Skip to main content
Mohsen Tavakoli
Available for Software Development & Security Research

Mohsen Tavakoli

Full Stack Engineer

React | Python | TypeScript | Blockchain | AI

Full Stack Engineer with 12+ years of experience building scalable web applications, APIs, and distributed systems. From enterprise platforms to DeFi protocols — I ship production-grade software across the entire stack.

12+
Years Engineering
30+
Production Apps Shipped
9+ Years
Blockchain Experience
Active
Availability

Tech Stack

ReactNext.jsTypeScriptPythonDjangoFastAPINode.jsPostgreSQL

Tools & Frameworks

DockerKubernetesAWSGitCI/CDFoundryHardhatSolidity

About Me

I'm a full-stack engineer with 12+ years of experience building scalable web applications, APIs, and distributed systems. I've worked across the entire stack — from React and Next.js frontends to Python and Node.js backends, with deep expertise in database design, cloud infrastructure, and DevOps.

As CTO at PlayEstates, I led a cross-functional team building a real estate tokenization platform from the ground up — architecting the full stack including Django APIs, React frontend, Solidity smart contracts, and AWS infrastructure with CI/CD pipelines.

I have 9+ years of blockchain experience building DeFi protocols, dApps, and smart contracts on Ethereum, BSC, Flare, and Solana. At GrowthDeFi, I experienced a $1.4M exploit firsthand, which deepened my understanding of smart contract security and led me to pursue security research alongside development.

Currently at Turing, I build AI automation systems using LangChain, RAG architectures, and multi-agent frameworks — combining my full-stack engineering background with modern AI tooling to deliver enterprise-grade solutions.

Quick Facts

Location
Stockholm, Sweden
Experience
12+ Years Software Engineering
Education
Bachelor's degree in Systems Engineering — University of Oslo

Core Expertise

  • Full-stack engineering (React, Python, Node.js, TypeScript)
  • Database design & API architecture (PostgreSQL, REST, GraphQL)
  • Cloud infrastructure & DevOps (AWS, Docker, Kubernetes, CI/CD)
  • Blockchain & smart contracts (Solidity, Web3, DeFi)
  • AI/ML integration (LangChain, RAG, LLMs)
  • Technical leadership & system architecture

Experience

2022 — Present

Full Stack Engineer & AI Trainer · Turing

Building full-stack applications and training AI models for enterprise clients. Developing React and Python-based platforms with integrated AI capabilities. Designing RAG pipelines and multi-agent systems using LangChain and LangGraph. Training and fine-tuning LLMs on domain-specific tasks, improving model output accuracy by 40%.

ReactPythonTypeScriptLangChainRAGLLMsFastAPI
2023 — 2024

Full Stack Engineer · SSV Labs

Built distributed validator infrastructure for SSV Network — a permissionless, decentralized platform enabling multiple operators to collectively run Ethereum validators. Developed React-based dashboards for monitoring validator performance and network health. Delivered key features for the SSV Network's mainnet launch.

ReactTypeScriptSolidityNode.jsPostgreSQLEthereum
2021 — 2022

Chief Technology Officer · PlayEstates

Led a cross-functional engineering team building PlayEstates — a platform empowering global real estate trading and fractional ownership starting from $10. Architected the full technical stack including smart contracts for tokenization, backend APIs, and a React frontend. Established CI/CD pipelines and engineering best practices.

ReactDjangoSolidityAWSDockerLeadership
2021

Senior Full Stack Developer · FlareFinance

Implemented DeFi protocol interfaces including DEX, lending, and yield farming modules on Flare Network — a full-stack L1 blockchain with enshrined data protocols (FTSO oracle, FDC data connector). Built responsive frontends with React and integrated with Flare smart contracts.

ReactSolidityDeFiWeb3.jsNode.js
2018 — 2020

Senior Full Stack Blockchain Developer · GrowthDeFi

Designed and deployed DeFi smart contracts on Ethereum and BSC for GrowthDeFi's decentralized ecosystem managing substantial TVL. Built analytics dashboards and user-facing dApps. Experienced the $1.4M LP injection exploit firsthand, contributing to post-incident security hardening and validation patterns.

SolidityReactEthereumBSCDeFiWeb3
2014 — 2017

Full Stack Web Developer · Stealthdata

Built and maintained enterprise web applications using JavaScript frameworks and Python backends. Developed RESTful APIs, database schemas, and frontend interfaces for data-intensive platforms.

JavaScriptPythonPostgreSQLREST APIsDjango
View Full Resume

Projects

Gridzilla — Real-Time NFT Tracker & Analytics

Full-stack real-time tracker and analytics dashboard for all 10,000 GUNZ Hacker License NFTs. Features an animated canvas-based bubble map visualization sized by hashpower and colored by rarity tier, wallet explorer, sortable leaderboard, ecosystem stats, and live decode feed. Backend syncs data every 2 minutes from GUNZ API and on-chain GunzScan sources.

ReactNode.jsExpressMySQLCanvasRedis

Flaw Gaming — Esports & Web3 Gaming Platform

Custom WordPress platform for an esports and Web3 gaming organization. Built custom theme and plugin with PHP 8, featuring custom post types for games, teams, players, creators, events, and partners. Includes event management with state tracking, team rosters filterable by game, and a join application system with admin review.

PHPWordPressJavaScriptCSSPods Framework

SSV Network — Distributed Validator Infrastructure

Core infrastructure for decentralized Ethereum staking. SSV Network enables multiple operators to collectively run validators through distributed validator technology (DVT), eliminating single points of failure. Built React dashboards for validator monitoring, operator management, and network health analytics.

ReactTypeScriptSolidityEthereumNode.jsPostgreSQL

PlayEstates — Real Estate Tokenization

A platform empowering global real estate trading and fractional ownership starting from $10. Architected the full stack: smart contracts for property tokenization and dividend distribution, Django backend APIs, React frontend with KYC/AML compliance integration, deployed on AWS.

ReactDjangoSolidityAWSDockerWeb3

FlareFinance — DeFi on Flare Network

Suite of DeFi protocol interfaces (DEX, lending, yield farming) built on Flare Network — a full-stack L1 with enshrined data protocols including the FTSO time-series oracle and FDC data connector. Developed responsive frontends and integrated with Flare's native smart contracts.

ReactSolidityDeFiWeb3.jsFlareFTSO Oracle

GrowthDeFi — Decentralized DeFi Ecosystem

DeFi protocol on Ethereum and BSC featuring staking, yield farming, and liquidity provision with substantial TVL. Built analytics dashboards and dApp frontends. Site of the $1.4M fake-LP injection exploit (Feb 2021) — contributed to post-incident security hardening.

SolidityReactEthereumBSCDeFiSecurity

AI-Powered Enterprise Platform

Full-stack enterprise platform integrating AI automation with LangChain and RAG pipelines. Built with FastAPI backend, React frontend, PostgreSQL database, and Docker deployment. Processes thousands of documents with sub-second response times.

ReactFastAPIPythonPostgreSQLDockerLangChain

Portfolio Website

This portfolio — a modern, SEO-optimized single-page application built with Next.js 14, TypeScript, and Tailwind CSS. Features server-side rendering, structured data (JSON-LD), dynamic sitemap, Google Analytics integration, and responsive design.

Next.jsTypeScriptTailwind CSSSEOVercel

Skills & Expertise

Frontend

ReactNext.jsTypeScriptJavaScriptTailwind CSSHTML/CSS

Backend

PythonDjangoFastAPINode.jsPostgreSQLMongoDBREST APIsGraphQL

DevOps & Cloud

DockerKubernetesAWSCI/CDGitLinux

Blockchain & Web3

SolidityEthereumWeb3.jsEthers.jsDeFiSmart Contracts

AI & Machine Learning

LangChainLangGraphAutoGenCrewAIRAGPrompt EngineeringLLMsVector Databases

Security Expertise

EVM (Solidity)

  • Security pattern analysis
  • Upgradeable proxies (UUPS, Transparent)
  • ERC-20 / ERC-721 / ERC-4626 / ERC-1155
  • Reentrancy protection patterns
  • Access control (Ownable, RBAC, multi-sig)
  • Storage layout safety
  • Delegatecall risks & proxy patterns
  • Flash loan attack vectors
  • MEV protection strategies

Solana (Rust / Anchor)

  • CPI safety & authority validation
  • PDA derivation & bump seed security
  • Account constraint validation
  • Signer & ownership verification
  • Rent & lamport handling
  • Anchor security patterns
  • SPL token program interactions
  • Close account vulnerabilities

What I Look For

Broken accounting invariants
Privilege escalation vectors
Oracle manipulation & price feed attacks
Flash loan attack surfaces
State desynchronization
Unsafe upgrade patterns
Missing input validation
Integer overflow/underflow
Frontrunning & MEV vulnerabilities
Cross-contract reentrancy

Certifications

Professional certifications in cloud computing, DevOps, and project management.

Security Research

Real production exploit analysis + technical methodology samples in Sherlock-style reporting format.

1 Real Case Study (GrowthDeFi)

Audit Workflow

Systematic approach combining manual review, automated tooling, and proof-of-concept development.

01

Scope & Threat Modeling

Define attack surface, identify critical invariants, map trust boundaries

02

Define Invariants

Document expected system properties and economic constraints

03

Attack Surface Mapping

Enumerate entry points, external dependencies, privilege levels

04

Deep Manual Review

Line-by-line analysis, data flow tracing, edge case exploration

05

PoC Development

Build working exploits in Foundry/Anchor to validate findings

06

Structured Report

Severity justification, impact analysis, remediation guidance

Every finding includes a working PoC in Foundry or Anchor

Get In Touch

Available for full-stack engineering projects, security consulting, and collaboration.

Or email me directly at mtavakolibusiness@gmail.com

Available For

  • Full-stack engineering projects
  • Web & mobile application development
  • Security consulting & smart contract audits
  • AI integration & automation

Fast Response

Typically respond within 24 hours. For urgent matters, email with [URGENT] in subject.