Go · Platform Engineering · Systems Integration · Identity & Security Automation

Turning complexity into reliability.

I build and own Go platforms that run an organization’s core operations: integrating identity, devices, HR, and assets, and automating everything between them.

LinkedIn GitHub
📍 Location
Belgrade, Serbia
🎯 Focus
Platform & backend engineering, systems integration, IAM, security automation
🧠 Core
Go, Okta, Jamf, Terraform, PostgreSQL, Docker, Linux

About

I’m a platform and backend engineer. I design, build, and own Go systems end to end, and I’m the primary author of the internal platform that runs my company’s IT operations. My work is an organization’s connective tissue: services that integrate identity, device, HR, and asset systems, automate the work between them, and keep running for years without hand-holding.

More details

The platform is roughly 20,000 lines of Go running as a single binary: an HTTP API plus two background-worker pools that unify nine enterprise systems (Okta, Jamf Pro, BambooHR, Snipe-IT, Cloudflare, Slack, Jira, Planhat, Datadog) into one control plane. It runs the entire employee IT lifecycle on an idempotent, failure-aware job queue: event-driven provisioning on hire, continuous cross-system reconciliation, and safe, gated deprovisioning on departure. That includes a SCIM-style access-governance engine that keeps downstream tool access in lockstep with identity.

That is one system among several I have shipped and own. I have built full-stack Go web apps backed by PostgreSQL with Google OIDC single sign-on and hardened sessions, a pipeline that catalogs and distributes 77 macOS applications to a managed fleet, a fleet software-deployment engine of about 7,000 lines of Python with a self-healing lock subsystem, and a zero-dependency security-audit tool that collects access-review evidence from seven SaaS platforms.

I own the infrastructure and the security posture underneath all of it: Terraform for a DigitalOcean fleet, a CIS-style Linux and SSH hardening toolkit I wrote from scratch, TLS and certificate lifecycle, and network segmentation across global offices. I build secure-by-default and fail-safe: strict CSP and CSRF, rate limiting, supply-chain integrity checks, and automation designed to stop rather than cause damage when something looks wrong.

What I build

  • Go platforms that unify identity, device, HR & asset systems
  • Full-stack internal web apps (Go, PostgreSQL, OIDC SSO)
  • Event-driven background-job systems (idempotent, self-healing)
  • Fleet automation & software distribution at scale

What I run

  • Go services on Linux (DigitalOcean), single-binary deploys
  • Terraform IaC & hardened server fleets
  • Containerized deployments (Docker, distroless)
  • Okta IAM (SSO/SCIM/OIDC) & macOS fleet (Jamf Pro)
  • TLS lifecycle, networks (VPN, firewall, VLANs) across offices

How I work

  • Secure-by-default, observable-by-design
  • Idempotent, failure-aware workflows that fail safe
  • Clear ownership, explicit interfaces, predictable behavior
  • Docs that stay alive (and short)

Skills

GoPythonBashBackend & systems engineeringFull-stack web (Go)Systems integrationREST API integrationsEvent-driven / background jobs (Faktory)PostgreSQL / GORMIdentity & Access ManagementOkta (SSO/SCIM/OIDC)OAuth2 / OpenID ConnectWeb security (CSP, CSRF, rate limiting)Terraform (IaC)DockerLinux admin & hardeningTLS / certificate lifecycleDigitalOcean / AWS (S3, CloudFront)CloudflareJamf Pro / macOS fleetGitLab CI/CDDatadog

Strengths

  • Designing and owning Go platforms that integrate many real-world systems
  • Failure-aware architecture: idempotency, safe retries, fail-safe writes
  • Identity & access automation across the full employee lifecycle
  • Turning ambiguous operational problems into systems I can own for years

What teams get

A senior engineer who takes end-to-end ownership: platforms that integrate cleanly, fail safe, and keep running with little hand-holding, which means fewer repeated incidents and data you can trust across systems.

Experience

Systems Developer · LearnUpon Ltd.
Oct 2025 — Present
  • Primary author and architect of an internal IT-automation platform in Go (~20K LOC, single binary, HTTP API plus two background-worker pools) that unifies nine enterprise systems into one control plane
  • Designed an event-driven, idempotent job system (Faktory) with a serialized write queue for race-free changes to external systems and fail-safe guards that never act on unverifiable data
  • Built a SCIM-style access-governance engine using Okta group membership as source of truth to grant, revoke, and continuously reconcile access across Datadog, Planhat, and Jamf
  • Automated the entire employee IT lifecycle: event-driven provisioning, HR-driven onboarding and offboarding ticket automation, timezone-aware deactivation, and gated device wipes
  • Shipped full-stack Go web apps (PostgreSQL/GORM, Google OIDC SSO, hardened sessions, CSRF) and a zero-dependency access-review tool spanning seven SaaS platforms
Senior IT System Administrator · LearnUpon Ltd.
Mar 2023 — Oct 2025
  • Started and led the Go engineering now central to IT operations, including the automation platform above, while owning network, endpoint, and cloud operations across global offices
  • Authored a macOS software-deployment engine (~7K LOC Python) run fleet-wide via Jamf Pro, with a self-healing atomic-locking subsystem and a generic multi-format installer
  • Built a 77-application software-catalog pipeline feeding fleet auto-updates: fault-tolerant parallel scraping, supply-chain integrity checks, and keyless CI/CD to AWS S3 and CloudFront
  • Owned Terraform IaC for a DigitalOcean fleet and wrote a reusable Linux and SSH hardening toolkit from scratch (CIS-style baseline, audit, and user-lifecycle automation)
  • Redesigned onboarding and access workflows to standardize access, reduce wait time, and cut support load
IT Administrator · LearnUpon Ltd.
Feb 2021 — Mar 2023
  • Built and grew a ~250-script fleet-automation library (Bash, Python, Go) for configuration, security, and inventory across the macOS estate, deployed via Jamf Pro
  • Engineered certificate and Wi-Fi (EAP-TLS) tooling and self-contained service subsystems, including a reverse-SSH remote-access system and a centrally governed application firewall
  • Handled provisioning, onboarding, and troubleshooting across endpoints and office networks, and improved operational documentation and workflows
IT Support Engineer · Hyperoptic Ltd.
Jul 2020 — Feb 2021
  • Investigated incidents with root-cause focus and consistent ticket hygiene
  • Supported Windows/Azure AD/Intune operations and device lifecycle processes
  • Improved processes and trained users to reduce repeat issues

Education

University of Belgrade

BA — English Linguistics and Literature

University of Belgrade

MA — English Literature

Languages

  • English — Native/Bilingual
  • Serbian — Native/Bilingual

Certifications & Volunteering

Jamf Certified Associate

Issued Jul 2021

macOS for IT Administrators

Issued Feb 2021

Volunteering

English Translator — The Ministry of Foreign Affairs of the Republic of Serbia · Dec 2014 — Dec 2015