I build systems that are not allowed to fail.
Senior software engineer and solutions architect. A decade of .NET, distributed systems and cloud platforms — most of it inside a regulated bank, where an outage is not a bug report but a regulatory event.
I am self-taught, I read specifications and C source for fun, and everything I can show you publicly is open source.
Core expertise
Languages & runtime
- C# — primary, since 2014
- F# — production, at scale
- .NET / ASP.NET / gRPC
- Golang
- C and C++
- TypeScript, SQL
Distributed systems
- High-throughput services
- Grid computing, load scheduling
- Master/worker architectures
- Concurrency and performance work
- Protocols from specification
- Distributed caching
Cloud & platform
- AWS — EKS, networking, IAM
- Kubernetes, Cilium, Envoy
- Terraform — incl. custom providers
- Pulumi, Cloud-Init, OpenShift
- GitHub, GitLab, Azure DevOps CI/CD
- Internal developer platforms
Security
- PKI and certificate automation
- Secure remote development
- Hardened machine images
- Applied cryptography
- Vulnerability research
- Regulated-environment approvals
Work
Software Engineer P4
Software Engineer, Cloud Specialist (Senior)
Solutions Architect
Software Engineer, Cloud Specialist (Senior)
OSS Developer
Open source
Undocumented protocols, cryptography and build infrastructure. Read the code.
HPCC
Security-oriented distributed compilation and caching for large-scale C++ codebases, isolating every build in AWS Firecracker or Hyper-V microVMs. Written in Golang.
NOnion
The Tor network specification implemented in pure F# — no interop with C binaries, so it runs anywhere .NET does. Cryptography read off the spec and out of the C source.
TgSharp / TLSharp
A Telegram MTProto client in C#. Eight years of chasing an undocumented, moving protocol taught me code generation and reflection-based programming the hard way.
DotNetLightning.Kiss
Core Lightning protocol and wallet logic in F#, including a complete watchtower implementation.
geewallet
Lightning support inside a cross-platform F# wallet — the protocol work above, put in front of real users.
Writing
Notes on protocols, .NET internals and infrastructure that misbehaves.
Firecracker, part four: BusyBox init, SquashFS, and a day lost to systemd
Firecracker, part three: a request's journey through MangoFaaS
Firecracker, part two: one rootfs, many microVMs
Firecracker, part one: getting a microVM to boot
Get in touch
[email protected]A CV is available on request — I share it privately rather than publishing it.