VKR.
Senior Software Engineer/Frontend & Full Stack/Delhi, India

VaibhavKumar Rai

I take complex frontends and full-stack systems and turn them into systems a whole team can build on.

7+ years across security, compliance, healthcare and IoT. Mostly React, Next.js, TypeScript, FastAPI and PostgreSQL. Design systems, data-heavy UI, solid backend APIs, and modern RAG pipelines with evals.

Open to senior and staff roles (Frontend & Full Stack)

Experience7 roles / 2018 to now
2024 — 2026Bangalore

Scrut Automation

Senior Software Engineer

Promoted from SDE II (Jun 2024) to Senior (Apr 2025), same team

  • Owned frontend architecture and built backend APIs across the core security products, findings and vulnerability management, using FastAPI, Python and PostgreSQL.
  • Rearchitected the app around a UI design system spanning multiple modules, the layer the rest of the pod built against every sprint.
  • Added virtualization and a reusable real-time table for live, data-heavy views, then used code splitting to cut initial bundle size and load time.
  • Built the dashboards that surface security findings and incidents, so customer teams could resolve issues faster.
  • Integrated PostHog and worked with PMs and designers to add business-level signals and analytics.
FastAPIPythonPostgreSQLReactTypeScriptDesign systemVirtualizationNxPostHog
2022 — 2024Bangalore

Kami Vision

Senior Software Engineer

Kami Cloud · B2C
  • Rewrote the Vue.js app in React and built a reusable design system under it with Storybook and custom theming.
  • Added responsive layouts, internationalization, code splitting, lazy loading and Stripe payments with backend webhook handling, with integration tests behind them.
Internal Dashboard · B2B
  • Built the org-facing dashboard in Next.js with SSR and SSG, plus TypeScript transformers that normalized inconsistent API responses into one shape.
  • Set up the shared design system and testing approach the internal teams onboarded onto.

Vue.js React

ReactNext.jsNode.jsTypeScriptStorybookStripei18nSSR / SSG
2022Remote

Milky Way AI

Freelance Software Engineer

  • Built a dashboard that automates stock replenishment and gives retail operations a real-time read on inventory.
2021 — 2022Remote

Quizizz

Freelance Software Engineer

  • Worked the migration off Krafty onto Nuxt and built the complex UI components that came with it.

Krafty Nuxt

Vue.jsNuxt
2019 — 2021Remote

Klinify

Software Engineer

  • Cut dashboard load time by 45% with memoization, API optimizations and code splitting.
  • Built a configurable design system carrying per-clinic branding, themes and layouts, with SSR and SSG for dynamic content.
  • Wrote backend Flask APIs and CouchDB map-reduce transformations to handle clinic workflows and patient records.
ReactFlaskCouchDBPythonSSR / SSGDesign systemi18n
2019Bangalore

Appknox

Software Engineer

  • Built the Ember.js interface for running and managing application security scans, so customers could run several scans in parallel instead of one at a time. Throughput went up, turnaround came down.
  • 25 pull requests merged into appknox/irene, their open source frontend.
Ember.jsAppSecAPIsOpen source
2018 — 2019Bangalore

Squadcast

Software Developer Intern

  • Built a bidirectional sync between Slack and Squadcast chat (Node.js and WebSockets) so incident updates landed in real time on both sides.
  • Wrote Enzyme tests across the frontend, shipped backend serverless Kubeless microservices, and stood up an Artifactory registry for private npm packages.
ReactNode.jsWebSocketsKubelessEnzymeArtifactory
What I actually do
Design systems

Three built from scratch

Rearchitected the UI design system across multiple modules at Scrut, the layer the rest of the team built against every sprint. Storybook and custom theming at Kami Vision. Per-clinic branding, themes and layouts at Klinify.

Full stack & backend

APIs and services that hold up

FastAPI, Python and Postgres at Scrut for live security findings and vulnerability views. Flask APIs and CouchDB map-reduce at Klinify. Real-time chat sync over WebSockets and serverless Kubeless microservices at Squadcast, plus Stripe webhooks at Kami Vision.

RAG & evals

Context retrieval that doesn’t hallucinate

Agentic RAG pipelines with pgvector and semantic search in Bandhu. Set up Langfuse evals to catch hallucinations, score retrieval quality, and keep crisis safety rails rock solid. Tool security and permissions over MCP in AgentGate.

Framework internals

5 patches merged into Svelte

Bindings, contenteditable regressions and lifecycle bugs in Svelte core, plus a fix in Qwik. 75 merged pull requests into repos I don’t own. I read framework source when the bug stops making sense.

Built on my own timegithub.com/RaiVaibhav

AgentGate

Permission control for AI agents over MCP. It sits between an agent and a server like GitHub, Stripe or Slack, enforces per-tool permissions, scans responses for security problems, logs every decision, and revokes access instantly. The agent never gets the real API key, only a gateway URL.

Give an agent a GitHub token today and it gets everything that token allows. There's no way to say “read repos, never delete them.” This is my answer to that.

TypeScriptMCPAI SecurityAccess ControlAudit Log

Bandhu

A companion-first mental health check-in app for India. The idea is that it should feel like texting a friend, not opening a treatment tool. Built with an agentic RAG pipeline — FastAPI with async SQLAlchemy and Postgres/pgvector on the back, React 19, Vite, Tailwind v4 and shadcn/ui on the front, NVIDIA NIM and Langfuse for tracing and evals.

Anything safety-critical sits behind an eval pipeline to catch crisis language and test retrieval relevancy before it ships. The engineering docs cover the RAG pipeline design, the vector schema and the manual and automated eval cases.

React 19FastAPIpgvectorRAGLLM evalsLangfuseTailwind v4

The real app, running here. Try it.

Open source

Svelte & Qwik core

5 pull requests merged into Svelte and one into Qwik: element bindings, a contenteditable regression, beforeUpdate firing twice, onDestroy ordering, each-block bindings with spread syntax. Small fixes, but they meant reading someone else's compiler until the bug made sense.

SvelteQwikCompilers
2017 — 2018

coala, GSoC and Code-in

Google Summer of Code 2018. Wrote a Python tool that drops you straight into an analyzer's code and steps through it with a debugger interface like pdb, so debugging an analyzer got about as easy as writing one.

Google Code-in mentor, two terms, with coala, the open source static analysis org. Also 2 merged fixes into man-group/pytest-plugins and an ESLint plugin of my own for nested-if detection.

PythonStatic analysisMentoring
Toolkit
Frontend
React.js, Next.js, Vue.js, TypeScript, JavaScript, HTML5, CSS3, Tailwind CSS
State & data
Redux, Zustand, React Query, REST APIs, WebSockets
Testing
Jest, Cypress, Storybook, Enzyme
Architecture
Design systems, micro frontends, Nx monorepo, SSR, SSG, component libraries, i18n, virtualization, performance work
Backend
FastAPI, Python, Node.js, PostgreSQL, pgvector, Flask, CouchDB, Swagger
RAG & evals
RAG pipelines, LLM evals, Langfuse, semantic search, prompt engineering, MCP
Tools & ops
Git, CI/CD, Webpack, Vite, Docker, AWS, PostHog, Grafana
Languages
English (full professional), Hindi (full professional)
Education, certificates & current
2015 — 2019
B.Tech, Computer Science and Engineering. Shri Mata Vaishno Devi University, Jammu & Kashmir
Certificates
DeepLearning.AI: Neural Networks and Deep Learning · DeepLearning.AI: Machine Learning · Google: Foundations of Project Management · Google: Project Initiation
Right now
Going deep on RAG pipelines, LLM evals and tool security over MCP (like Bandhu and AgentGate), plus high-throughput data visualization in the browser.
Off the clock
Runner, paragliding pilot, licensed skydiver. I keep a CSS-only art gallery on CodePen, because I'd rather battle CSS than DS Algo.