Leading frontend recovery across SaaS and commerce
Measuring first, cutting performance debt, strengthening delivery controls, and solving a separate headless-commerce integration without hiding team boundaries.
Outcome: A 48% smaller web bundle, 80% fewer asset bytes, 50% faster initial load, and known mobile dependency vulnerabilities reduced from 43 to 2.
An inherited product approaching launch
One web and mobile SaaS product was nearing launch with an 8.32 MB web bundle, 21.9 MB of assets, overlapping UI systems, outdated dependencies, an aging mobile build, and a release process that still depended heavily on manual regression work.
As Head of Frontend, I led the performance and security workstream while remaining hands-on in the code. The team already had substantial component refactoring underway, so my job was not to retell the work as a solo rewrite. It was to measure the remaining constraints, sequence the highest-leverage changes, unblock implementation, and make launch risk visible.
Measuring before removing
I used bundle analysis, browser performance tools, and project reports to establish the baseline. We replaced a heavy document-viewer interaction with native browser behavior, consolidated duplicate date and UI dependencies, tested compatible table-library versions instead of forcing a broken upgrade, lazy-loaded routes and media, and converted oversized assets.
Over the recorded three-week workstream:
- the web bundle fell from 8.32 MB to 4.3 MB, a 48% reduction;
- assets fell from 21.9 MB to 4.52 MB, an 80% reduction;
- initial loading time fell 50%;
- one oversized asset fell from 2,059 kB to 143 kB, a 93% reduction.
Not every metric improved. The recorded layout-stability result still needed work, so I did not present the intervention as a universal performance win.
Security, testing, and release control
I audited browser, dependency, authentication, and API security, then sequenced dependency remediation, security headers, content-security policy, end-to-end testing, and reusable-component work in the delivery plan. The mobile upgrade reduced known dependency vulnerabilities from 43 to 2.
I compared E2E tools, selected Cypress, implemented the initial login flow, and prepared examples for the team. An expected reduction from days of manual regression to minutes remained a projection, so it is not presented here as a measured outcome.
The broader delivery reset used capacity-based sprint planning, daily coordination, backlog grooming, smoke testing, stabilization, and retrospectives. Releases were shared after the test and stabilization gates—not simply when feature coding stopped.
A separate headless-commerce mission
For a consumer-commerce product, I connected Storyblok and Shopify through a custom editorial plugin, a Shopify app, and a theme extension. The goal was to keep product content editable by nontechnical teams without making every page request depend directly on the CMS origin.
A Cloudflare Worker cached the CMS path at the edge. In the measured scope, origin/server load fell 99% and response times improved 50%. This was a separate commerce intervention and is not blended with the workforce SaaS measurements above.
What remains private
Client and project names, teammate identities, private URLs, screenshots, infrastructure identifiers, and detailed vulnerability findings are excluded. The case distinguishes the work I led and implemented from refactoring already completed by another engineer.