Responsibilities
- Design, develop and operate distributed Gateway services with focus on high availability, low latency, scalability and security.
- Write production-grade, well-tested, idiomatic code in Go and TypeScript/Node.js and Lua, with measurable impact on latency, reliability and security.
- Contribute to the technical design of new Gateway features and to high-level architecture decisions.
- Drive the evolution toward a self-serve, API-driven Gateway in AWS so that internal customers (game teams, online services) can onboard their routes safely without manual intervention.
- Embed security by design into the Gateway: threat modeling, OWASP API Security Top 10 mitigations, WAF and edge protection policies, hardening of routing, authentication and rate-limiting layers.
- Provision and operate Gateway infrastructure with infrastructure-as-code (Terraform, AWS CDK or CloudFormation).
- Build observability into everything: metrics, structured logs, traces, SLO-driven alerting.
- Be part of an agile team collaboratively working on technical designs, new features and steady improvements of existing code.
- Mentor and support less experienced colleagues; participate in code reviews and architecture discussions.
- Debug, profile and improve the existing code base under production load.
Requirements
- Production-grade coding experience in Go, TypeScript/Node.js, or Lua
- Experience designing and operating distributed systems with focus on high availability, low latency, scalability, and security
- Experience with infrastructure-as-code tools such as Terraform, AWS CDK, or CloudFormation
- Ability to contribute to technical design and high-level architecture decisions
- Experience building observability: metrics, structured logs, traces, SLO-driven alerting
- Experience in agile development environments
- Ability to debug, profile, and improve code under production load
- Experience mentoring or supporting less experienced developers
Nice to Have
- Experience with security by design principles: threat modeling, OWASP API Security Top 10, WAF, edge protection, routing, authentication, and rate-limiting hardening