• Файл

Yaroslav

Front-end програміст

Розглядає посади:
Front-end програміст, AI-розробник
Вік:
29 років
Місто проживання:
Хмельницький
Готовий працювати:
Дистанційно, Хмельницький

Контактна інформація

Шукач вказав: Телефон

Прізвище, контакти та світлина доступні тільки для зареєстрованих роботодавців. Щоб отримати доступ до особистих даних кандидатів, увійдіть як роботодавець або зареєструйтеся.

Завантажений файл

Версія для швидкого перегляду

Це резюме розміщено у вигляді файлу. Ця версія для швидкого перегляду може бути гіршою за оригінал резюме.

Yaroslav PROFILE

Kovalchuk Fullstack Developer with commercial experience building web interfaces across the full complexity range — from
landing and corporate sites to CRMs, dashboards, and full SPA/SSR applications. Strong in the Vue ecosystem
Fullstack Developer · Security-minded (Vue 2/3, Nuxt) and confident with React + TypeScript, with hands-on experience building frontend inside Laravel
monoliths (Blade + Alpine.js).
Applies a security mindset while building — testing the projects I develop for vulnerabilities using OWASP
methodology (Top 10, WSTG): input validation, XSS/CSRF/injection awareness, and access control. Conducted
a full grey-box web assessment of a production SPA.

SKILLS

Languages: JavaScript, TypeScript, HTML5, CSS3
Frameworks & Libraries: Vue 2/3, Nuxt, Pinia, Vuex, Vue Router, vue-i18n, React, TanStack Query, Zustand,
React Router
C O N TA C T
UI & Styling: Tailwind CSS, SCSS/Sass, BEM, PrimeVue, PrimeReact, Bootstrap, Headless UI, GSAP, AOS,
Swiper, Chart.js, ApexCharts
✈ @yaroslav_kovalchuk972
Frontend in Laravel: Blade + Alpine.js, jQuery, DataTables
● Khmelnytskyi, Ukraine
Tools & Build: Vite, Webpack (Vue CLI), Gulp, Laravel Mix, Git (GitHub/GitLab), Figma, Chrome DevTools, Docker
(basic), Firebase, Vercel
C O R E S TA C K
Data / API: REST API, Axios, MySQL (queries), form validation (Yup, Vuelidate)
Frontend Security — hands-on: OWASP WSTG v4.2 & Top 10, grey-box web assessment, access control / IDOR / BOLA
Vue 2/3, Nuxt, Pinia, React, TypeScript testing, authentication & JWT/session security, input validation, TLS/cipher analysis. Tools: Nmap, OWASP ZAP,
Styling Postman, curl, OpenVAS.
Tailwind, SCSS, BEM, PrimeVue Security — fundamentals: Networking (OSI & TCP/IP, subnetting, TCP/UDP, DNS, DHCP, TLS, HTTP/HTTPS,
Security SSH); Linux CLI (permissions, processes, package mgmt); basic Windows / Active Directory.
OWASP WSTG / Top 10 Practices: Responsive, cross-browser, semantic, SEO-friendly markup; pixel-perfect from Figma; component-
based architecture; ESLint, Prettier, BEM.
SECURITY HIGHLIGHTS Soft skills: Communication, teamwork, problem-solving, accountability, attention to detail, adaptability, proactivity,
UX mindset.
Grey-box web assessment (WSTG v4.2)
29 findings · 3 High-severity PROFESSIONAL EXPERIENCE
Nmap · OWASP ZAP · Postman · curl · OpenVAS
Fullstack Developer — IT Company
09/2024 – Present
LANGUAGES
Delivered frontend for commercial projects of varying complexity (all under NDA):
Ukrainian Static & landing pages — responsive, cross-browser, semantic, SEO-friendly markup from Figma (pixel-
perfect).
English (B2)
Corporate / content websites — multi-page sites in Laravel monoliths using Blade + Alpine.js, with
i18n/localization, forms, and interactive UI wired to existing backend endpoints.
E D U C AT I O N
CRM & admin dashboards — dynamic data tables, filtering, data export (CSV/XLSX), drag-and-drop, and real-
time UI updates.
MSc, Software Engineering
Western Ukrainian National University (ZUNU) SPA / SSR applications — Vue 2/3 & Nuxt apps with Pinia/Vuex state, routing, REST API integration, reusable
09/2025 – 12/2026 · Ternopil component architectures; integrated payment and identity-verification flows on the UI side.
MSc, Law Integrated animations (GSAP, AOS), sliders (Swiper), and charts (Chart.js/ApexCharts).
Yaroslav Mudryi National Law University Collaborated in an Agile team with designers, PM, QA, and Team Lead; detected and fixed bugs, optimized
09/2014 – 01/2021 · Kharkiv UI/UX, followed code standards (ESLint, Prettier, BEM).
Security-by-design: detected and remediated client-side XSS sinks; applied input-validation and access-
COURSES control awareness in day-to-day frontend work.

Front-end Development Fullstack Developer — Freelance
Stfalcon School · 02/2023 – 06/2023 · Khmelnytskyi 07/2023 – 09/2024
HTML5, CSS3, SCSS, JS, Bootstrap, Vue.js, Vuex, Pinia, Developed and supported commercial web projects with Vanilla JS, Vue 2/3, and Vuex/Pinia.
Git, npm, Figma
Built responsive interfaces with Bootstrap and Tailwind CSS, optimizing UI/UX.
Used Gulp.js for build tooling.

CYBERSECURITY

While developing projects, I also test them for vulnerabilities — applying web-application security testing
following OWASP methodology (Top 10 & WSTG — Web Security Testing Guide).
Grey-box security assessment of a production SPA (Vue 3 + Laravel REST API):
Conducted a structured WSTG v4.2 assessment covering Information Gathering, Configuration, Authentication,
Authorization, Session, Business Logic, and Cryptography.
29 findings, including 3 High-severity — chained an account-takeover path from user enumeration + no
account-lockout + weak password policy; identified broken access control (IDOR/BOLA), mass-assignment, and
misconfiguration issues.
Verified secure controls too (positive testing): JWT hardening (alg:none rejected, jti-blacklist logout), server-
derived pricing against payment tampering, TLS class-A cipher suite.
Delivered a professional report (per-test methodology, evidence, severity, remediation) plus an HTML findings
dashboard.
Tooling: Nmap (recon, TLS/cipher analysis), OWASP ZAP, Postman (API auth/BOLA testing), curl (header &
session analysis), OpenVAS.

Інші резюме цього кандидата

Схожі кандидати

Усі схожі кандидати


Порівняйте свої вимоги та зарплату з вакансіями інших підприємств: