Сервіс пошуку роботи №1 в Україні
Yaroslav
Front-end програміст
- Розглядає посади:
- Front-end програміст, AI-розробник
- Вік:
- 29 років
- Місто проживання:
- Хмельницький
- Готовий працювати:
- Дистанційно, Хмельницький
Контактна інформація
Шукач вказав: Телефон
Прізвище, контакти та світлина доступні тільки для зареєстрованих роботодавців. Щоб отримати доступ до особистих даних кандидатів, увійдіть як роботодавець або зареєструйтеся.
Отримати контакти цього кандидата можна на сторінці https://www.work.ua/resumes/10457550/
Завантажений файл
Версія для швидкого
перегляду
Це резюме розміщено у вигляді файлу. Ця версія для швидкого перегляду може бути гіршою за оригінал резюме.
Yaroslav PROFILE
Kovalchuk Fullstack Developer with commercial experience building web interfaces across the full complexity range — from
landing and corporate sites to CRMs, dashboards, and full SPA/SSR applications. Strong in the Vue ecosystem
Fullstack Developer · Security-minded (Vue 2/3, Nuxt) and confident with React + TypeScript, with hands-on experience building frontend inside Laravel
monoliths (Blade + Alpine.js).
Applies a security mindset while building — testing the projects I develop for vulnerabilities using OWASP
methodology (Top 10, WSTG): input validation, XSS/CSRF/injection awareness, and access control. Conducted
a full grey-box web assessment of a production SPA.
SKILLS
Languages: JavaScript, TypeScript, HTML5, CSS3
Frameworks & Libraries: Vue 2/3, Nuxt, Pinia, Vuex, Vue Router, vue-i18n, React, TanStack Query, Zustand,
React Router
C O N TA C T
UI & Styling: Tailwind CSS, SCSS/Sass, BEM, PrimeVue, PrimeReact, Bootstrap, Headless UI, GSAP, AOS,
Swiper, Chart.js, ApexCharts
✈ @yaroslav_kovalchuk972
Frontend in Laravel: Blade + Alpine.js, jQuery, DataTables
● Khmelnytskyi, Ukraine
Tools & Build: Vite, Webpack (Vue CLI), Gulp, Laravel Mix, Git (GitHub/GitLab), Figma, Chrome DevTools, Docker
(basic), Firebase, Vercel
C O R E S TA C K
Data / API: REST API, Axios, MySQL (queries), form validation (Yup, Vuelidate)
Frontend Security — hands-on: OWASP WSTG v4.2 & Top 10, grey-box web assessment, access control / IDOR / BOLA
Vue 2/3, Nuxt, Pinia, React, TypeScript testing, authentication & JWT/session security, input validation, TLS/cipher analysis. Tools: Nmap, OWASP ZAP,
Styling Postman, curl, OpenVAS.
Tailwind, SCSS, BEM, PrimeVue Security — fundamentals: Networking (OSI & TCP/IP, subnetting, TCP/UDP, DNS, DHCP, TLS, HTTP/HTTPS,
Security SSH); Linux CLI (permissions, processes, package mgmt); basic Windows / Active Directory.
OWASP WSTG / Top 10 Practices: Responsive, cross-browser, semantic, SEO-friendly markup; pixel-perfect from Figma; component-
based architecture; ESLint, Prettier, BEM.
SECURITY HIGHLIGHTS Soft skills: Communication, teamwork, problem-solving, accountability, attention to detail, adaptability, proactivity,
UX mindset.
Grey-box web assessment (WSTG v4.2)
29 findings · 3 High-severity PROFESSIONAL EXPERIENCE
Nmap · OWASP ZAP · Postman · curl · OpenVAS
Fullstack Developer — IT Company
09/2024 – Present
LANGUAGES
Delivered frontend for commercial projects of varying complexity (all under NDA):
Ukrainian Static & landing pages — responsive, cross-browser, semantic, SEO-friendly markup from Figma (pixel-
perfect).
English (B2)
Corporate / content websites — multi-page sites in Laravel monoliths using Blade + Alpine.js, with
i18n/localization, forms, and interactive UI wired to existing backend endpoints.
E D U C AT I O N
CRM & admin dashboards — dynamic data tables, filtering, data export (CSV/XLSX), drag-and-drop, and real-
time UI updates.
MSc, Software Engineering
Western Ukrainian National University (ZUNU) SPA / SSR applications — Vue 2/3 & Nuxt apps with Pinia/Vuex state, routing, REST API integration, reusable
09/2025 – 12/2026 · Ternopil component architectures; integrated payment and identity-verification flows on the UI side.
MSc, Law Integrated animations (GSAP, AOS), sliders (Swiper), and charts (Chart.js/ApexCharts).
Yaroslav Mudryi National Law University Collaborated in an Agile team with designers, PM, QA, and Team Lead; detected and fixed bugs, optimized
09/2014 – 01/2021 · Kharkiv UI/UX, followed code standards (ESLint, Prettier, BEM).
Security-by-design: detected and remediated client-side XSS sinks; applied input-validation and access-
COURSES control awareness in day-to-day frontend work.
Front-end Development Fullstack Developer — Freelance
Stfalcon School · 02/2023 – 06/2023 · Khmelnytskyi 07/2023 – 09/2024
HTML5, CSS3, SCSS, JS, Bootstrap, Vue.js, Vuex, Pinia, Developed and supported commercial web projects with Vanilla JS, Vue 2/3, and Vuex/Pinia.
Git, npm, Figma
Built responsive interfaces with Bootstrap and Tailwind CSS, optimizing UI/UX.
Used Gulp.js for build tooling.
CYBERSECURITY
While developing projects, I also test them for vulnerabilities — applying web-application security testing
following OWASP methodology (Top 10 & WSTG — Web Security Testing Guide).
Grey-box security assessment of a production SPA (Vue 3 + Laravel REST API):
Conducted a structured WSTG v4.2 assessment covering Information Gathering, Configuration, Authentication,
Authorization, Session, Business Logic, and Cryptography.
29 findings, including 3 High-severity — chained an account-takeover path from user enumeration + no
account-lockout + weak password policy; identified broken access control (IDOR/BOLA), mass-assignment, and
misconfiguration issues.
Verified secure controls too (positive testing): JWT hardening (alg:none rejected, jti-blacklist logout), server-
derived pricing against payment tampering, TLS class-A cipher suite.
Delivered a professional report (per-test methodology, evidence, severity, remediation) plus an HTML findings
dashboard.
Tooling: Nmap (recon, TLS/cipher analysis), OWASP ZAP, Postman (API auth/BOLA testing), curl (header &
session analysis), OpenVAS.
Kovalchuk Fullstack Developer with commercial experience building web interfaces across the full complexity range — from
landing and corporate sites to CRMs, dashboards, and full SPA/SSR applications. Strong in the Vue ecosystem
Fullstack Developer · Security-minded (Vue 2/3, Nuxt) and confident with React + TypeScript, with hands-on experience building frontend inside Laravel
monoliths (Blade + Alpine.js).
Applies a security mindset while building — testing the projects I develop for vulnerabilities using OWASP
methodology (Top 10, WSTG): input validation, XSS/CSRF/injection awareness, and access control. Conducted
a full grey-box web assessment of a production SPA.
SKILLS
Languages: JavaScript, TypeScript, HTML5, CSS3
Frameworks & Libraries: Vue 2/3, Nuxt, Pinia, Vuex, Vue Router, vue-i18n, React, TanStack Query, Zustand,
React Router
C O N TA C T
UI & Styling: Tailwind CSS, SCSS/Sass, BEM, PrimeVue, PrimeReact, Bootstrap, Headless UI, GSAP, AOS,
Swiper, Chart.js, ApexCharts
✈ @yaroslav_kovalchuk972
Frontend in Laravel: Blade + Alpine.js, jQuery, DataTables
● Khmelnytskyi, Ukraine
Tools & Build: Vite, Webpack (Vue CLI), Gulp, Laravel Mix, Git (GitHub/GitLab), Figma, Chrome DevTools, Docker
(basic), Firebase, Vercel
C O R E S TA C K
Data / API: REST API, Axios, MySQL (queries), form validation (Yup, Vuelidate)
Frontend Security — hands-on: OWASP WSTG v4.2 & Top 10, grey-box web assessment, access control / IDOR / BOLA
Vue 2/3, Nuxt, Pinia, React, TypeScript testing, authentication & JWT/session security, input validation, TLS/cipher analysis. Tools: Nmap, OWASP ZAP,
Styling Postman, curl, OpenVAS.
Tailwind, SCSS, BEM, PrimeVue Security — fundamentals: Networking (OSI & TCP/IP, subnetting, TCP/UDP, DNS, DHCP, TLS, HTTP/HTTPS,
Security SSH); Linux CLI (permissions, processes, package mgmt); basic Windows / Active Directory.
OWASP WSTG / Top 10 Practices: Responsive, cross-browser, semantic, SEO-friendly markup; pixel-perfect from Figma; component-
based architecture; ESLint, Prettier, BEM.
SECURITY HIGHLIGHTS Soft skills: Communication, teamwork, problem-solving, accountability, attention to detail, adaptability, proactivity,
UX mindset.
Grey-box web assessment (WSTG v4.2)
29 findings · 3 High-severity PROFESSIONAL EXPERIENCE
Nmap · OWASP ZAP · Postman · curl · OpenVAS
Fullstack Developer — IT Company
09/2024 – Present
LANGUAGES
Delivered frontend for commercial projects of varying complexity (all under NDA):
Ukrainian Static & landing pages — responsive, cross-browser, semantic, SEO-friendly markup from Figma (pixel-
perfect).
English (B2)
Corporate / content websites — multi-page sites in Laravel monoliths using Blade + Alpine.js, with
i18n/localization, forms, and interactive UI wired to existing backend endpoints.
E D U C AT I O N
CRM & admin dashboards — dynamic data tables, filtering, data export (CSV/XLSX), drag-and-drop, and real-
time UI updates.
MSc, Software Engineering
Western Ukrainian National University (ZUNU) SPA / SSR applications — Vue 2/3 & Nuxt apps with Pinia/Vuex state, routing, REST API integration, reusable
09/2025 – 12/2026 · Ternopil component architectures; integrated payment and identity-verification flows on the UI side.
MSc, Law Integrated animations (GSAP, AOS), sliders (Swiper), and charts (Chart.js/ApexCharts).
Yaroslav Mudryi National Law University Collaborated in an Agile team with designers, PM, QA, and Team Lead; detected and fixed bugs, optimized
09/2014 – 01/2021 · Kharkiv UI/UX, followed code standards (ESLint, Prettier, BEM).
Security-by-design: detected and remediated client-side XSS sinks; applied input-validation and access-
COURSES control awareness in day-to-day frontend work.
Front-end Development Fullstack Developer — Freelance
Stfalcon School · 02/2023 – 06/2023 · Khmelnytskyi 07/2023 – 09/2024
HTML5, CSS3, SCSS, JS, Bootstrap, Vue.js, Vuex, Pinia, Developed and supported commercial web projects with Vanilla JS, Vue 2/3, and Vuex/Pinia.
Git, npm, Figma
Built responsive interfaces with Bootstrap and Tailwind CSS, optimizing UI/UX.
Used Gulp.js for build tooling.
CYBERSECURITY
While developing projects, I also test them for vulnerabilities — applying web-application security testing
following OWASP methodology (Top 10 & WSTG — Web Security Testing Guide).
Grey-box security assessment of a production SPA (Vue 3 + Laravel REST API):
Conducted a structured WSTG v4.2 assessment covering Information Gathering, Configuration, Authentication,
Authorization, Session, Business Logic, and Cryptography.
29 findings, including 3 High-severity — chained an account-takeover path from user enumeration + no
account-lockout + weak password policy; identified broken access control (IDOR/BOLA), mass-assignment, and
misconfiguration issues.
Verified secure controls too (positive testing): JWT hardening (alg:none rejected, jti-blacklist logout), server-
derived pricing against payment tampering, TLS class-A cipher suite.
Delivered a professional report (per-test methodology, evidence, severity, remediation) plus an HTML findings
dashboard.
Tooling: Nmap (recon, TLS/cipher analysis), OWASP ZAP, Postman (API auth/BOLA testing), curl (header &
session analysis), OpenVAS.
Інші резюме цього кандидата
Схожі кандидати
-
Front-end програміст
20000 грн, Київ, Дистанційно -
Front-end програміст
50000 грн, Дистанційно -
Front-end Developer
40300 грн, Івано-Франківськ, Львів , ще 4 міста -
Front-end програміст
Київ, Дистанційно -
Front-end програміст
Дистанційно -
Front-end програміст
Інші країни, Дистанційно