Skip to main content
Joey KubalakSoftware Engineer

I build secure, high-craft web products.

Product-minded software engineer shipping TypeScript applications and production websites with React, Next.js, thoughtful UX, and security built into the architecture.

CompTIA Security+A.A.S. Information SecurityPennsylvania · Remote
Selected evidence

Selected work

Production launches, privacy-sensitive products, and developer tooling. Each record separates what shipped from what still needs to be proven.

Production client launch

Ascension Roofing

Strategy, design, engineering, migration, and launch

Ascension Roofing production homepage showing its roofing-first introduction and real project photography.
Release record
State
Live
E2E
27 / 27
A11y lab
100
Perf lab
94

A roofing-first Next.js rebuild that turns real project evidence into a clear estimate path without sacrificing search, email, or operational continuity.

Problem

Replace a legacy WordPress site with a faster, more trustworthy experience while preserving protected URLs, client-owned email, and a recoverable cutover.

Decisions

  • Structured the experience around roofing decisions and documented work instead of generic service claims.
  • Kept analytics consent-first and lead events free of form PII.
  • Documented redirects, DNS, email continuity, rollback, and ownership before production cutover.

Verified evidence

  • Owner-approved production launch on August 25, 2026.
  • 27 of 27 end-to-end release checks passed across the critical journey.
  • Mobile lab audits recorded 94 performance, 100 accessibility, and 100 best practices.

Evidence boundaryLaunch and lab evidence only. Lead, ranking, revenue, and ROI outcomes are not yet established.

Next.js 16TypeScriptPlaywrightResendGA4

Deployed validation product

PresentSphere

Product strategy, full-stack engineering, and privacy model

PresentSphere product interface showing the private gift-planning experience.
Privacy model
State
Deployed
Data layer
RLS
Coordination
Surprise-safe
Billing
Feature-gated

A private gift-planning product for families and close friends, designed to coordinate useful ideas without exposing surprise-safe activity.

Problem

Make birthdays, preferences, wishlists, and gift coordination useful to a trusted group without turning private relationships into public profile data.

Decisions

  • Enforced visibility at the Postgres layer with Row Level Security instead of relying on interface hiding.
  • Separated recipient-visible information from buyer coordination through a Surprise Mode privacy model.
  • Integrated authentication, invitations, transactional email, and feature-gated billing around one product contract.

Verified evidence

  • The validation product is deployed and available on its canonical domain.
  • Every application table is governed by Row Level Security policies.
  • The repository includes dedicated content, provider, redirect, RLS, and authenticated visual-test contracts.

Evidence boundaryValidation-stage product. This record does not claim user adoption, retention, or subscription revenue.

Next.js 16React 19SupabasePostgres RLSStripe

Production business platform

Codorus Web

Founder, product strategy, design, engineering, and operations

Codorus Web production homepage presenting founder-led website services and client proof.
Delivery profile
State
Live
Output
Static
UI runtime
None
Claims
Evidence-gated

A separate, roofing-first client platform built to market custom website services without diluting the employment-focused Build With Treez portfolio.

Problem

Give service-business owners a clear buying journey and honest proof while keeping review builds, form delivery, indexing, and public claims under explicit release control.

Decisions

  • Used Astro static output so the public experience ships ordinary HTML and CSS with no UI framework runtime.
  • Created source-controlled gates for indexing, form delivery, public claims, and cross-brand boundaries.
  • Published production work with explicit permission and kept unmeasured business outcomes out of the story.

Verified evidence

  • The standalone business site launched publicly on August 7, 2026.
  • The approved Ascension production record was published on August 25, 2026.
  • Release checks cover responsive layouts, JavaScript-off behavior, accessibility references, metadata, forms, and security headers.

Evidence boundaryProduction and release evidence only. Search discovery, leads, conversions, and revenue remain measurement questions.

AstroTypeScriptStatic HTMLNetlifyRelease gates

Phase 0 security prototype

Identity OS

Product architecture, threat modeling, and technical spikes

Identity OS Phase 0 interface prototype visualizing account trust and security controls.
Decision register
State
Phase 0
Auth spike
Open
Realtime spike
Open
Production
Not ready

A security control-center concept for passkeys, live sessions, trusted devices, OAuth applications, scoped API keys, and a visible audit trail.

Problem

Turn fragmented account-security settings into one understandable trust map where access can be inspected and revoked in real time.

Decisions

  • Bounded the product to its own ecosystem rather than presenting it as a third-party identity provider.
  • Made WebAuthn, OAuth authorization, and server-sent-event viability explicit decision gates before feature implementation.
  • Established architecture, security, and threat-model authorities before treating the skeleton as a product.

Verified evidence

  • The Phase 0 repository contains the application skeleton and source-controlled architecture package.
  • CI is configured to run type checking, linting, and the production build.
  • Security and threat-model documents define protected assets, trust boundaries, and open decisions.

Evidence boundaryPhase 0 only. The project is not production-ready and its final name and platform decisions remain open.

Next.js 16TypeScriptPostgresWebAuthnSSE

Validated beta tooling

AI Engineering Operating System

Systems design, TypeScript CLI, schemas, and contract testing

AI Engineering Operating System command-line output showing governed workflow state and the next authorized action.
Kernel contract
State
Beta
Profiles
4
Authority
Ledger
Provider
Neutral

Provider-neutral, local-first workflow governance for product discovery, repository intelligence, implementation planning, and evidence-backed delivery.

Problem

Keep scope, authority, evidence, approvals, and next actions durable when work moves between people, models, and fresh coding sessions.

Decisions

  • Made a versioned JSON ledger the sole workflow-state authority instead of relying on copied chat summaries.
  • Used deterministic CLI commands, digest bindings, stable exit codes, and review gates to make handoffs inspectable.
  • Kept model choice outside the kernel so repository data does not need to pass through a provider API.

Verified evidence

  • Discovery and audit workflows were exercised on a production repository and a greenfield build.
  • The v2 TypeScript kernel includes automated coverage for CLI, schema, state, and delivery-interface contracts.
  • Four profiles share one governed delivery kernel and repository-local next-action packet.

Evidence boundaryValidated beta. The v2 kernel still needs broader dogfooding, and licensing and contributor guidance are pending.

TypeScriptNode.js 22JSON SchemaAJVVitest

Where source is public, the repositories show the systems, contracts, and engineering decisions behind the work.

Browse GitHub

How I engineer

I'm Joey Kubalak, a product-minded software engineer who cares about how a system feels, how it fails, and how confidently it can be released.

  1. Product judgment

    I translate user needs, business constraints, and interface decisions into one shippable product contract.

    Discovery, information architecture, interaction design, and implementation stay connected.

  2. Security in the architecture

    Authorization, privacy, validation, and recovery are designed into the system instead of added after the interface is finished.

    Security+ foundation, Postgres RLS, threat modeling, PII boundaries, and secure release practices.

  3. Proof before claims

    I treat verification and honest outcome boundaries as part of the work, not as cleanup before a launch.

    Type checks, browser tests, accessibility review, release gates, rollback plans, and post-launch measurement.

Working set

Tools are selected for the product and its constraints. These are the ones carrying the current body of work.

Core engineering
TypeScript, React, Next.js, Node.js, PostgreSQL, Supabase
Interface & delivery
HTML, CSS, Astro, Three.js, Playwright, Figma, Vercel, Netlify
Security practice
Row Level Security, threat modeling, WebAuthn, Burp Suite, Wireshark, Nmap

Experience & credentials

Independent engineering work is presented as professional experience, with the degree and certification that shape my secure-by-design approach.

Codorus Web / Build With Treez

2026 - Present

Founder & Software Engineer

  • Own product strategy, interface design, implementation, verification, deployment, and maintenance across client and independent software.
  • Built and launched the Ascension Roofing production rebuild and the standalone Codorus Web business platform.
  • Translate privacy, authorization, analytics, migration, and recovery constraints into explicit engineering and release decisions.

Northampton Community College

September 2022 - May 2025

Information Security, A.A.S.

  • Dean's List every semester while working full-time.
  • Coursework and labs in network defense, security operations, cryptography, vulnerability testing, and incident response.
  • Also completed the University of Denver Full-Stack Web Development Bootcamp in 2019.

CompTIA

Certified 2024 - 2027

CompTIA Security+

  • Validated foundation across threats, secure architecture, security operations, identity, risk, and cryptography.

Additional experience

Delivery Associate

Walmart

Manage time-sensitive routes and customer issues while building products, delivering client work, and completing an information-security degree.

April 2023 - Present

Let's talk about the work.

Hiring for a software, product, front-end, or full-stack role? Send the role, the problem your team is solving, or the part of my work you want to discuss.

Best fit
Product-minded web engineering with a security-first edge
Location
Pennsylvania · Open to remote opportunities

Direct inquiry

I reply personally. No mailing list, sales sequence, or automated follow-up.

Please avoid including passwords or other sensitive information.