Website:
codexray.io
Job details:
About CodeXray
CodeXray is building an AI-guided observability and API security platform — one place for engineering, DevOps, and security teams to see what's happening across their systems, understand why, and know what to do next.
Three things sit under one roof:
- Full-stack observability — eBPF-powered telemetry capture across applications, nodes, databases, cloud infrastructure, and real end-user experience, with OpenTelemetry SDK and Collector support plus custom agents for legacy stacks
- Agentic SRE — every anomaly gets investigated automatically for root cause, instead of dumping a wall of alerts on an on-call engineer
- API security observability — OWASP Top 10 coverage, PII detection, live API traffic assessment, and CVSS-based risk scoring
We ship both SaaS and on-premise, and were named Best Product in Agentic SRE &Full-Stack Observability Tools at the CIO Conclave & Awards 2025.
We're competing with Datadog, New Relic, and Grafana — companies with far more people than us. The bet is that better product thinking beats bigger headcount, and the UI is a large part of where that bet gets won or lost.
Why this role
Observability UIs are hard in a way most frontend work isn't.
You're rendering millions of data points without dropping frames. You're streaming live telemetry into views that can't flicker or reflow while an engineer is reading them. You're designing trace waterfalls, flame graphs, service topology maps, and log tables that stay usable at high cardinality. And you're doing it for users who are, by definition, having a bad day — someone opens our dashboard because production is broken, and every second of confusing UI costs them.
Most of our competitors' interfaces are dense, intimidating, and built up over a decade of accretion. Ours doesn't have to be. That's the opportunity.
You'll have real authority over frontend architecture, the component library, and how the product actually feels to use.
What you'll do
- Own the frontend for our observability and API security consoles end—to—end— architecture, implementation, performance, and iteration after release
- Build high-density data visualization: time-series charts, trace waterfalls, flamegraphs, service dependency maps, heatmaps, and virtualized log and event tables that stay smooth at scale
- Handle real-time data properly — WebSocket and streaming updates, backpressure, incremental rendering, and sensible behaviour when the data volume spikes
- Establish and maintain our design system so the three product surfaces feel like one product rather than three
- Make the product work in air-gapped on-premise deployments — no CDN assumptions, no external font or analytics calls, predictable bundle behaviour
- Set a real performance bar (interaction latency, memory under long-runningdashboard sessions, initial load) and hold the codebase to it
- Partner with backend on query and API shape — at this data volume, the frontend'sneeds have to influence the API design, not just consume it
- Raise the bar through code review, testing practices, and mentoring
What we're looking for
- 5–6 years building production web applications, with meaningful time on data-heavyor dashboard-style products
- Strong JavaScript and TypeScript — you understand the runtime, not just the framework
- Deep React experience, including the parts people avoid: render performance, memoization that actually helps, virtualization, and profiling real bottlenecks
- Hands-on data visualization work with something like D3, ECharts, uPlot, visx, Recharts, or Canvas/WebGL directly — and the judgment to know when SVG stops being viable
- Solid CSS: dense information layouts, responsive behaviour, and a modern styling approach (Tailwind, CSS Modules, or CSS-in-JS)
- Practical experience with real-time data in the browser — WebSockets, SSE, polling strategies, and the state management that comes with them
- Comfort consuming complex REST or GraphQL APIs, including caching, pagination, error and empty states
- Modern build tooling (Vite, Webpack), testing habits (Vitest/Jest, React Testing Library, Playwright or Cypress), and CI/CD
- Accessibility fundamentals — semantic HTML, keyboard navigation, WCAG 2.1 AA
- Comfort with ambiguity and enough product sense to push back on a spec that won'twork for an engineer at 3 am
Strongly preferred
You don't need all of these, but any of them will move you up our list:
- You've used observability tools seriously — Datadog, Grafana, New Relic, Prometheus, Jaeger, Honeycomb — and have opinions about where they're good and where they're painful
- Familiarity with OpenTelemetry concepts: traces, spans, metrics, logs, and how they relate
- Experience with WebGL or Canvas rendering for large datasets
- Background in security tooling UI, or comfort with concepts like OWASP Top 10 and CVSS scoring
- Next.js and a real grasp of SSR/SSG trade-offs
- Enough Node.js to build a BFF layer or unblock yourself
- Open-source contributions, side projects, or writing we can read
Click on Apply to know more.