Senior Software Engineer based in Lisbon, Portugal. I build backend systems for products where being wrong is expensive — fintech fraud detection, AI platforms, and multi-tenant SaaS.
EU work rights, no visa sponsorship required. Open to remote across Europe.
Two production components extracted from Raiza and released standalone.
Multi-provider AI orchestration for OpenAI, Anthropic and Gemini — automatic fallback chains, circuit breakers with configurable thresholds, exponential backoff with jitter, and per-request cost tracking. The circuit breaker and retry helpers are exported standalone, so you can use them without the orchestrator.
TypeScript · MIT
Type-safe, phase-based conversational state machine. Lifecycle hooks (onEnter / onMessage / onAction / onExit) per phase, automatic transitions, Redis persistence so conversations survive restarts, and a validation framework. Generic over your own phase enum and data shape. Ships with a complete pizza-ordering example.
TypeScript · MIT
Sole engineer and architect. Took a multi-tenant B2B SaaS from empty repository to paying production, owning architecture, infrastructure, security and release process.
Reached 100+ registered users and 5,000+ candidates processed in its first three months.
- Adapter-based distribution engine — publishes one vacancy to six external channels (LinkedIn, Instagram, Facebook, TikTok, Threads, Google Jobs), each with its own OAuth flow, media pipeline and billing rules
- 11-phase conversational AI system over the WhatsApp Business API, with a real-time Kanban board and WebSocket tracking
- 2,064-test automated suite (1,620 backend, 444 front-end) across a pnpm monorepo with GitHub Actions CI — the control that kept a solo-maintained production codebase releasable on demand
- AI CV parsing — structured extraction from PDFs, images and documents via multi-provider AI with fallback chains
- Intelligent job matching — scores candidates against requirements, including transit-time calculations
- Credits and billing system — purchase gating, refunds and a full audit trail
Found and closed a critical data-exposure vulnerability: production object storage was serving candidate CVs to anonymous unauthenticated requests. Locked every published container port behind an iptables allowlist and restricted the origin to Cloudflare-only, closing the leak and hardening all internal services in one pass.
- Backend: Node.js + Fastify + TypeScript, PostgreSQL with PostGIS, Redis for caching/sessions
- Frontend: Next.js 14 + React + Tailwind CSS + Zustand, real-time updates via Socket.IO
- Infrastructure: Docker, GitHub Actions CI/CD, Traefik reverse proxy, Cloudflare, MinIO object storage
- AI Layer: Multi-provider (OpenAI, Google Gemini, Anthropic Claude) with fallback chains
Automotive engineer by training, then business owner — three language school franchises and a vehicle rental company. That's why I tend to ask what a feature is worth before I ask how to build it.
Most of my commit volume lives in private organisation repositories, so the language breakdown above reflects public repos only.
LinkedIn · taciosurf@gmail.com · Lisbon, Portugal



