Full-stack engineer with a backend focus, building event-driven systems, real-time APIs, and RBAC platforms in TypeScript and Kotlin, on PostgreSQL and Redis.
A cybersecurity threat intelligence platform that aggregates vulnerability data (CVEs) and exploit proofs-of-concept, tracking them against specific software inventories to provide real-time alerting and cybersecurity risk profiles.
- Data Ingestion: Architected diverse ingestion pipelines (API polling, web scraping, and Git diffing) to continuously synchronize and normalize distributed threat intelligence feeds via transaction-safe
PostgreSQLbatch processing. - Threat Indexing: Engineered a proprietary composite risk metric for vulnerabilities that evaluates real-world exploitability by blending foundational CVSS scores, predictive EPSS probabilities, and time-decayed exploit evidence with immediate federal catalog overrides.
- Event-Driven Alerting: Built asynchronous, idempotent notification pipelines (Email, Telegram, Discord, WhatsApp) utilizing
BullMQandRedispub/sub. - Infrastructure: Configured
Nginxreverse proxy for real-time Server-Sent Events (SSE) stream delivery and SSR micro-caching.
An enterprise IT support ticketing platform engineered for the ICT Dte., National University of Sciences and Technology (NUST), managing the complete complaint lifecycle with strict role-based access control (RBAC) for university staff and technicians.
- State Machine Logic: Designed role-based ticket lifecycle transitions, enforcing conditional status updates per stage.
- Real-Time Events: Integrated
Socket.IOfor instant, room-based event broadcasting to keep distributed teams synchronized. - Security & Compliance: Append-only audit logging written in-transaction with every mutating operation, and refresh-token rotation on each use with an absolute expiry to cap refresh chains.


