Backend & AI systems engineer — I take AI agents from pilot to production: architecture, MCP integrations, reliability, and the security review most deployments skip. Independent security researcher since 2018.
10+ years shipping · 400K+ user platform scaled · 1M+ user scheduling SaaS · 10+ engineers led
- 🤖 Built production AI agents: a crash-triage agent that root-causes incidents and opens PRs, and Brendon AI — a RAG coaching avatar with an in-house feedback engine serving 400K+ users
- 🔐 Reported 3 vulnerabilities in AWS MCP servers — all accepted, disclosure in progress
- 🧰 Building memory-blackbox — append-only memory provenance for AI agents: reconstruct what an agent knew, when, and why it acted
- ✍️ Writing on MCP auditing, agent forensics, and pilot→production engineering → blog
- 🏗️ GrowthDay (lead engineer, 2021–2026) — 400K+ active users, 4.8★ iOS, 10K+ concurrent live viewers, 99.99%+ crash-free; hired and led the engineering team
- 📅 Appointy (2015–2021) — scheduling SaaS for 1M+ users; SaaStack framework (load 15s → <1s); delivered at Google (REWS) and Telefónica
- 🏥 UChicago Medicine, Summit Health / VillageMD (via Toptal, 2023–2026) — HIPAA-compliant analytics, BigQuery, Salesforce personalization
- 🛡️ 100+ companies acknowledged my security research — AT&T, Opera (Hall of Fame), Airwallex, Check24, University of Michigan, and more
AI agents & LLM systems — where I spend my time now
agent architecture MCP — servers, clients & security tool use / function calling RAG pipelines vector search LangGraph LLM evals & observability agent forensics & provenance prompt injection defense OWASP LLM Top 10 Claude & OpenAI APIs context & cost engineering
Core backend — the decade underneath
Go C#/.NET Node.js/TypeScript Java gRPC + Protobuf microservices & DDD Kubernetes · Docker · Istio GCP · AWS · Azure PostgreSQL · Redis · Elasticsearch · MongoDB RabbitMQ · NATS · WebSockets payments: Stripe · Square · PayPal · Apple Pay · Authorize.net OAuth2 · JWT · SAML · LDAP · Keycloak
Full inventory (everything I've shipped with, by category)
| Category | Skills |
|---|---|
| Languages | Go, C#, Java, JavaScript/TypeScript, SQL, GraphQL, Bash, HTML/CSS |
| AI / agents | Agentic AI, LLM integration, MCP, RAG, LangGraph, embeddings & vector search, eval pipelines, agent security |
| Frameworks | gRPC, .NET 5/Core, Spring Boot, Express.js, OAuth 2, JWT, Ory Hydra |
| Architecture | Microservices, DDD, REST, serverless, scalable architecture, sharding, load balancing, telemetry, software design patterns |
| Cloud & infra | GCP, AWS (ECS), Azure, Kubernetes, Docker, Istio, NGINX, IIS, Jenkins, Linux, Windows Server |
| Storage | PostgreSQL, SQL Server, MySQL, MongoDB, Redis, Memcached, Elasticsearch |
| Messaging & realtime | RabbitMQ, NATS, WebSockets |
| Payments | Stripe, Square, PayPal, Apple Pay, Authorize.net — subscriptions, billing, monitoring |
| Identity & security | OAuth/OAuth2, SAML, JWT, LDAP, Keycloak, Identity Server, Azure AD, web/cloud/infra security, secure code review |
| Integrations | Twilio, Mixpanel, Google Analytics, Sentry, OneSignal, Pushwoosh, Zapier, Zoho CRM, Airtable, Kajabi, LearnWorlds, Cisco TMS |
| Tooling | Git, Jira, GoLand, IntelliJ IDEA |
🎓 MTech Cyber Security · 🛡️ Claude Certified Architect — Foundation (Anthropic, 2026) · ⚡ Toptal verified (top 3%)
Contract work — AI agents → production, MCP/agent security reviews · Senior/staff roles — for the right team.
🌐 Website & writing · 💼 LinkedIn · ⚡ Toptal · 📫 [email protected]





