What I build
- Go platforms that unify identity, device, HR & asset systems
- Full-stack internal web apps (Go, PostgreSQL, OIDC SSO)
- Event-driven background-job systems (idempotent, self-healing)
- Fleet automation & software distribution at scale
Go · Platform Engineering · Systems Integration · Identity & Security Automation
I build and own Go platforms that run an organization’s core operations: integrating identity, devices, HR, and assets, and automating everything between them.
I’m a platform and backend engineer. I design, build, and own Go systems end to end, and I’m the primary author of the internal platform that runs my company’s IT operations. My work is an organization’s connective tissue: services that integrate identity, device, HR, and asset systems, automate the work between them, and keep running for years without hand-holding.
The platform is roughly 20,000 lines of Go running as a single binary: an HTTP API plus two background-worker pools that unify nine enterprise systems (Okta, Jamf Pro, BambooHR, Snipe-IT, Cloudflare, Slack, Jira, Planhat, Datadog) into one control plane. It runs the entire employee IT lifecycle on an idempotent, failure-aware job queue: event-driven provisioning on hire, continuous cross-system reconciliation, and safe, gated deprovisioning on departure. That includes a SCIM-style access-governance engine that keeps downstream tool access in lockstep with identity.
That is one system among several I have shipped and own. I have built full-stack Go web apps backed by PostgreSQL with Google OIDC single sign-on and hardened sessions, a pipeline that catalogs and distributes 77 macOS applications to a managed fleet, a fleet software-deployment engine of about 7,000 lines of Python with a self-healing lock subsystem, and a zero-dependency security-audit tool that collects access-review evidence from seven SaaS platforms.
I own the infrastructure and the security posture underneath all of it: Terraform for a DigitalOcean fleet, a CIS-style Linux and SSH hardening toolkit I wrote from scratch, TLS and certificate lifecycle, and network segmentation across global offices. I build secure-by-default and fail-safe: strict CSP and CSRF, rate limiting, supply-chain integrity checks, and automation designed to stop rather than cause damage when something looks wrong.
A senior engineer who takes end-to-end ownership: platforms that integrate cleanly, fail safe, and keep running with little hand-holding, which means fewer repeated incidents and data you can trust across systems.
BA — English Linguistics and Literature
MA — English Literature
Issued Jul 2021
Issued Feb 2021
English Translator — The Ministry of Foreign Affairs of the Republic of Serbia · Dec 2014 — Dec 2015