I'm a Senior Software Engineer with 12 years of experience, including 7 years designing cloud architectures on AWS and GCP. I specialize in turning complex infrastructure into resilient, production-ready platforms and Argo CD GitOps workflows that eliminate delivery bottlenecks.
• Cloud & Infra: AWS, GCP, DigitalOcean, Multi-Region Terraform Design
• Orchestration: Kubernetes, Argo CD (GitOps)
• Delivery & CI/CD: CircleCI, GitHub Actions, End-to-End Release Automation
Event-Driven Trading Infrastructure
A production-grade event-driven algorithmic trading bot, designed to serve as a reference architecture for zero-trust cloud infrastructure, automated GitOps delivery pipelines, and real-time observability.
-
Infrastructure as Code (IaC): Orchestrated cloud resource deployment programmatically via Terraform, enforcing declarative configurations, structural validation checks, and tag-based associations.
-
Perimeter & Network Security: Provisioned an isolated DigitalOcean VPC network and enforced firewall rules to block unauthorized inbound connections and limit outbound egress strictly to DNS, HTTP/S, and NTP boundaries.
-
Zero-Trust Secrets Management: Integrated Doppler to inject application secrets and RSA cryptographic credentials directly into container memory at startup, eliminating the need to store plaintext keys or configs on the host disk.
-
Container Hardening & Least Privilege: Engineered multi-stage Docker builds to minimize runtime surface areas, executing services under a low-privilege system user while restricting database and telemetry port bindings to prevent public exposure.
-
Observability Pipeline: Configured a local Grafana Alloy telemetry collector to scrape application-level Prometheus metrics (API latency histograms, inventory levels, PnL) and remote-write them directly to Grafana Cloud.
-
Automated GitOps Pipeline: Programmed a GitHub Actions workflow executing automated testing with coverage metrics, terraform validation, security scanning, image publication to GitHub Container Registry (GHCR), and SSH-based remote deployments.
-
Disaster Recovery & Redundancy: Authored a POSIX-compliant PostgreSQL backup script featuring transaction-consistent dumps and archive verification, coupled with automated daily DigitalOcean snapshot backups for full-host recovery.
Stack: DigitalOcean, Terraform, Docker/Compose, GitHub Actions, Grafana Alloy, Doppler Secrets Manager, PostgreSQL, Python.
| Languages | Cloud Platforms | CI/CD & Infra | Data Systems | Observability & Security | AI Tooling |
|---|---|---|---|---|---|
|
Go Python Node.js Bash Swift Kotlin |
AWS (EKS, ECS, EC2, S3) GCP (GKE, GCE, GCS) DigitalOcean |
Kubernetes Helm Argo CD Terraform Atlantis Docker GitHub Actions CircleCI Buildkite Bazel |
PostgreSQL Redis BigQuery Pub/Sub |
Datadog Prometheus Grafana OpenTelemetry Sentry HashiCorp Vault Doppler Snyk |
Claude Code Gemini API OpenAI API Model Context Protocol (MCP) |





