← The workTonic engagement

easyJet careers site

A careers-site revamp that began after a security breach at easyJet. The planned infrastructure (AWS with Strapi) did not meet the security requirements that followed.

Tonic engagement: easyJet was Tonic's client; the work was delivered through Tonic. Built 2022–23; ongoing technical management since.

His role

  • StatedTitled Project Director.
  • StatedBy his attested account: the pitch, the audit, a large technical onboarding, the build, its management, and ongoing technical management including monthly security patches and single sign-on, on Contentful.

Team context

  • AttributedA team of about eight across Tonic, easyJet's analytics, HR and security teams and a developer he recruited and managed. The build itself was a team effort; his first-hand account describes technical oversight, managing the developer and running daily stand-ups.

His contribution

  • StatedAfter consultations with easyJet's head of IT, he moved the project to a SaaS stack (Contentful and Netlify) that met the airline's ISO-aligned security requirements. His original wording: "I pivoted to a secure, SaaS-based solution".
  • StatedTechnical oversight of the build, recruitment and management of the developer, and daily stand-ups.
  • StatedOngoing post-launch technical management, security patching and SSO.

Decisions and trade-offs

  • StatedSecurity first: some planned interactive features were dropped to stay within the security requirements, so the security constraint shaped the architecture, and the architecture shaped the feature set.

What was delivered

  • AttributedA React front-end on Contentful, launched in English and then six languages using Crowdin's machine translation connected to Contentful.

What is documented

  • UnknownNo traffic, engagement or recruitment figure is documented.

What this demonstrates

  • InferenceMovement between organisational constraint (post-breach security policy), architecture, experience and implementation, with a lower layer forcing a change in the one above.
Fullest account: leantonio.me/projects/easyjet (a fuller Merlin case study does not exist yet)

Part of the Tonic partnership.

Each line is labelled by the evidence behind it. Documented: checkable in code, a live product or a primary artefact. Stated: his own account. Attributed: a wider team's or client's. Inference: a reading of the evidence, not a fact. Unknown: not established. No outcome or metric is documented for any of this work. The same record is published for AI assistants at /llms-full.txt.