Next.js/TypeScript Expert for DrawDash

Job ID: 39775178

Budget: $15 – $25 USD

Role: Senior Next.js/TypeScript Engineer (Contract)

- Build the next iteration of DrawDash, a premium raffle/draw platform focused
on trust, fairness, and great UX. You’ll drive the transition from a well-
structured mock/demo stack to a production-ready system with real auth,
payments, and provably fair draws.

About DrawDash

- Stack: Next.js (App Router), TypeScript, Tailwind, Netlify
- Data: Prisma schema (Postgres/Neon) ready; mocks currently power reads/
writes
- Payments: Demo route in place; Stripe integration planned
- Auth: Local mock; NextAuth planned
- Fairness: Cryptographically secure RNG with public audit endpoints; moving
audits server-side
- Repo hygiene: Clean, documented, and feature-flagged for safe incremental
rollout (ONBOARDING, ARCHITECTURE, ROADMAP included)

What You’ll Do

- Migrate from mocks to Prisma/Postgres behind a data-source adapter
- Implement Stripe Payments (payment intents, webhooks, DB writes)
- Introduce NextAuth with server-side sessions and RBAC for admin
- Move RNG seed commitments and audit logs server-side; expose public
verification
- Tighten security: roll out nonce-based CSP, remove unsafe inline code
- Add rate limiting/session storage backed by Redis/KV; harden API inputs
(Zod)
- Improve observability (structured logging, Sentry) and CI (type/lint/tests)
- Keep performance, accessibility, and i18n in mind as you go

You Have

- 5+ years building production-grade web apps
- Deep Next.js (App Router), TypeScript, and Tailwind experience
- Strong knowledge of Prisma/Postgres and serverless deployment (Netlify or
Vercel)
- Hands-on Stripe integration (payment intents, webhooks, idempotency,
retries)
- NextAuth or equivalent auth/session experience; role-based access control
- Security awareness: CSP, SSRF/XSS mitigation, input validation, secrets
handling
- Practical testing (unit/integration), CI, and error monitoring

Nice To Have

- Experience with regulated or payments-heavy products
- Knowledge of cryptographic RNG, auditability, and fairness verification
- Redis/KV patterns for rate limiting/sessions
- i18n frameworks (next-intl/next-i18next) and accessibility best practices
- Familiarity with Chainlink VRF or public randomness sources

Why Join

- Greenfield-to-production journey with clear roadmap and clean scaffolding
- Tight feedback loops, real user impact, and emphasis on trust/compliance
- Fast setup: mock mode for local dev, docs for quick onboarding, feature
flags for safe rollout

Engagement Details

- Contract: 15–30 hrs/week to start (flexible), option to scale up
- Location: Remote (EU-friendly hours preferred)
- Start: Immediate
- Tools: GitHub, Netlify, Postgres/Neon, Stripe, Sentry (to be added), Redis/
KV (to be added)

First 4–6 Weeks Deliverables

- NextAuth live with RBAC for admin routes
- Stripe payment flow end-to-end with secure webhooks and DB persistence
- Prisma read-paths in production behind adapter; write-paths migrated for
core flows
- Server-side RNG audit storage + public verification endpoint
- Baseline CI (type-check, lint, minimal tests) and Sentry configured

How To Apply

- Send:
- Short intro and relevant experience
- Links to GitHub or shipped projects (Next.js/Stripe/Prisma work)
- Availability (hours/week, timezone) and hourly rate
- Brief note on your approach to rolling out Stripe+NextAuth safely in a
live app
Related categories: Cryptography PostgreSQL Redis Stripe Security Next.js Netlify CI/CD