Nima Shahmoradi — Toronto, ON

Senior developer

Senior Front-End Developer with 5+ years of experience designing and optimizing enterprise-scale web applications. Expert in React, TypeScript, and scalable component architectures — with a strong emphasis on performance, security, and maintainability.

terminal://nimashahmoradi
┌───────────────────────┐
│  ███╗  ██╗███████╗    │
│  ████╗ ██║██╔════╝    │
│  ██╔██╗██║███████╗    │
│  ██║╚████║╚════██║    │
│  ██║ ╚███║███████║    │
│  ╚═╝  ╚══╝╚══════╝    │
│                       │
│  > role: Sr. FE Dev   │
│  > status: busy       │
└───────────────────────┘
5+ yrs exp
Secure by Design

Artifacts

Selected Projects

Featured
shipped
2024

Enterprise Risk Analysis Dashboard

Built and optimized a large-scale React dashboard for enterprise risk analysis, enabling users to paginate, filter, and transform complex datasets with high responsiveness. Improved maintainability through strict TypeScript contracts, reusable component architecture, and performance-focused rendering patterns.

frontend
ReactTypeScriptRedux ToolkitRTK QueryMaterial UITailwind CSS
shipped
2023

High-Performance Data Grid & Filtering System

Developed advanced pagination, filtering, and client-side data transformation logic for large enterprise datasets. Leveraged Redux Toolkit and React memoization patterns to reduce unnecessary re-renders and maintain smooth UI performance under heavy data loads.

frontend
ReactTypeScriptRedux ToolkituseMemouseCallbackData Tables
shipped
2023

Reusable UI Component System

Standardized shared UI patterns across enterprise applications by building reusable components with Material UI and Tailwind CSS. Improved design consistency, responsiveness, and accessibility while accelerating feature delivery through a more scalable component architecture.

frontend
ReactMaterial UITailwind CSSDesign SystemAccessibilityComponent Library
shipped
2023

Scalable TypeScript Refactor for Enterprise UI

Refactored legacy React modules into strongly typed, hook-based functional components to improve scalability and developer experience. Introduced reusable interfaces and stricter typing conventions that reduced ambiguity and made the codebase significantly easier to extend and maintain.

frontend
ReactTypeScriptRefactoringHooksFunctional ComponentsArchitecture
shipped
2023

API Caching & Data Fetching Architecture

Modernized asynchronous data handling by integrating RTK Query to replace legacy fetch logic. Streamlined API communication, improved caching behavior, reduced boilerplate, and created a more predictable data flow across multiple enterprise application modules.

frontend
ReactTypeScriptRTK QueryAPI IntegrationCachingState Management
shipped
2022

Next-Gen POS Interface

Next-generation Point of Sale interface for Volante Systems, improving transaction speed and UX by 35%. Built with React, Redux Toolkit, RTK Query, and styled with Material UI and Tailwind CSS. Integrated real-time inventory and sales analytics with Azure DevOps CI/CD.

frontend
ReactTypeScriptRedux ToolkitRTK QueryMaterial UI
shipped
2024

Secure Frontend Implementation

Applied secure frontend engineering practices across React applications, including input validation, safer API interaction patterns, and mitigation of common web risks such as XSS, injection vectors, and insecure data exposure. Strengthened the security posture of production-facing interfaces without sacrificing usability.

security
ReactTypeScriptXSS PreventionInput ValidationSecure CodingAppSec
shipped
2024

Secure React Component Library

Storybook-documented React component library with built-in XSS sanitization, CSRF token handling, and strict Content Security Policy headers. Production-ready with open-source distribution.

security
ReactTypeScriptStorybookCSPXSS
shipped
2024

Real-Time Threat Detection Dashboard

SOC analyst dashboard built with React and D3.js, ingesting simulated network logs and visualizing anomaly spikes, SYN flood patterns, and DDoS indicators in real time.

blue-team
ReactD3.jsNode.jsWebSockets
shipped
2024

OAuth2 / JWT Secure Auth System

Full OAuth2 authorization code flow with PKCE and JWT refresh token rotation. Built with React and Node.js, covering token storage best practices and session hijacking prevention.

security
ReactNode.jsOAuth2JWTPKCE
in-progress
2025

Azure DevSecOps Pipeline

CI/CD pipeline with integrated SAST static analysis, dependency vulnerability scanning via npm audit and Snyk, and automated security gate enforcement before deployment on Azure Pipelines.

devsecops
Azure DevOpsCI/CDSnykSASTDocker
Featured
shipped
2025

SOC Sentinel — Real-Time Security Operations Dashboard

Built a full-stack SOC-style operations dashboard with live threat feeds over WebSockets, buffered event history, pause/filter controls, and keyboard shortcuts. Implemented a backend threat pipeline with configurable simulation modes, MITRE tactic to kill-chain mapping, event correlation into incidents (time-windowed, per-source-IP), geo intelligence, and IP reputation scoring. Delivered analyst-grade features: SOAR-style rules, blocked IP management, saved searches, incident notes, session replay, and report export — all persisted to SQLite.

blue-team
React 18TypeScriptD3.jsNode.jsWebSocketSQLiteDockerMITRE ATT&CK
shipped
2025

JWT Attack Demo — Security Education Platform

Engineered a full-stack JWT vulnerability analysis platform that performs real attack simulations without JWT libraries, using manual base64url parsing and Node.js crypto. Implemented three parallel attack modules — alg:none downgrade forgery, HMAC brute-force via weak-secret dictionaries, and replay weakness detection across exp/nbf/jti/iat — each returning structured risk reports with MITRE ATT&CK-aligned tags. Built a React frontend with token paste/load/clear controls, instant client-side decode validation, and tabbed attack result visualization for SOC analyst and engineer workflows.

red-team
ReactTypeScriptNode.jsExpressJWTHMACMITRE ATT&CKSecurity Education
shipped
2024

Web Application Exploit Chain

Chained XSS + CSRF + insecure JWT vulnerabilities in a React/Node.js app to achieve full account takeover simulation. Includes a detailed remediation report with code-level fixes.

red-team
Red TeamXSSCSRFJWTNode.js
shipped
2024

Packet Capture Analysis Pipeline

Wireshark + Python pipeline that captures live traffic, parses PCAP files, and outputs structured threat reports identifying ARP anomalies, SSL handshake failures, and port scan signatures.

blue-team
PythonWiresharkPCAPNetwork Security

Work History

Experience

5+ years delivering production-grade frontend systems across insurance, gaming, and cybersecurity.

Senior Frontend Developer

Current

Pong Game Studios

Toronto, ON

Apr 2023 – Present[ collapse ]
  • Refactored enterprise-level React apps using TypeScript with functional components, hooks, and strict typing for improved maintainability.
  • Built advanced pagination, filtering, and data transformation for large-scale dashboards with Redux Toolkit and React performance hooks (useMemo, useCallback).
  • Styled and standardized UI components using Material UI and Tailwind CSS, delivering responsive and accessible interfaces.
  • Integrated RTK Query for efficient API communication and caching, replacing legacy fetch logic to streamline data flows.
  • Applied secure coding practices — input validation, XSS/injection mitigation, and secure API interaction patterns.
  • Collaborated with backend and DevOps on secure auth mechanisms (JWT, OAuth2) ensuring protected resource access.
ReactTypeScriptRedux ToolkitRTK QueryMaterial UITailwind CSS

Application and Systems Developer

Liberty Mutual Canada

Toronto, ON

Aug 2020 – Mar 2022[ expand ]

Network Packet Analyzer Course Instructor

HydroOne on behalf of NobleProg

Mississauga, ON

May 2024[ expand ]

Technical Stack

Skills & Certifications

A full-spectrum toolkit spanning front-end engineering, backend integration, secure software development lifecycle, and SOC-level security engineering.

Front-End

ReactNext.jsAngularTypeScriptRedux ToolkitRTK QuerySPA DevelopmentPerformance Optimization

UI & Styling

Tailwind CSSMaterial UIStyled ComponentsAnt DesignBootstrapSassFigma

Backend & APIs

Node.jsExpress.jsRESTful APIsGraphQLApollo ClientJava Spring BootJWTOAuth2

Secure Coding & CSSLP

Secure SDLCThreat ModelingSecurity RequirementsSecure Design PatternsInput ValidationOutput EncodingLeast PrivilegeDefense in DepthSecure Code ReviewOWASP Top 10

SOC & Security Engineering

SIEM AnalysisIncident ResponseLog CorrelationVulnerability AssessmentNetwork Traffic AnalysisWiresharkCVE TriageSecurity HardeningISO 27001NIST Framework

DevOps & CI/CD

GitDockerKubernetesAzure DevOpsAzure PipelinesJenkinsGitHub ActionsWebpackBabel

Cloud & Tools

AWSAzure ReposStorybookJiraAgile / Scrum

Certifications

2021Microsoft

Microsoft Certified Solutions Expert: Security (MCSE)

2021Microsoft

Microsoft Certified Solutions Associate (MCSA)

2021Microsoft

Microsoft Certified Trainer (MCT)