I'm a Backend Developer focused on building APIs, data-driven applications and reliable backend services.
My main stack includes Python, FastAPI, Java, Spring Boot and PostgreSQL, with hands-on experience in:
- REST API design
- asynchronous processing
- relational databases
- data validation and integrity
- automated testing
- containerized environments
- observability
- API security
- CI/CD
I'm especially interested in the intersection between backend engineering, distributed systems and security.
|
|
|
Event-driven backend designed to simulate a realistic endpoint telemetry and threat detection pipeline.
Python · FastAPI · PostgreSQL · Kafka · SQLAlchemy · Prometheus · Grafana
Telemetry
│
▼
┌─────────────┐
│ Ingest API │
└──────┬──────┘
│
├────────────► PostgreSQL
│
▼
Kafka
│
▼
┌─────────────┐
│ Normalizer │
└──────┬──────┘
│
▼
Kafka
│
▼
┌─────────────┐
│ Detector │
└──────┬──────┘
│
├────────────► Alerts
│
└────────────► Metrics
- Secure telemetry ingestion
- Request validation and hardening
- Raw event persistence and audit trail
- Asynchronous Kafka processing
- Event normalization pipeline
- Rule-based threat detection
- Structured alert evidence
- Replay datasets for validation
- Prometheus metrics
- Grafana observability
- Automated tests
- CI with GitHub Actions
Full-stack application developed from a real client requirement, with special emphasis on backend architecture and data integrity.
Java · Spring Boot · PostgreSQL · JPA · Next.js · Docker
- REST API with Spring Boot
- Layered backend architecture
- Jakarta Bean Validation
- Transactional service layer
- Relational data modeling
- Foreign keys and database constraints
- PostgreSQL indexes
- Automatic update triggers
- Standardized API error handling
- Dockerized PostgreSQL environment
The project applies validation at multiple levels:
Client
│
▼
Frontend Validation
│
▼
Spring Boot API
│
▼
Jakarta Bean Validation
│
▼
Service Layer
│
▼
PostgreSQL
│
├── NOT NULL
├── UNIQUE
├── CHECK
└── FOREIGN KEY
Academic research focused on reducing risks associated with shared credentials in academic environments.
IAM · COBIT 2019 · ISO/IEC 27001 · NIST SP 800-63
- Identity and Access Management
- Authentication models
- Shared credential risks
- User traceability
- Security requirements
- Privacy requirements
- Risk identification
- Technology comparison
- Governance controls
- Improvement planning
Backend Architecture
├── REST API Design
├── Distributed Systems
├── Event-Driven Architecture
├── Database Design
├── Automated Testing
├── API Security
├── Observability
└── CI/CD
Security
├── Identity & Access Management
├── Authentication
├── Detection Engineering
└── Security Governance

