Discover how Vollna streamlines your project search on Upwork with powerful filters, real-time alerts, and extensive analytics for optimal reverse engineering opportunities.
Signup for free
to get access to all filter attributes and instant notifications when new jobs are posted.
Setup filter
Get access to over 30+ filter attributes, setup instant notifications, integrate with your CRM and marketing tools, and more.
I currently use an invite-only TradingView indicator that plots nothing more than its buy and sell signals, yet I need the complete Pine Script source so I can study, adapt, and extend the logic myself. Your task is to deliver a fully readable, well-commented script that reproduces the indicator’s behaviour one-for-one on the chart.
The original script fires simple long/short markers—no custom alerts, dashboards, or extra overlays—so please focus on reverse-engineering whatever calculations drive those entries and exits, then rewriting them in Pine Script v5 so the code compiles without warnings.
To validate your work I will check that:
• The reconstructed script aligns candle-for-candle with the invite-only version’s buy/sell arrows on multiple assets and timeframes.
• Key variables and functions are commented clearly so I can tweak thresholds or add alerts later.
• All external libraries or special TradingView functions, if any, are included or replicated.
Deliverables: the .pine file plus a brief note summarising usage and any limitations you found while reproducing the logic.
I am seeking a consultant to review STEP files and BOM for a punch and die project. The task involves ensuring the design is suitable for punching holes in a stainless steel lid for a spice jar using an arbor press. The ideal candidate will have experience in mechanical engineering and design, with a focus on precision and material compatibility.
Please show prior stamping/die design experience in your proposal.
Hourly rate:
25 - 50 USD
7 hours ago
Engineering & Architecture, Energy & Mechanical Engineering
## Build an Advanced DeFi Flash Loan Arbitrage Bot for BSC
I’m looking for an experienced Solidity / DeFi developer to build a high-performance **Flash Loan Arbitrage Bot** for Binance Smart Chain (BSC).
I have already completed extensive research and reverse engineering of an existing deployed smart contract to understand its architecture and transaction flow. I also have live on-chain transaction history and contract interactions for reference.
The goal is **not** to clone or copy the existing contract, but to develop a **new implementation** with similar trading logic, improved architecture, better gas optimisation, and stronger security.
### Reference repository
https://github.com/danywayGit/OnChainArbitrage
### Available references
* Decoded contract source for research
* Dedaub analysis
* Live deployed contract
* BscScan transaction history
* Wallet interaction history
* Real arbitrage transaction examples
* Relevant GitHub repositories
* Previous DeFi projects
* Smart contracts you have written
* Experience with arbitrage or flash loans
* Estimated timeline
* Fixed price or hourly rate
Only experienced blockchain developers with proven DeFi work should apply.
Senior Full-Stack / AI Engineer — Production Ad-Ops SaaS (React + Supabase + LLM agents)
Applied
not specified
8 hours ago
Client Rank
- Risky
Payment method not verified
Phone number verified
$35 640 total spent
24 hires, 11 active
45 jobs posted
53% hire rate,
1 open job
4.75 /hr avg hourly rate paid
6 085 hours paid
5.00
of 11 reviews
Registered: Jul 14, 2020
United States
Oakland
01:21
1
What we've built
Spectra is a multi-tenant platform that runs paid media for DTC brands end to end — from generating the creative, to launching it, to watching the numbers and changing bids. It's live, it's in production against real ad accounts, and it moves real money daily.
The parts that matter:
An autonomous media-buying agent. It reads live account state, forms a hypothesis, proposes budget and status changes with reasoning attached, queues them for human approval, executes against the Meta Marketing API, then verifies the change actually landed and flags drift. Copilot and autopilot modes.
A creative generation engine. Brand-locked static ad production, every render is pinned to a brand kit (palette, logo, product references, compliance rules) with categorized reference images that each inject a different instruction into the model. A prompt-lint gate refuses to spend a render credit on an underspecified brief.
A creative learning loop. Human verdicts plus real spend/ROAS feed back into which patterns win, so the generator gets better at a specific brand over time instead of regressing to generic.
A performance layer. Continuous sync across 100+ ad accounts, blended with a revenue/attribution source, plus competitor intelligence pulled from the public ad library and auto-classified.
Stack
React 18 + TypeScript + Vite + Tailwind + Redux Toolkit. Supabase: Postgres with row-level security throughout, Deno edge functions, pg_cron, pg_net. Meta Marketing API. Gemini for image generation, Anthropic for the agent reasoning. Roughly 80 tables, 40 edge functions, 20+ scheduled jobs.
What we need
We're past prototype and into the part that decides whether this scales: hardening, developer infrastructure, and shipping the next layer of product. Specific tracks, and you don't need all of them:
CI/CD and release engineering. Automated edge-function deploys, preview environments, migration discipline. Today deploys are manual and it's the main thing slowing us down.
Integrations layer. A proper self-serve settings surface so each tenant connects only the data sources they use, with per-integration health and onboarding.
The learning loop. Turning verdicts and performance data into a versioned prompt/pattern corpus — schema design, an evaluation harness, A/B on prompt variants.
Multi-tenant correctness. We take isolation seriously — RLS on every table, column-level grants, tenant-scoped everything. If you find that boring, we're not a fit.
Who we're looking for
Someone who has shipped and operated a real multi-tenant SaaS, not just built one. Concretely, you should be comfortable saying why row-level security alone can't restrict a column, what happens to a webhook you process twice, and why a key in a Vite env var is still a public key.
Bonus if you've worked against the Meta Marketing API — its rate limits, error taxonomy, and review process shape a lot of our architecture.
Engagement
Start with a paid scoped project (1–2 weeks) so we can both see how it goes, then move to ongoing retainer or part-time contract if it works. We have a clear backlog, written architecture docs, and inline commentary explaining why things are the way they are — you won't be reverse-engineering intent.
Tell us about a system you've operated in production and one thing that broke in a way you didn't expect. That answer tells us more than a portfolio.
Effects of Nitrogen and Phosphorus Enrichment on Grassland Biodiversity and Ecosystem
Applied
$5
11 hours ago
Client Rank
- Excellent
Payment method verified
Phone number verified
$1 874 total spent
79 hires, 13 active
80 jobs posted
99% hire rate,
2 open job
16.83 /hr avg hourly rate paid
101 hours paid
5.00
of 60 reviews
Registered: Jan 27, 2026
United States
New york
11:21
5
We are seeking a skilled freelancer to assist with a meta-analysis protocol examining the effects of nitrogen and phosphorus enrichment on grassland biodiversity and ecosystem. The project involves conducting a systematic literature review, data extraction, and statistical analysis to synthesize findings. The ideal candidate will have experience in meta-analysis and data interpretation, particularly in environmental science contexts. The project aims to provide insights into the impacts of nutrient enrichment on grassland ecosystems.
Senior Full-Stack AI Engineer for Sales Automation
Applied
$15 - $20
/ hr
12 hours ago
Client Rank
- Medium
Payment method verified
Phone number verified
1 open job
no reviews
Registered: Aug 5, 2025
Canada
13:21
3
I'm looking for a senior full-stack AI engineer to build an AI-powered sales automation platform similar to Amplemarket. The ideal candidate has experience in AI and full-stack development, with a focus on creating scalable and efficient solutions. Familiarity with sales automation tools is essential. The role involves designing and implementing AI-driven features to enhance sales processes.
Client's questions:
Describe your recent experience with similar projects
Describe your approach to testing and improving QA
We are seeking an experienced OCR Programmer to optimize an existing program. The ideal candidate will have a strong background in OCR programming and problem-solving skills to enhance the efficiency of the current system. The role involves analyzing the program, identifying areas for improvement, and implementing effective solutions to optimize performance.
We are a small hardware security company in Germany. We are building a
tool that reads firmware from ESP32 devices.
We write the firmware and the PC software ourselves. We need one person
to draw the schematic and lay out the PCB.
Scope Schematic + PCB layout + manufacturing files
Not in job Firmware, prototypes, PC software
Tool KiCad
Made at JLCPCB, parts from LCSC
Budget EUR 800 fixed price
Milestone 1 Schematic, pin map, current budget EUR 300
Milestone 2 Layout and JLCPCB files EUR 500
We review and approve the schematic before layout starts. Milestone 1 is
small on purpose — it is a paid trial. If the schematic is good we
continue with you, and we have more board projects after this one.
1. WHAT THE DEVICE DOES
A user connects an unknown ESP32 device and the tool reads its firmware
out. These are the situations it has to handle:
1. Identify the chip: type, revision, MAC, flash size, security fuses
2. Read firmware out, and write firmware back in
3. Read through the device's own USB port, without opening it
4. Read through a pin header, when there is no usable USB port
5. Read the SPI flash chip directly with a test clip
6. Do all of this on 1.8 V flash without damaging it
7. Work on a device already powered by its own supply
8. Watch signals with an 8 channel logic analyzer
9. Detect a short or wrong voltage and cut power before damage
10. Recover a bricked device by erasing and reflashing it
If something in the design would stop one of these from working, please
tell us.
2. HOW THE BOARD IS BUILT
PC side
USB-C connects to a UART bridge chip, which talks to the module over
a serial link. An auto-reset circuit lets us flash the module without
pressing buttons. BOOT and RESET buttons are also fitted.
Target side
Three ways to connect, all live at once, no rewiring:
- USB-A port, where our board is the USB host
- 2.54 mm header: UART, EN, IO0, JTAG, SPI, power, and several
ground pins spread along the row
- SOIC-8 flash clip connector, including a line that holds the
target's EN low
Signal path
Eight shared channels sit behind eight level shifters. UART, JTAG,
SPI and the logic analyzer all use these same eight pins, selected in
software. Each channel has its own direction control.
Target power
Three fixed rails, 1.8 V, 3.3 V and 5 V, each behind a load switch.
Only one may be on at a time, and this is enforced in hardware. A
current sensor watches the rail and cuts power on a short. A resistor
divider into an ADC pin reads the target's own voltage before we
drive anything.
Everything is software controlled
No jumpers, no solder bridges, no switches. Firmware selects the
target voltage, the direction of each channel, whether the board is
connected at all, and where the shifters take their reference from.
This is a sealed product, not a dev board.
3. PARTS
Part Why we chose it Change it?
-------------------- --------------------------- -----------
ESP32-S3-WROOM-1 8 MB PSRAM for the analyzer Suggest a
-N16R8 module buffer. Module, so no RF variant if
work. Wi-Fi stays off. you prefer
CH343G UART bridge SOP16 is easy to rework. Yes, CP2102N
(SOP16) CH343P is the QFN version is fine too
with custom VID/PID.
SN74LVC1T45 Own DIR pin per channel. Yes, if it
level shifter x8 Both rails 1.65 to 5.5 V. keeps per
Eight packages is a lot. channel DIR
PCA9555 I2C Drives direction lines and Any
expander slow control signals equivalent
74HC139 decoder Makes two rails on at once Yes, if
physically impossible hardware
enforced
INA226 current Milliamp resolution and INA219 also
sensor short detection acceptable
Load switches, Not specified Your choice
ESD parts, LDOs
We are not experts in everything and we are happy to be corrected. If
you know a better part, tell us at Milestone 1 with a short reason. Good
advice is worth money to us.
4. WHAT CANNOT CHANGE
These come from how the ESP32-S3 works, not from preference. You may
propose a different way to meet them, but not to drop them.
A USB-C goes through a bridge chip, not straight to the module
B A module, not a bare chip
C Independent direction control on every channel
D No auto-direction shifters (TXS0108E, TXB0108 and similar)
E Everything software controlled, no user-touchable jumpers
F One target voltage at a time, enforced in hardware
G 1.8 V target support
5. THINGS YOU NEED TO KNOW
Six details that are easy to miss and expensive to get wrong.
The two USB controllers share one PHY
The ESP32-S3 has USB-OTG and USB-Serial-JTAG, but they share a single
internal PHY, so only one runs at a time. We need to be a device to
the PC and a host to the target simultaneously. That is why the PC
side uses a bridge chip. An external PHY would also work but costs
six GPIOs and adds risk, so we are not going that way.
The level shifters have no output enable
The SN74LVC1T45 has a DIR pin but no OE pin, so a control pin cannot
put a channel into high impedance. Its VCC isolation feature does:
with VCCB at ground, both ports go high impedance and current
backflow is blocked. So VCCB is our disconnect switch, and it needs
to be software selectable between 1.8 V, 3.3 V, 5 V, the target's own
voltage, and off.
The CH343 DTR pin is also a config input
At power-up, a pull-down on DTR switches the chip to half-duplex mode
and turns DTR into a TNOW output. If that happens we can never flash
the board. Worth checking the auto-reset circuit against the
datasheet.
Some GPIOs do not exist on this module
GPIO26-32 are the in-package flash bus and are not broken out.
GPIO33 and GPIO34 have no module pin. GPIO35, 36 and 37 belong to the
octal PSRAM. That leaves about 33 usable pins.
One GPIO must stay completely unconnected
The logic analyzer uses it for its capture clock.
Use ADC1 for the voltage sense
ADC2 is not reliably available.
Slow signals — direction lines, load switch enables, LEDs — belong on
the expander rather than the module, to keep pins free.
6. PROTECTION
ESD parts on USB-C, USB-A and the target header
Series resistors on all target signal lines
Resettable fuse on the target rail
Separate current limited switch for the USB-A port
The board should survive a live target, a reversed header, a short on
the target rail, and being set to the wrong voltage.
The whole board runs from USB with a 500 mA budget shared with the
target, so please include a current budget at Milestone 1.
7. WHAT YOU DELIVER
Schematic KiCad source file, not only PDF
Layout KiCad, 4 layers
Manufacturing Gerbers, drill files, BOM and CPL for JLCPCB
Model 3D STEP
Documents Pin map, current budget, and a short note on your
part choices including anything you changed
Please use parts LCSC has in stock.
8. TERMS
Work for hire, we own the design. NDA required. KiCad source files
delivered at both milestones, not held until the end. Faults caused by
the schematic or layout are fixed free of charge.
Payment Link Method — Backend Integration (Node.js)
Applied
$20 - $30
/ hr
22 hours ago
Client Rank
- Risky
Payment method not verified
Phone number verified
1 jobs posted
1 open job
no reviews
Registered: Jul 24, 2026
United Kingdom
17:21
1
We want to move our payment link method to the backend due to UX concerns — instead of
redirecting users to a different page, we want them to stay within our own interface. This is a
web project, not a mobile app.
Problem: The payment link service doesn't allow configuring the return URL after 3D Secure
verification. Because of this, the flow needs to be reverse engineered and integrated into our
backend.
Able to perform network traffic analysis (using Burp Suite, mitmproxy, or similar tools)
Able to write in Node.js
Experienced with payment system integrations, especially correctly handling the 3D Secure
screen
We prefer working with someone who also has mobile development experience (we'll need this
for an upcoming mobile project)
We have an active merchant account with the payment provider, and the work will be carried
out through this account. A HAR file of the existing flow will be shared.
Deliverable: Working Node.js module + brief documentation
We are looking for a skilled 3D Model Designer to support us in creating highly detailed 3D representations of agricultural machinery. The work is focused on visual accuracy, not on functional engineering.
As a 3D Model Designer, you will:
• Build clean, realistic 3D models from 3D scan data (provided by us), technical drawings, and reference photos.
• Use 3D scans as a template to accurately reconstruct shapes and details.
• Refine and adjust models based on feedback to achieve a high visual standard.
• Collaborate directly with our team on multiple ongoing projects.
We strongly prefer direct collaboration with the designer (no exclusive agency intermediaries). Our goal is a reliable, long-term partnership.
Deliverables
• Accurate CAD models of agricultural machinery, focused on optical/visual precision.
• Processing of 3D scan data: cleaning, rebuilding, and refining scanned meshes into usable CAD geometry.
• Iteration based on feedback until the required detail level is achieved.
• Delivery of files in consistent, agreed formats (e.g. STEP, IGES, STL).
• Reliable communication and timely progress updates.
• Consistent availability for long-term collaboration (multiple projects).
Budget & Collaboration
We work on a fixed-price basis per project. The budget depends on complexity and is agreed upon in advance.
• Smaller projects may be around $500.
• Larger, more complex projects can go up to $2000.
Our objective is to build a long-term collaboration, working project by project.
Client's questions:
What challenging part of this job are you most experienced in?
Which software do you normally use to clean and rebuild CAD data from 3D scans, and why?
Can you share an example of a project where you had to build a clean CAD model from imperfect / incomplete or noisy scan data?
How do you normally communicate progress and share intermediate results with clients?
I have a native Android app whose network traffic refuses to show up in HttpCanary or similar sniffers. I need the exact requests and responses that this app generates—including headers, body content, and any metadata—in a clean, readable format.
You are free to bring whatever technique works best: Frida instrumentation, certificate-pinning bypass, custom SSL proxies, or low-level packet captures. What matters is that you return at least one verifiable request-response pair for the action I specify and show me how you achieved the interception so I can reproduce it on my side.
Deliverables
• Raw request and matching response captured from the app
• Short walkthrough (commands, scripts, patched APK if needed) so I can repeat the capture on another device
If you’ve cracked stubborn Android traffic before, this should be a straightforward task. Let me know how quickly you can get the capture and what access or info you’ll need from me.
Skills: C Programming, Java, Mobile App Development, Android, Debugging, Network Security, Reverse Engineering, Android App Development
Fixed budget:
600 - 1,500 INR
1 day ago
Websites, IT & Software, Mobile Phones & Computing, Sales & Marketing, Business, Accounting, Human Resources & Legal, Debugging, Mobile App Development, Android, Network Security, Reverse Engineering, Android App Development
Hello,
I am looking for a mechanical engineer to design a smart floor drain similar to the attached concept, taking it from concept to a production-ready product. The scope includes the complete mechanical design, all individual components, assembly, and manufacturing files ready for production.
Confidentiality is mandatory. All project information, designs, and related materials must be kept strictly confidential and must not be shared or used for any purpose outside this project.
If you have experience designing similar products, please send examples of your previous work alon
g with your estimated cost and timeline.
I am looking for an advanced Premiere Pro 2026 colorist to take a raw Mavic 4 Pro D-Log 6K drone clip and build a highly specific cinematic grade. This project is strictly for my own educational reverse-engineering. The final milestone will only be released upon delivery of the final video export AND the fully un-nested, un-rendered Premiere Pro (.prproj) project file with best export settings for full youtube resolution and Instagram/Tiktok reels.
All Lumetri Color effects, Rec.709 conversions, HSL secondary masks, and adjustment layers must remain completely active and unflattened so I can review the exact layer structure and mathematical adjustments.
I need a mechanical CAD designer to create a custom automotive part based on my 3D scan. The part must fit precisely, and I need the final files in Fusion 360 format. The designer should have experience in automotive parts and precision fitting.
We are looking for experienced embedded hardware engineers to design and prototype a programming solution for a complex 12-layer PCBA used in a medical device. The board includes an FPGA, ARM processor, Intel 64 MB Flash Memory, EEPROM, and other high-density components.
Photos of the board is attached for reference.
Scope of Work
- Design a programming solution that can program the Intel Flash memory and EEPROM in-circuit, without removing any components from the PCB. Minor soldering jobs is accepted but we cant remove any BGA components.
- Design and build a working prototype programmer.
- Provide all required hardware, firmware, software, user manual, manufacturing documents and service manual.
- User should be able to connect the programmer to the board, select a hex file for the Intel memory and a hex file for the EEPROM for programming.
- Files can be transfer thru a computer connection or can be stored on another memory on the programmer board
Available Information
- Reverse-engineered PCB design files
Schematics
- Sample working PCBA with power adapter and LCD
and instruction on how to turn on the board and boot up the board
- Existing HEX files for programming (several existing different hex files are available for Intel memory and EEPROM)
- Intel/Micron Memory PN#RC48F4400P0VB0E
- ST EEPROM PN#M24C04-W
Note: The reverse-engineered files may contain minor inaccuracies, and the selected engineer should be capable of identifying and resolving them.
Deliverables
- Fully functional programming hardware
- Programming software/firmware
- Source files and documentations
- Successful in-circuit programming of the Intel Flash memory and EEPROM
-
Timeline
Prototype completion is expected within 8–12 weeks.
Requirements
- Strong experience with FPGA- and ARM-based hardware
- Extensive PCB design and reverse-engineering experience
- Experience with Intel Flash memory, EEPROMs, and in
circuit programming (JTAG, SPI, ISP, etc.)
- Ability to troubleshoot complex multilayer PCBs
- Experience with medical electronics is a strong advantage
- NDA required
Payment Terms
This is a fixed-price project with a total budget of USD $40,000.
Payment will be released upon successful completion of the project, including demonstration that the programmer can reliably program the board using our existing HEX files without removing the memory devices.
Are you able to handle this formulation? If so, let me know if you would like me to send over our target percentage breakdown so we can set up an Upwork milestone.
I have the blueprints for a custom app. The app has 4 layers; A .net launcher, a C++ orchestrator that launches an intermediary program which launches the game client. At the time of this happening the orchestrator pauses game client functions. This is all connected to a core (logic engine) which acesses a shared memory channel with the client. The client is monitored real time and the logic engine feeds it feedback.
Job Description:
We are looking for an experienced PCB Design Engineer to review reverse-engineered PCB designs for ultrasound probes. The projects involve MUX PCBs and Connector PCB Boards, and the goal is to verify accuracy, fix errors including routings, BOM, Gerber files and prepare file files for the manufacturer.
Requirements:
- Strong experience with PCB design and reverse engineering.
- Experience with high-density, multilayer PCBs.
- Experience reviewing schematics, Gerber files, and PCB layouts.
- Familiarity with Altium Designer (preferred).
- Experience with Medical Ultrasound Systems and Probes is a strong advantage.
- Ability to identify design issues and recommend improvements and fix issues
- NDA required
Deliverables:
- Review PCB design files.
- Identify errors, missings tracks or vias, missing components, components part numbers and routing issues.
- Provide recommendations for improvement.
- Fix BOM, Gerber file, part markings,
- Preparing final Gerber, BOM and Altium design files for manufacturers
We're an Australian custom furniture company that designs original pieces for hospitality venues. We generate photorealistic furniture concepts using AI image tools, and we manufacture at commercial scale — but right now there's a slow, manual gap between "approved concept image" and "drawings a factory can build from."
We want to close that gap with a fully scripted pipeline, and we're looking for someone to architect and build it with us.
The pipeline we want to build
Stage 1 — Multi-view renders → 3D mesh. Take a set of consistent rendered views of a furniture piece (front, side, three-quarter, etc.) and produce a clean 3D mesh. We're open on approach: AI image-to-3D services via API (Tripo, Meshy, Hunyuan3D, TRELLIS, or similar), photogrammetry adapted for synthetic imagery, or a hybrid. You should know the current landscape well enough to recommend what's production-viable today, not just what demos well.
Stage 2 — Mesh → manufacturable CAD. Raw AI meshes aren't buildable. This stage cleans, retopologises, and converts the mesh into a proper CAD representation — NURBS/BREP surfaces or a parametric reconstruction — with real-world dimensions, correct wall thicknesses, and geometry a factory can actually machine, cast, or fabricate. We currently work in Rhino 8, so Rhino.Compute / rhino3dm / Grasshopper experience is highly relevant, but we're open to your recommended stack if you can justify it.
Stage 3 — CAD → shop drawings. Scripted generation of dimensioned 2D shop drawings from the CAD file: orthographic views, sections, key details, exploded views where relevant, title blocks, and a basic bill of materials. Output as PDF + DXF/DWG. The goal is that a human reviews and annotates, rather than draws from scratch.
Stage 4 — Everything callable from the web. The whole pipeline needs to run headless, triggered by API calls, so it can sit behind an HTML-based product configurator. A user (or our team) adjusts a concept in the browser, the pipeline runs server-side, and manufacturable files come out the other end. You don't need to build the configurator front-end — but the pipeline must be architected as clean, documented services/endpoints that a front-end can plug into.
What you'll deliver
Architecture document — recommended tools, services, and data flow for the full pipeline, with honest notes on what's reliable now vs. what needs human-in-the-loop checkpoints.
Working proof of concept — one real furniture piece (we'll supply the renders) taken end-to-end: renders in, dimensioned shop drawing set + BOM out, via script.
Production pipeline — the PoC hardened into documented, repeatable code (Python preferred) with a defined API surface for the configurator integration.
Handover — clear documentation and a walkthrough session so our team can run, maintain, and extend it.
Required skills
Deep experience with mesh processing and repair (retopology, decimation, watertight checking) — e.g. Blender scripting, MeshLab, Open3D, PyMeshLab
Rhino 8 / Grasshopper / Rhino.Compute / rhino3dm, or an equivalent programmatic CAD stack (FreeCAD + Python, Fusion API, OpenCascade), with mesh-to-BREP conversion experience
Automated 2D drawing generation — scripted views, sections, dimensioning, and layout export to PDF/DXF
Strong Python; comfortable building headless services and REST APIs
Familiarity with current AI image-to-3D tools and their APIs, including their real-world limitations
Understanding of what makes geometry manufacturable (tolerances, wall thickness, joinery logic, material constraints) — furniture, joinery, product design, or industrial design background is a big plus.
How we'll work
We'll start with a paid discovery/architecture milestone before committing to the full build. We're a small, fast-moving company — you'll work directly with the founder, decisions get made quickly, and there's meaningful ongoing work if the pipeline succeeds (this is the manufacturing backbone of a larger product vision).
To apply, please answer
Describe a project where you converted mesh data into manufacturable CAD or drawings. What broke, and how did you fix it?
Which image-to-3D approach would you reach for first with synthetic renders (not photos) as input, and why?
What's your honest view on how much of Stage 2 (mesh → clean CAD) can be automated today vs. requiring a human checkpoint?
What's your preferred stack for Stage 3 (automated shop drawings), and can you share an example output?
Applications that answer these specifically will be prioritised over generic proposals.
Client's questions:
Describe a project where you converted mesh data into manufacturable CAD or drawings. What broke, and how did you fix it?
Which image-to-3D approach would you reach for first with synthetic renders (not photos) as input, and why?
What's your honest view on how much of Stage 2 (mesh → clean CAD) can be automated today vs. requiring a human checkpoint?
What's your preferred stack for Stage 3 (automated shop drawings), and can you share an example output?
We are looking for a highly skilled and experienced Android Security and APK Processing Engineer for a long-term monthly contract.
The ideal candidate should have strong practical experience with Android application internals, APK file structures, cryptography, binary formats, automation, native libraries, and secure software engineering.
The work involves developing and maintaining authorized tools and workflows for Android application protection, secure APK processing, encryption, software integrity, and security research.
The successful candidate should be comfortable working at both a high level with Android applications and a low level with DEX bytecode, binary XML, native libraries, ELF structures, cryptographic systems, and automation pipelines.
All work must be performed only on software and application files that are owned by the client or for which the client has appropriate authorization to analyze, process, modify, or protect.
This is intended to be a long-term working relationship with ongoing technical development and maintenance work.
What You Will Work On
* Design and implement custom encryption and decryption pipelines for authorized Android APK files
* Develop secure APK packaging and application protection workflows
* Analyze and process Android APK internals, including DEX bytecode, binary Android XML (AXML), AndroidManifest.xml, ZIP/APK structures, and native .so libraries
* Build secure outer application wrappers for protected application components and authorized application packaging workflows
* Develop systems that securely process and manage protected application payloads
* Parse and programmatically modify AndroidManifest.xml in binary AXML format
* Work with cryptographic systems including AES-CBC, AES-GCM, RSA, symmetric encryption, asymmetric encryption, and custom cryptographic workflows
* Understand and manipulate DEX file structures, string tables, metadata, and bytecode representations
* Analyze and modify native ARM and ARM64 ELF libraries for authorized application protection and compatibility requirements
* Implement JNI and native library changes where required
* Develop Python scripts for automating APK processing and security workflows
* Build reliable, repeatable APK processing pipelines
* Work with Android build and packaging tools including AAPT, apktool, zipalign, and apksigner
* Maintain and improve existing codebases
* Debug complex APK processing, encryption, packaging, and signing issues
* Collaborate through Git and follow existing project architecture and coding standards
* Research application integrity, anti-tampering, and software protection techniques in authorized environments
Required Skills
Android APK internals: DEX, AXML, ZIP structure — Expert
Cryptography and custom encryption design — Expert
AES, RSA, symmetric and asymmetric cryptography — Expert
Binary XML (AXML) parsing and processing — Expert
Python 3 — Expert
Java / Kotlin — Strong
C / C++ — Intermediate+
JNI / native Android development — Intermediate+
ELF binary analysis — Intermediate+
ARM / ARM64 native library analysis — Intermediate+
Smali / Dalvik bytecode — Intermediate+
Linux command line and shell scripting — Strong
Git version control — Required
Bonus Skills
The following skills are beneficial but not mandatory:
* Experience with Android application security testing
* Experience with APK signing and signature schemes including v1, v2, and v3
* Knowledge of ProGuard and R8 obfuscation
* Experience with JADX
* Experience with apktool
* Experience with Frida in authorized security testing environments
* Experience with Ghidra
* Understanding of Android application installation and package management processes
* Experience developing application protection systems
* Experience developing integrity verification and anti-tampering systems
* Experience with secure application packaging
* Experience with Android security research
* Experience with vulnerability assessment in authorized environments
* Experience with software protection and reverse engineering for applications where appropriate authorization exists
* How many hours per week you are available
* Your usual working hours or timezone
* Your earliest possible start date
5. Compensation
Please confirm whether your expected compensation is within the listed budget of:
$380–$420 USD per month
If your expectations are different, please mention them clearly in your proposal.
Proposal Requirement
Generic proposals may not be considered.
To confirm that you have carefully read this job description, please include the word:
AXML
somewhere in your proposal.
Authorized Use Requirement
All technical work must be limited to software, applications, files, and systems that the client owns or is authorized to analyze, process, modify, test, or protect.
The work must comply with applicable laws, software licenses, intellectual property rights, platform rules, and project agreements.
The role does not involve unauthorized access to systems, unauthorized modification of third-party software, credential theft, or bypassing access controls without proper authorization.
We are seeking an experienced Penetration Testing Agency or Senior Cybersecurity Consultant to perform a comprehensive security assessment of a large-scale enterprise payment platform. The engagement includes Web Application, API, Internal Network, Android, and iOS security testing, with deliverables aligned to PCI DSS penetration testing requirements.
This is a manual security assessment requiring strong expertise in business logic testing, authentication, authorization, and payment application security.
Scope of Work
The selected team will perform penetration testing for the following components:
1. Web Application Penetration Testing
Authentication & Session Management
User & Role Management
Merchant Onboarding & KYC
Dashboard & Administration Portal
Payment Links
Hosted Checkout
Transactions
Reports & Analytics
Settlement & Reconciliation
File Upload/Download
Business Logic Testing
Horizontal & Vertical Privilege Escalation
IDOR Testing
OWASP Top 10 (2025)
2. API Penetration Testing
The platform contains approximately 460 REST API endpoints across multiple backend services.
Testing should include:
Authentication & Authorization
JWT Security
API Key Security
Broken Object Level Authorization (BOLA)
Broken Function Level Authorization (BFLA)
Rate Limiting
Business Logic Testing
Injection Testing
Input Validation
Sensitive Data Exposure
Security Misconfiguration
Webhook Security
HMAC Validation
OWASP API Security Top 10
3. Internal Network Penetration Testing
Assessment of approximately 11 internal IP addresses.
Testing should include:
Network Enumeration
Port Scanning
Service Enumeration
Vulnerability Assessment
Configuration Review
Weak Services
Remote Access Security
Patch Validation
4. Android Application Security Testing
The Android application should be assessed for:
Static Analysis
Dynamic Analysis
Authentication
Session Management
Secure Storage
Token Security
SSL Pinning
Reverse Engineering
API Communication Security
OWASP MASVS / MSTG
5. iOS Application Security Testing
Assessment should include:
Static & Dynamic Analysis
Face ID / Touch ID Security
Secure Storage
Keychain Security
Token Protection
SSL Validation
API Communication
Session Management
Reverse Engineering
Proposal Requirements
Please include the following in your proposal:
Brief introduction and relevant penetration testing experience.
Experience with enterprise web application, API, mobile application, and internal network penetration testing.
Experience with payment platforms, fintech applications, or PCI DSS environments (preferred).
A redacted sample penetration testing report.
Your testing methodology (manual and automated).
Estimated project timeline.
Client's questions:
Estimated project timeline in hr.
Fix Cost according to your timeline
Relevant certifications
Hourly rate:
8 - 30 USD
3 days ago
IT & Networking, Information Security & Compliance
We have an existing Android application called **Know Your Rights**, currently published on Google Play.
The application was originally built many years ago under an old platform called **Reesh KSA**, which was managed by a former business associate. We no longer have a relationship with this individual, and **the Reesh KSA platform/company has since closed down**.
We need an **exceptional senior Android developer** with deep experience in Google Play Console, app signing, legacy Android applications, and app migrations.
This is **not** a standard development project. The first phase is to determine the safest and most technically sound path before redevelopment begins.
What We Need
The successful developer should:
* Audit the existing Android application.
* Determine ownership of the Google Play listing, Google Play Console access, signing certificates, and publishing rights.
* Advise on the best migration strategy.
* Transfer or rebuild the application under our own Google Play developer account.
* Ensure we own all source code, build systems, certificates, and publishing credentials going forward.
Current Situation
The existing application is **Know Your Rights** and is published under the package:
**com.reeshksa.knowyourrights_copy.sc_32UUH8**
Based on our research:
* The package name suggests the application may have been built using a no-code/mobile app builder rather than custom software.
* The "reeshksa" package prefix reflects the old Reesh KSA platform rather than our own organisation.
* The Play Console account and Android signing credentials may not currently be under our control.
* We cannot verify whether Google Play App Signing is enabled.
These findings are based on publicly available information and must be verified before redevelopment begins.
Two Possible Approaches
Option A (Preferred)
The developer is able to recover, migrate, or recreate the Android application under our own Google Play developer account **without requiring assistance from the former Reesh KSA platform or its owner**.
This may involve:
* Recovering access where possible.
* Verifying Google Play App Signing status.
* Preserving the existing Google Play listing if technically possible.
* Rebuilding the application where necessary while ensuring all future ownership and publishing rights are transferred to us.
Option B
If the existing application cannot legally or technically be transferred without involvement from the former **Reesh KSA** owner, the developer should clearly explain why and advise on the minimum cooperation required.
However, there is an additional complication: **the Reesh KSA platform/company has since closed down**. We therefore need the developer to assess what options remain if the original platform is no longer operating.
This may include:
* Determining whether the Google Play Console account is still accessible.
* Determining whether Google Play App Signing is enabled and whether the app can still be updated.
* Advising whether the original Android signing key can be recovered or replaced.
* Identifying whether any assets, source files, or build files can be recovered.
* Explaining whether the existing Google Play listing can be preserved or whether a new application must be published.
* Advising whether there are any alternative technical or legal routes to recover ownership or control of the existing app despite the platform having closed.
If cooperation from the former Reesh KSA owner is the only viable path, we may make a one-time request solely to obtain Play Console access, transfer ownership, or recover signing credentials. Otherwise, we expect the developer to recommend the best alternative solution.
Critical Technical Assessment
Before redevelopment begins, the developer must determine:
* Who owns the Google Play Console account.
* Whether Google Play App Signing is enabled.
* Whether the Android signing key can be recovered or reset.
* Whether the existing application can continue receiving updates.
* Whether the existing Google Play listing can be retained.
* If not, the best migration strategy while minimising disruption for existing users.
We are looking for a factual technical assessment—not assumptions.
Ideal Candidate
The ideal developer will have proven experience with:
* Google Play Console administration.
* Android signing certificates and keystores.
* Google Play App Signing.
* Legacy Android applications.
* Android app recovery and migration.
* Reverse engineering existing Android applications where appropriate.
* Native Android development (Kotlin/Java).
* Flutter or React Native (if recommending a rebuild).
* Secure transfer of applications into client-owned developer accounts.
Please Include in Your Proposal
1. Examples of similar Android migration or recovery projects you have completed.
2. Your experience with lost Android signing keys and Google Play Console ownership issues.
3. Whether you believe this application can likely be migrated without involving the former Reesh KSA owner, and why.
4. Your proposed technical approach for investigating and resolving this project.
5. The information you would need from us to carry out the initial technical assessment.
The engagement will begin with a **paid technical audit**. Once the technical path has been confirmed, the successful developer will complete the migration, recovery, and redevelopment of the **Know Your Rights** Android application, ensuring that all future ownership, publishing rights, source code, certificates, and developer accounts are fully under our control.
We are seeking a skilled CAD Engineer or Industrial Designer to reverse engineer a series of complex, organic saddle designs. The ideal candidate will have experience in CAD software and industrial design, with a strong understanding of organic shapes and structures. The project involves analyzing existing designs and creating detailed CAD models for production. If you have a passion for design and a keen eye for detail, we would love to hear from you.
I am looking for an experienced Mechanical Design Engineer to design a manufacturing-ready industrial conveyor system.
Conveyor Specifications
Conveyor Size: 300 mm (W) × 1500 mm (L) × 800 mm (H)
Frame Material: Mild Steel (Powder Coated) with a design suitable for Stainless Steel (SS) version as well
Belt: Black matte PVC flat belt
Drive: Geared motor with VFD speed control
Structure: Modular construction for easy transportation and assembly at the customer's site (minimum welding preferred)
Load Capacity: Up to 2 kg
Application:
Empty pouches
Mono carton boxes
Sweet boxes (up to 1.1 kg)
Empty lubricant oil buckets (0.85–1.1 kg)
Conveyor Features
One fixed side guide
Product collection tray for pouches and mono cartons
Adjustable conveyor feet for height leveling
Belt tracking and tension adjustment mechanism
Easy belt replacement and maintenance
Compact industrial design suitable for coding and marking applications
Friction Feeder (Stacker)
Design a friction feeder compatible with the above conveyor.
The feeder should be suitable for:
Empty pouches
Mono carton boxes
Ice cream paper lids
The feeder should include:
Adjustable side guides
Adjustable friction belt pressure
Variable speed operation
Easy integration with the conveyor
Adjustable mounting bracket
Reliable single-product feeding
Deliverables
The project must include:
Complete 3D CAD model
Manufacturing drawings
Assembly drawings
Exploded assembly drawing
Detailed Bill of Materials (BOM)
Standard components list with specifications
Fastener list
Bearing and shaft details
Belt and pulley specifications
Motor and gearbox mounting details
Design suitable for manufacturing in both MS and SS versions
Preferred CAD Software
SolidWorks (Preferred)
Autodesk Inventor
Solid Edge
Please Include in Your Proposal
Your quotation for the complete project
Estimated completion time
CAD software you will use
Examples of similar conveyor or industrial machine designs (if available)
Please share contact details for complete product detail discussion
Budget:
not specified
3 days ago
Engineering & Architecture, Energy & Mechanical Engineering
We are engaging a senior Softr + Airtable specialist to construct a secure, dark-mode B2B Client Portal for Hog Work Industrial Hub Ltd. (portal.hogwork.com) connected natively to our existing Airtable Master Ledger.
Please review our Master Specification Document below and provide an itemized fixed-price bid and completion timeline broken down by phase (Phase 1, Phase 2, and Phase 3).
MASTER SPECIFICATION DOCUMENT (you may add comments to this Google Doc for any clarifications needed):
https://docs.google.com/document/d/1VMZslDAw_xzTu_Ucl1oY-Vwh4WuF_X5SIQ0nV8S4zPo/edit?usp=sharing
MEETING & COMMUNICATION POLICY:
Given that our project scope, database schema, and design specifications are fully detailed in the linked Master Specification Document, a preliminary discovery meeting is not necessary. If you require any technical clarification on specific block requirements or parameter links, please ask your questions directly in the Upwork chat, and we will clarify them immediately.
MANDATORY LEGAL B2B MUTUAL NDA AGREEMENT:
Before responding with your quote, please review the B2B Non-Disclosure Agreement terms below. By replying to this message with your bid, you explicitly accept and agree to the following binding parameters:
CONFIDENTIAL INFORMATION: All database schemas, software architecture, field logs, pass-code structures, rate cards, and copy specifications shared during this engagement are proprietary trade secrets of Hog Work Industrial Hub Ltd.
COVENANT OF SECRECY: You agree to hold all materials in strict confidence, use them solely for executing this project, and refrain from copying, disclosing, or reverse-engineering any system assets.
IP SOVEREIGNTY: All Airtable structures, Softr layouts, and custom CSS code injections remain the sole intellectual property of Hog Work Industrial Hub Ltd.
NON-CIRCUMVENTION & ANTI-POACHING: You agree not to bypass Hog Work to deal directly with any client, contractor, or partner disclosed in our network.
PENALTY: Any unauthorized data extraction or intellectual property breach triggers an immediate $50,000.00 CAD Technical IP Surcharge as liquidated damages under the laws of the Province of Ontario, Canada.
================================================================================
REQUIRED BID RESPONSE FORMAT:
To be considered, please reply directly with:
• Your explicit acceptance of the NDA (e.g., "I have read and agree to the HW-MNDA-2026 terms.").
• Itemized Fixed-Price Quote & Completion Timeline for Portal Phase 1 (Single-Page Command Deck).
• Itemized Fixed-Price Quotes for Portal Phase 2 and Portal Phase 3.
• Links to 2–3 Softr + Airtable multi-tenant portals you have previously built.
Phase 1 will be contracted and funded immediately via an Upwork Escrow Milestone upon developer selection. Target completion window for Phase 1 is 1 to 2 business days from kickoff.
Note: Domain DNS / CNAME bindings (portal.hogwork.com) have ALREADY been configured directly within AWS Route 53 / DNS. Your execution scope focuses strictly on Softr block configuration, Airtable pass-code authentication, Typeform modal parameter links, and custom dark-mode CSS styling.
Looking forward to your quote.
Best regards,
Jeff Senia
Principal, Hog Work Industrial Hub Ltd.
https://hogwork.com
California Attorney to Review a B2B License & NDA Agreement (Industrial Equipment)
Applied
not specified
3 days ago
Client Rank
- Good
Payment method verified
$3 475 total spent
4 hires
5 jobs posted
80% hire rate,
1 open job
4.82
of 3 reviews
Registered: Aug 10, 2017
United States
San Dimas
13:21
4
## Project Description
We are a small California-based manufacturer of engineered industrial control systems. We've prepared a draft agreement that lets our distributors/integrators facilitate remote troubleshooting access to the control software (PLC programs) on equipment we've built. We need a licensed California attorney to review the draft, flag risks, and provide a marked-up redline with plain-English explanations before we put it into use.
The document is a combined **limited software license + non-disclosure agreement**, structured as a standing master agreement that activates on a per-project basis. Roughly 8–9 pages including an exhibit. It already reflects our intended business terms — we need a professional legal review, not a drafting-from-scratch job (though we welcome suggested language where terms should be tightened).
## Scope of Work
- Review the full draft agreement for legal soundness and enforceability under California law.
- Identify risks, gaps, ambiguous language, and any clauses that are unenforceable or unfavorable.
- Confirm key provisions are properly constructed, including: confidentiality/trade-secret protection, limited license grant, IP ownership and assignment of modifications, use restrictions (no reverse engineering / no competing use / no third-party sharing), warranty-voidance for unauthorized changes, indemnification, limitation of liability (with a cap tied to project value), insurance and licensing requirements, term/termination, and governing law.
- Advise whether the on-site/remote-access model creates any licensing exposure (e.g., state electrical contractor licensing) or other regulatory issues.
- Provide a redlined version (tracked changes in Word) plus a short summary memo of the most important issues and recommendations.
## Deliverables
1. A redlined/marked-up version of the agreement (Microsoft Word, tracked changes).
2. A brief written summary (1–3 pages) of key risks, recommended changes, and any open questions for us to decide.
3. A short call (optional) to walk through the findings.
## Required Qualifications
- **Licensed, active attorney in California** (please state your bar number / status in your proposal).
- Demonstrated experience with commercial contracts, software/technology licensing, NDAs, and IP/trade-secret protection.
- Bonus: familiarity with B2B manufacturing, industrial equipment, or distributor/integrator relationships.
- Clear communicator who can explain legal issues in plain English.
## Engagement Details
- **Type:** Fixed-price, one-time review.
- **Budget:** Open — please propose your fixed fee for this scope in your bid.
- **Timeline:** Completion within one (1) week of engagement.
- **Confidentiality:** The full document contains proprietary and business-sensitive terms. We will share it only after engaging you, and we ask that you sign a mutual NDA first.
---
### Note to applicants
Please do not submit AI-generated boilerplate. Answer the screening questions directly. We're looking for a real attorney relationship we can come back to as our agreements evolve.
Client's questions:
1. Are you a licensed, active member of the California State Bar? Please provide your bar number.
2. Briefly describe your experience reviewing commercial software license and NDA agreements.
3. Have you worked with manufacturing or industrial-equipment clients? If so, describe.
4. What is your estimated turnaround for a review of this scope?
5. Are you willing to sign a mutual NDA before receiving the document?
Seeking an experienced steel detailer to produce accurate, high-quality structural steel shop drawings with fast turnaround times.
Scope of Work:
Complete fabrication/shop drawings
Erection framing plans
Member piece markings
Bill of materials (BOM)
Splice connection detailing
Fabrication dimensions and schedules
The ideal candidate will have experience with structural steel detailing, deliver precise and code-compliant drawings, and consistently meet tight deadlines.
I am seeking a consultant to review STEP files and BOM for a punch and die project. The task involves ensuring the design is suitable for punching holes in a stainless steel lid for a spice jar using an arbor press. The ideal candidate will have experience in mechanical engineering and design, with a focus on precision and material compatibility.
Please show prior stamping/die design experience in your proposal.
Client's questions:
Have you designed or reviewed a punch/die tool for sheet metal stamping? Briefly describe.
What punch/die clearance would you use for 3/16" holes in ~0.4-0.5mm stainless steel?
I have an Android APK that must be taken apart, inspected, and stress-tested so I can see exactly where attackers could slip through. The sole objective is to identify vulnerabilities—no feature work, no code recovery, just a security deep dive.
What you will do
The job calls for classic Android reverse-engineering techniques: unpack the APK, de-obfuscate where possible, step through the code with JADX or similar, and hook live calls with tools such as Frida or Xposed to watch data flow. Network traffic, storage, inter-process communication, and custom crypto routines all need attention so any flaw—from insecure logging to poorly handled intents—pops out clearly.
Expected outcome
• A concise report that lists each vulnerability, explains the risk, and shows a reproducible proof-of-concept or trace.
• Clear remediation advice for every issue you uncover.
• Screenshots or captured logs that back up your findings.
I will supply the release and debug builds, plus any credentials needed for authenticated areas. The engagement is complete once I can replicate your proofs and the report reads cleanly for my developers to action.
Mechanical Engineer for Luxury Product Mechanism Development
Applied
not specified
3 days ago
Client Rank
- Medium
Payment method verified
Phone number verified
2 jobs posted
1 open job
no reviews
Industry: Fashion & Beauty
Company size: 2
Registered: Jul 23, 2026
United States
11:21
3
I’m looking for a mechanical engineer to help develop the internal mechanical architecture for a premium luxury handbag with a concealed opening system.
This is not a traditional handbag design project. The primary challenge is engineering a refined opening experience through hidden mechanisms, moving assemblies, and a manufacturable internal chassis that will later be integrated with leather construction.
The product concept, user experience, and design intent have already been carefully developed. I’m looking for someone who enjoys solving complex mechanical problems and translating a well-defined vision into a manufacturable product.
Experience with moving mechanisms, CAD assemblies, design for manufacturing (DFM), prototyping, and production-ready engineering is highly valued.
Urgent Hiring: Integration Engineer for Intake 360!
Applied
not specified
4 days ago
Client Rank
- Excellent
Payment method verified
$141 410 total spent
15 hires, 3 active
134 jobs posted
11% hire rate,
2 open job
23.59 /hr avg hourly rate paid
5 542 hours paid
5.00
of 13 reviews
Registered: Nov 12, 2021
United States
Blue Bell
13:21
5
Important Notice to Applicants:
Please note that we are only contacting and communicating with candidates through Upwork. Any applications or direct contact made outside of these channels, including emails, social media messages, direct messages to our CEO, or messages sent to our general company email, will not be considered and will be automatically declined.
About Us:
Important Notice to Applicants:
Please note that we are only contacting and communicating with candidates through Upwork or our dedicated company HR email address. Any applications or direct contact made outside of these channels, including emails, social media messages, direct messages to our CEO, or messages sent to our general company email, will not be considered and will be automatically declined.
About the Company:
We are a private U.S.-based company operating across multiple departments that support legal, staffing, and client-service operations. Our teams collaborate in dynamic, fast-paced environments focused on innovation, integrity, and client success.
About the Role
Intake360 is a fractional intake service for law firms. We're looking for an Integration Engineer to own the integration layer between our Salesforce environment and our clients' CRMs (Litify, Filevine, SmartAdvocate, Clio, CASEpeer, and others). You will build and secure the connected apps and API integrations that move intake data between systems, and you will contribute to a team initiative to transition our bulk integrations from Salesforce Apex to AWS Lambda.
This is a hands-on, high-ownership role. You will architect your own work and present your proposals to management for sign-off before building. You won't be working alone: our in-house Apex developers own the Salesforce side of the platform, so you'll collaborate closely with them rather than reverse-engineering our Apex architecture yourself. Most of our clients are law firms whose CRM API access is granted on a request basis, so you'll need to be as comfortable coordinating with a vendor's support team as you are writing code.
What You'll Do
Design, build, and maintain integrations between our Salesforce environment and client CRMs, handling the full lifecycle: connected/custom app creation, OAuth 2.0 flows, credential management, and go-live.
Architect your integration work up front and present proposals to management for sign-off before implementation.
Collaborate with our in-house Apex developers on the transition of bulk integrations from Salesforce Apex to AWS Lambda, a joint effort where they bring the Salesforce architecture knowledge and you bring the AWS and serverless expertise.
Provision and manage AWS resources: Lambda functions, IAM users and roles with least-privilege policies, API Gateway endpoints, and event routing from Salesforce to the correct Lambda function per client firm.
Help stand up our CI/CD pipeline for serverless deployments. We're transparent: we don't have one today, and you'll play a key part in establishing it (e.g., GitHub Actions, AWS SAM, or CodePipeline).
Secure every integration you build: token storage and rotation, scoped API access, IP allowlisting where supported, and secrets management.
Implement rate limits, throttling, retry/backoff strategies, and idempotency so integrations behave well under load and respect vendor API limits.
Set up monitoring, alerting, and error logging (e.g., CloudWatch) for every integration, and triage failures before clients notice them.
Coordinate with client CRM vendors to obtain client secrets, API keys, and sandbox access, and to register custom apps in their environments.
Map and transform data across widely varying CRM schemas, documenting each client's data structure and integration behavior.
Required Qualifications
5+ years building production API integrations between SaaS platforms, ideally CRM-to-CRM.
Strong AWS Lambda experience: function design, cold-start and concurrency considerations, versioning/aliases, and deployment.
Solid IAM fundamentals: creating users and roles, writing least-privilege policies, and managing credentials safely.
Deep working knowledge of OAuth 2.0 (authorization code, client credentials, JWT bearer flows) and API authentication patterns across vendors.
Experience with API security hardening: scoping, secret rotation, encryption in transit/at rest, and audit logging.
Experience implementing rate limiting, throttling, retries, and dead-letter handling in integration pipelines.
Experience setting up or maintaining CI/CD pipelines for serverless or API workloads.
Proficiency in at least one Lambda runtime language (Node.js or Python preferred).
Self-sufficient: able to architect, document, and deliver your own work following serverless and integration best practices, with management sign-off on proposals rather than close supervision.
Nice to Have
Familiarity with Salesforce concepts: connected apps, Platform Events, and how Apex-based integrations work. Deep Apex expertise is not required — you'll work alongside our in-house Apex developers, who own that architecture.
Experience with legal industry CRMs: Litify, Filevine, SmartAdvocate, Clio, CASEpeer, or similar.
Experience with EventBridge, SQS/SNS, Step Functions, or similar event-routing services.
Infrastructure-as-code experience (SAM, Serverless Framework, Terraform, or CDK).
How We Measure Success
Vendor collaboration - You independently manage vendor relationships end to end: obtaining client secrets, registering custom apps, and acquiring API keys from client CRM vendors, including the slower request-based access processes common with law firm systems.
CRM flexibility - You quickly learn and adapt to the varying data structures of different client CRMs, producing reliable field mappings and transformations without extensive hand-holding.
Cross-team collaboration - You work effectively with our in-house Apex developers on the Apex-to-Lambda transition, and your architecture proposals are clear enough for management to review and sign off on.
Operational ownership - Integration failures are caught by your monitoring before clients report them, and error logs are actionable enough to diagnose issues within minutes.
Our Stack
Salesforce (Apex, Platform Events, Flows - maintained by our in-house team) · AWS (Lambda, IAM, CloudWatch) · REST APIs & webhooks · Node.js · Client CRMs: Litify, Filevine, SmartAdvocate, and more. CI/CD: not yet in place - you'll help build it.