
Mar 2026
Coldchain Optimization
Real-time cold-chain logistics matching engine. Pairs shippers with transporters using live geospatial scoring, ETA tracking, and dynamic pricing.
I'm a software engineer working across Linux systems, containers, and developer tooling.
Day to day, I build systems at Rocket Software.
Open Source
I gravitate toward the layer underneath the application: a compile-time instrumentation tool rewriting Go source before it builds, a Kubernetes GPU device plugin sharing memory with a C process, a Jenkins agent coordinating threads over a socket. The bugs there cluster into a handful of patterns: silent failures, thread-safety gaps, unbounded cardinality, spec drift. Browse by problem category below, not by repo.
Everything below, across every problem category, that touches this repo.
The Metrics SDK hardcoded a 2000 cardinality limit and silently discarded any user-supplied override from declarative YAML config.
Wired a configurable limit through MetricReader and CollectorHandle end-to-end, fixing a sentinel-value bug along the way; a follow-up fix (#4314) closed a gap where histogram views setting only a cardinality limit were silently rejected.
Get("")/Set("") silently touched the wrong slot instead of normalizing to "_", a spec violation - fixed alongside documenting the caching contract's string_view lifetime guarantees.
minimum_severity and trace_based were missing from LoggerConfig's YAML configuration path, so file-configured loggers silently ignored severity filtering.
Values were stored raw instead of percent-decoded per the W3C Baggage grammar the spec defers to, so key=hello%20world produced the literal string instead of "hello world".
Caught and fixed a real operator-precedence bug during review: << binds looser than +, so combining hex nibbles with + rather than | would have silently miscomputed the decoded byte.
Swapping deprecated C headers for their C++ equivalents left calls like memcpy, strcmp, and strtod unqualified, relying on implementations happening to expose them globally, which the standard does not guarantee.
Added std:: to those call sites across api, sdk, exporters, ext, examples, and functional, plus the includes that had relied on transitive inclusion, leaving vendored code untouched.
predicate_factory.h used uint8_t without including cstdint, compiling only because another header in the same translation unit happened to pull it in.
Added the missing include directly to the header that needs it, so it builds in isolation and under standard libraries without that transitive include.
Closed out a long-running clang-tidy tracking issue by wrapping the last four file-local symbol groups in anonymous namespaces, reducing ODR risk on symbols with no header exposure.
Swept ~90 files from legacy C headers to their C++ equivalents, fixing IWYU's mappings first so it would stop recommending the headers being removed; excluded vendored code a reviewer flagged as out of scope.
Filed a scoped follow-up (#4356) for the std:: qualification gap the header swap exposed, rather than scope-creeping it into the same PR.
When a view set aggregation_cardinality_limit without an explicit aggregation, AddView always built a plain AggregationConfig. For histogram and exponential-histogram instruments that type didn't match, so the whole view was dropped with a warning and the limit never applied.
AddView now resolves the instrument's effective aggregation type the same way the view registry does, so the configured limit takes effect.
WriteValue stored a log record's body/attributes as given, and Export() dumped them via nlohmann::json with its default strict error handler - any non-UTF-8 byte (a truncated multibyte sequence, a differently-encoded payload) threw type_error.316 inside a noexcept function, turning std::terminate() into the actual failure mode for one bad log record.
Switched to error_handler_t::replace, which substitutes U+FFFD for the invalid bytes so the record and the rest of the bulk batch still export instead of crashing the process.
A record created while the logger was disabled was a no-op record, but enabling the logger before emit let it reach two unconditional static_casts, which is undefined behavior. The issue's dynamic_cast fix doesn't build under the project's no-RTTI CI job.
CreateLogRecord now returns an empty MultiRecordable while disabled, which is a real Recordable, so both casts are always safe and the record is dropped without reaching a processor.
Experience
Full-time engineering and product-based internships - all focused on production-grade backend systems in Go and cloud-native infrastructure.

Jun 2026 - Present
Jun 2026 - Present
Modernizing mainframe software with cloud-native solutions, bridging legacy enterprise systems with contemporary distributed infrastructure.
Decomposing monolithic codebases into microservice-based architectures, improving deployment flexibility, scalability, and independent service ownership.

Jan 2026 - May 2026
Jan 2026 - May 2026
Architected and scaled a production vendor adapter microservice bridging internal trading workflows with external OMS systems using Go, gRPC, REST, and NATS JetStream.
Designed environment-isolated runtime configuration across prod, preprod, and UAT, enabling build-once-deploy-many workflows and eliminating cross-environment traffic risk.
Implemented secure secret injection and strict file-permission controls (least privilege), replacing hardcoded credential paths with rotation-friendly operational patterns.
Engineered deterministic fail-fast startup with strict dependency sequencing and singleton initialization, preventing fail-silent behavior in high-frequency trading flows.
Built recovery-ready subscription management and trace-aware structured logging across REST, gRPC, and async callbacks, improving fault tolerance and incident triage speed.

Jun 2025 - Jul 2025
Jun 2025 - Jul 2025
Engineered a production-grade entitlement client in Go with resilient transport abstractions and config-driven endpoint resolution for reliable external integrations.
Implemented Hystrix-inspired circuit-breaker and fallback controls to preserve service availability during partial outages.
Built shard-aware partner onboarding and offboarding workflows, contributing to scalable Aurora data access patterns and better data locality.
Operationalized end-to-end reliability validation via local service mocks, API verification, Kafka event checks, and controlled failure simulations.
Projects

Mar 2026
Real-time cold-chain logistics matching engine. Pairs shippers with transporters using live geospatial scoring, ETA tracking, and dynamic pricing.

Mar 2026
Multi-tenant AI memory assistant for financial workflows. Combines graph and vector retrieval for fast, isolated context recall across users.

Dec 2025
Real-time APT detection framework built on the ELK stack. Simulates attacks mapped to MITRE ATT&CK and flags anomalies with a reinforcement-learning model.

Oct 2025
Real-time paint-shop vehicle routing and sequencing system. Uses constraint optimization and discrete-event simulation to minimize color changeovers across buffer lines.

Mar 2025
Metadata explorer for data lakehouses. Reads Iceberg, Delta, Hudi, and Parquet schemas straight from S3, no external catalog required.

Mar 2026
Safety education platform for 5,000+ concurrent learners. Generates age-adaptive AI narratives from live news and reads emotion cues for feedback.
Blog
Notes on backend engineering and the occasional production mistake, currently hosted on Medium.
I care about writing code that is simple to reason about, easy to monitor, and dependable when it matters most. The problems that pull me in are usually about concurrency, data consistency, and holding up under load. Here's how I got here.
I write about backend engineering on my blog, and I've led technical communities and national-level events on the side. I also play badminton competitively.
Contact
If you're building something in that space, or just want to talk shop, my inbox is open.