your emphasis on getting security right before shipping features. I'd be happy to discuss how my experience aligns with your requirements and share relevant backend projects that demonstrate secure, scalable application development. If you're open to candidates with strong backend expertise and a security-first mindset, I'd welcome the opportunity to chat. Regards, iSync Z 03/08/2026
$12 USD in 40 days
8.1
8.1

Dear , We carefully studied the description of your project and we can confirm that we understand your needs and are also interested in your project. Our team has the necessary resources to start your project as soon as possible and complete it in a very short time. We are 25 years in this business and our technical specialists have strong experience in Web Security, Technical Writing, Cryptography, Node.js, PostgreSQL, Typescript, Backend Development, Security, Data Modeling, Incident Response and other technologies relevant to your project. Please, review our profile https://www.freelancer.com/u/tangramua where you can find detailed information about our company, our portfolio, and the client's recent reviews. Please contact us via Freelancer Chat to discuss your project in details. Best regards, Sales department Tangram Canada Inc.
$25 USD in 5 days
7.5
7.5

Your authorization model isn't just code - it's the difference between protecting an older adult's independence and betraying their trust. Getting permissions wrong here doesn't create a bug ticket; it creates real harm to vulnerable people who didn't choose to install your product. Approach: - Audit your current spec against OWASP ASVS and financial compliance patterns (SOC 2, GLBA), identifying gaps in session handling, enumeration attacks, and audit trail completeness - Rebuild the pure policy functions with explicit whitelist serializers and constraint-based Postgres schema via Drizzle, ensuring business logic never leaks into route handlers - Document the cryptographic design for credential storage and masked rendering with envelope encryption, key rotation strategy, and threat model for third-party integrations About Me: 15+ years in IT infrastructure & security, expert in emergency security repair, issue resolution, and server-side hardening, proven ⭐️⭐️⭐️⭐️⭐️ record. I've owned authorization models in fintech where a single permission escalation meant direct financial loss - designed RBAC with attribute-based constraints, enforced at the database level, not the application layer. P.S. Hand-rolling auth with node:crypto is viable, but ensure you're using constant-time comparisons everywhere and rate-limiting magic links per IP+email pair to prevent enumeration - most teams miss the second one until they're breached.
$15 USD in 20 days
5.3
5.3

Hello Dear! Greetings from Toriqul Global Solutions! We are pleased to introduce our company as a reliable and experienced provider of Web Design & Development services. Founded and led by Engineer Toriqul Islam, a B.Sc. graduate in Computer Science & Engineering from Rajshahi University of Engineering & Technology (RUET), our team brings over 10 years of industry experience. At Toriqul Global Solutions, we specialize in building modern, user-friendly, and high-performance websites that help businesses grow and stand out in the digital world. Our design approach focuses on simplicity, elegance, and functionality to ensure maximum user engagement. I have some question-- Please start a conversation to discuss your project. Technologies We Use: Custom Websites Development Using ======>Full Stack Development. 1. HTML5 2. CSS3 3. Bootstrap4 4. jQuery 5. JavaScript 6. Angular JS 7. React JS 8. Node JS 9. WordPress 10. PHP 11. Ruby on Rails 12. MYSQL 13. Laravel 14. .Net 15. CodeIgniter 16. React Native 17. SQL / MySQL 18. Mobile app development 19. Python 20. MongoDB We would be honored to discuss your project requirements and help bring your ideas to life. Thank you for your time and consideration. Warm Regards, Toriqul Global Solutions
$12 USD in 40 days
5.5
5.5

With my solid experience in backend development over the past 5 years, I have acquired a thorough understanding of the significance of secure, efficient code in applications, especially in sectors like fintech and payments where I have worked extensively. What sets me apart is my deep appreciation for the importance of application-security, stemming from firsthand experience with security incidents that had serious consequences, which aligns perfectly with CLIQ's need. As a developer who has had to mitigate damages caused by security breaches, I am not only proficient in building robust security measures but also in performing stringent testing and revamping when necessary. In conclusion, my skill set, experience in securing customer's sensitive data, and genuine understanding of CLIQ's mission make me an ideal candidate for this role. So let's connect and discuss how we can take CLIQ to new heights together!
$10 USD in 40 days
4.9
4.9

Hello, I will own CLIQ's authorization and authentication surface part-time and treat the spec as the single source of truth. I will maintain the pure policy functions, explicit serializer field whitelists, and audit wrapper on every mutation, review Drizzle migrations and Postgres constraints so rules live in the schema, and vet changes to your node:crypto based auth including magic link, staff password plus TOTP, and WebAuthn. I will write and defend the cryptographic design for masked rendering and credential storage before anything ships, and translate spec rule IDs into contract tests and merge gates you can rely on. I built and owned auth and RBAC for a fintech backend serving 100,000 customers and remediated a production IDOR class bug. Do you want the initial paid spec review to prioritize credential storage or session and enumeration controls? Happy to jump on a quick chat, Ali Zain
$11.50 USD in 7 days
4.6
4.6

Hey there! I’m beyond excited to take this on! I recently wrapped up a similar project with good results. Drawing from my experience in Web Security, Technical Writing, Cryptography, Node.js, PostgreSQL, Typescript, Backend Development, Security, Data Modeling, Incident Response, I’m ready to dive into your project. Please come over chat and discuss your requirement in a detailed way. Cheers, Vishal Maharaj
$18 USD in 40 days
5.3
5.3

Hi there, I’m a seasoned backend engineer with deep expertise in secure systems, cryptography, and data modeling—perfect for CLIQ’s mission of empowering older adults with financial independence through privacy-first design. I’ve built and secured scalable Node.js backends using TypeScript and PostgreSQL, with strong experience in implementing end-to-end encryption, secure authentication flows, and audit-ready logging. I also have hands-on experience in incident response planning and writing clear technical documentation—critical for maintaining trust and compliance. For CLIQ, I’d focus on hardening the backend infrastructure, designing secure data models that respect user privacy, and ensuring all web security best practices are implemented from day one. My approach combines proactive threat modeling with maintainable, well-documented code. I’m available 10–20 hours/week and excited to contribute to a product that truly makes a difference. Best Regards, Khorshed Alam, RS Software
$10 USD in 40 days
4.5
4.5

Hi, CLIQ’s backend is the product: authorization, authentication, and credential handling all decide whether users stay protected and independent. That’s the right place to be obsessive. I’ve built production backend systems where security and data integrity were non-negotiable, including policy-driven authorization, audit trails, and relational schemas that enforce rules instead of trusting the app layer. TypeScript, PostgreSQL, and careful review of auth flows are where I do my best work. My approach would be to challenge the spec first, then tighten the policy layer, serializer boundaries, and mutation/audit path. I’d treat credential storage and masking as a design problem, not an implementation detail, and push constraints into Postgres wherever possible. If you want someone who will question the spec, defend the right design, and keep the sensitive paths boring, I’d be glad to talk. Best regards, Gabriel
$25 USD in 18 days
4.0
4.0

Hello, After carefully reviewing your project, I understand that security and authorization are the foundation of CLIQ, where correctness, auditability, and least-privilege access matter more than shipping features quickly. I have experience building secure backend systems with TypeScript, Node.js, PostgreSQL, authentication, data modeling, and application security, and I'm available to start immediately. The biggest challenge is ensuring every authorization decision, serializer, authentication flow, and database constraint consistently enforces your security model without exposing sensitive data. I follow a layered approach with policy-driven authorization, explicit DTO serialization, secure session handling, strong database constraints, thorough code reviews, and well-documented threat models to keep the backend maintainable and secure. I also appreciate your specification-first workflow. Reviewing the written rules, identifying security gaps, and validating them with tests before implementation is exactly how critical systems should evolve. I have a couple of quick questions: • Is your current authorization model RBAC, ABAC, or a hybrid approach? • Will the initial responsibility focus primarily on reviewing the existing security specification before implementing new features? I would be glad to discuss the architecture and help strengthen the security foundation of the platform. Best regards, Carlos
$10 USD in 40 days
3.6
3.6

★•══•★ Hi client ★•══•★ I get that you’re building something where every little permission slip means the difference between trust and betrayal. That’s a heavy responsibility, especially when it’s about protecting independence without spying. I’m all in on owning your authorization model and authentication with the care it deserves. Here’s how I’d tackle this: first, I’d dive deep into your spec to spot any weak spots or potential attack vectors. Then, I’d tighten up the policy functions and database constraints so rules live where they can’t be bypassed. After that, I’d audit the hand-rolled auth flows—sessions, magic links, passkeys—to make sure nothing slips through. Finally, I’d document everything clearly so your non-tech founder can understand and trust it. You’ll end up with a rock-solid backend security surface, clear docs, and peace of mind that every change is reviewed with a sharp eye. Quick question: What’s been the toughest authorization decision you’ve faced so far in this product? Best regards, Rico
$8 USD in 40 days
3.2
3.2

Your project demands clear-headed judgment on security rules and deep ownership of backend integrity. I’ve been the engineer defending systems where mistaken authorization wasn’t just a bug but a serious failure affecting users’ trust and safety—fintech platforms with similar sensitivity, where I rewrote the authorization logic to strictly enforce policy through layered constraints and audit trails. Your approach to separating policy logic, serialization, and audit makes complete sense and matches patterns I applied in those systems. I’d start by reviewing the spec’s numbered rules, pointing out any missing or ambiguous edge cases based on attack patterns I’ve encountered. Have you already modeled your threat scenarios with relevant adversaries, or would a joint review help tighten the spec before implementation? Regarding your homegrown auth: magic links and WebAuthn are tricky—especially around secret handling and timing attacks. I would audit the crypto usage and session lifecycle to ensure no unintended enumeration or replay windows exist. Would you be open to introducing ephemeral session keys for sensitive flows, or is lightweight cryptographic design prioritized over complexity? With Postgres constraints encoding invariants, I would carefully examine which can be expressed declaratively to prevent elevation, while balancing app-layer checks for richer logic. This balance avoids silent failures under race conditions—a common headache in real-world systems I’ve hardened. Ready to dive in with the spec excerpt and provide actionable, prioritized feedback so CLIQ can get this critical surface right before scaling.
$8 USD in 7 days
3.5
3.5

Hello, Security isn't about blocking attackers; it's about earning user trust every single day. When authentication, authorization, and data protection are designed correctly, people never have to think about them. That's exactly the kind of backend I enjoy building. I've worked on secure backend systems involving Node.js, PostgreSQL, TypeScript, API security, authentication workflows, role-based access, and enterprise-grade architectures where reliability and security come first. Here's what I'll deliver: ✓ Secure TypeScript/Node.js backend. ✓ Authorization & authentication review. ✓ PostgreSQL schema & data modeling. ✓ Audit logging & secure API design. ✓ Threat-focused architecture improvements. ✓ Documentation & deployment support. My recommendation would be to treat authorization as the foundation of the platform rather than a feature. Encoding security rules in policies, database constraints, and audit trails from day one creates a system that's easier to scale, easier to review, and far harder to misuse. If you're looking for someone who values long-term security over quick fixes, I'd love to discuss your backend architecture and roadmap.
$12 USD in 40 days
3.1
3.1

As a senior backend engineer specializing in secure infrastructure and cryptography, I am eager to join CLIQ as a Founding Security and Backend Engineer. I have extensive experience building scalable Node. js and TypeScript services with robust PostgreSQL data models. My background includes implementing end to end encryption, managing incident response protocols, and conducting deep security audits for early stage startups. I understand the unique challenges of a founding role and can efficiently handle both complex backend architecture and technical security documentation within a part time capacity. I am confident my expertise in cryptography and threat modeling will ensure CLIQ remains secure as it scales.
$12 USD in 40 days
2.8
2.8

Hello! I understand you are looking for a security-focused backend engineer to take ownership of CLIQ’s authorization, authentication, data protection, and backend reliability for a sensitive financial-care product. I have experience building secure TypeScript backend systems with strong authorization models, relational database design, API security, authentication flows, audit logging, and production-grade architecture. My approach includes reviewing the existing specification and codebase, validating permission boundaries, strengthening session and credential handling, improving database constraints, implementing secure service-layer patterns, and documenting security decisions through threat models and design reviews.
$12 USD in 40 days
3.0
3.0

hi, your product depends on getting authorization and security right from the start, especially for a platform handling sensitive financial relationships. i can contribute to reviewing backend architecture, strengthening authorization logic, improving authentication workflows, refining data modeling, and validating security critical code paths with a focus on maintainability and long term scalability. i am comfortable working with typescript backends, postgresql, security reviews, technical documentation, and collaborating through structured specifications and design discussions. could you share how mature the current backend specification is and which security workstream you would like the successful engineer to tackle first?
$17 USD in 40 days
2.5
2.5

Hello, I have 8+ years of software development experience across backend systems, APIs, databases, authentication, integrations, and production applications. My strongest focus is building reliable backend systems with clear authorization boundaries, secure data handling, validation, auditability, and maintainable architecture. One area I take particularly seriously is authorization: permissions should be explicit and enforced at the service/policy layer rather than relying on frontend visibility or assumptions in route handlers. For a product like CLIQ, I would want to review the authorization model, serializer boundaries, mutation/audit flow, authentication lifecycle, and database constraints before making changes. I’m also comfortable challenging a specification when a rule could create an unintended access path. Rate: $8 USD/hour Availability: 10–12 hours/week initially, with flexibility to increase as the engagement develops. I’m particularly interested in the paid specification review because it provides the right way to evaluate whether the security model is actually sound before implementation decisions become difficult to change. Best, JP
$8 USD in 40 days
2.5
2.5

Hi, I understand that CLIQ is seeking a part-time engineer to enhance the security and backend of your innovative product aimed at empowering older adults. With over 8 years of experience in PHP, Node.js, and database programming, I can ensure a robust authorization model that protects user privacy while maintaining independence. My expertise in developing secure authentication systems, including custom solutions with TOTP and WebAuthn, aligns perfectly with your requirements. I can also review your existing security measures and suggest improvements to fortify your architecture. Let's discuss how I can help safeguard CLIQ's mission with a reliable backend solution.
$8 USD in 7 days
1.2
1.2

I understand that having a secure backend is of utmost importance for CLIQ, especially considering the sensitive nature of the information involved. With over 5 years in backend development and a deep understanding of application security, I have firsthand experience dealing with the gravity of security breaches. Having worked in fintech, health, and payment sectors, I know the crucial role trust plays in fostering user engagement and loyalty. My skills in Node.js and PostgreSQL align well with CLIQ's stack. I'm proficient at building production-level backends and have always approached problems with a laser focus on security. My ability to write clean code while adhering to strict specifications will ensure a smooth transition into your development system. Additionally, my understanding of TypeScript gives me an edge in analyzing and debugging complex backend systems. Moreover, my approach to problem-solving complements CLIQ's existing framework - parsing, rate-limits and keeping business logic separate are all principles I firmly believe in.
$12 USD in 40 days
0.4
0.4

Hi, I can own the backend and security surface of CLIQ with the level of rigor your product demands. Building systems where authorization mistakes have real human consequences is something I’ve handled before, and getting your policy functions, audit wrappers and credential‑handling design absolutely correct is important. I’ve worked on products where session management, magic‑link flows, passkeys, TOTP, rate‑limiting and secure storage all had to be hand‑rolled and defensible under threat modeling, not just “working in staging”. We can outline a clear onboarding path once I review your spec, and I’ll keep communication direct so every rule, constraint and migration is grounded in attacker‑realistic reasoning rather than assumptions. I’d take ownership of the authorization model, authentication internals, cryptographic design document, Drizzle + Postgres schema constraints, audit trails, and sensitive‑path reviews, while producing clear written artifacts your founder can act on. I’d really like to win this role and I’m confident I can deliver the security judgment, backend ownership and disciplined review bar you’re looking for, looking forward to working together.
$12 USD in 40 days
0.0
0.0

Palm Springs, United States
Member since Aug 3, 2026
₹1500-12500 INR
₹12500-37500 INR
$15-25 USD / hour
₹12500-37500 INR
min $50 USD / hour
$10-30 USD
$30-250 USD
₹12500-37500 INR
$30-250 USD
$250-750 CAD
₹750-1250 INR / hour
€30-250 EUR
$30-250 USD
min ₹2500 INR / hour
₹12500-37500 INR
$30-250 USD
$8-15 USD / hour
£20-250 GBP
$30-250 USD
₹12500-37500 INR