Entropa_

aimozart

Phoenix, AZ, USA · Remote only

Backend / Systems Engineer — Java · Spring Boot / Spring Cloud Microservices · Kafka · Kubernetes · AI Agent Infrastructure

✓ AWS Certified Solutions Architect – Associate ✓ Databricks Certified Associate Developer for Apache Spark Google for Startups Cloud Program

Summary

Backend and systems engineer building Entropa, a tamper-evident audit-trail platform for AI-agent decisions, as a real Java 21 / Spring Boot / Spring Cloud microservices system: Eureka service discovery, a centralized Config Server, an OAuth2/JWT-secured Spring Cloud Gateway, Kafka-driven event flow between an ingest service and a single-writer transparency/hash-chain service, PostgreSQL persistence, Keycloak identity, and a Stripe-integrated demo signup flow — containerized with Docker and deployed on Kubernetes (GKE) via a templated Helm chart, behind a real SSL-terminated load balancer. Built and shipped solo, end to end: service design, security, CI/CD, observability, incident response — real production bugs (Kafka authentication misconfiguration, broken config-server wiring, JVM startup tuning under constrained resources) found and fixed the same session, not hand-waved past.

Prior credential: also designed and built Entropa's original Rust implementation — a production network with real ML-DSA (NIST FIPS-204) post-quantum signatures, verified byte-exact against NIST's own ACVP test vectors, and a beacon-seeded consensus mechanism (Proof of Entropy) — before migrating the system to the current Java/Spring microservices architecture.

I direct AI coding tools for a large share of implementation, and I'm the one setting architecture, reviewing code closely enough to catch real bugs, and driving debugging when production breaks — Entropa's own incident history is the record of that, not just a claim.

Also a data engineer with 12+ years in enterprise IT and security operations (SIEM, EDR, ITIL) plus hands-on HITRUST/HIPAA compliance work, and lakehouse experience across Apache Spark, Iceberg, and Delta Lake.

Work arrangement

Flagship project

Entropa — audit-trail platform for AI-agent decisions (Java / Spring microservices)

May 2024 – Present · entropa.space

  • Microservices architecture: Java 21 / Spring Boot 3.3.5 / Spring Cloud — Eureka service discovery, a centralized Config Server, and a Spring Cloud Gateway securing every downstream route with OAuth2/JWT.
  • Event-driven design: Apache Kafka connects an ingest service to a single-writer transparency service that appends to a real tamper-evident hash chain, persisted to PostgreSQL via JPA/Hibernate.
  • Identity & security: Keycloak (OAuth2/OIDC) for machine-to-machine auth, Resilience4j circuit breakers on every downstream call, secrets never in remote config.
  • Cloud-native deployment: Docker multi-stage builds, Kubernetes (GKE) via a templated Helm chart, a real SSL-terminated GCE load balancer with a Google-managed certificate, and a Stripe-integrated demo signup flow.
  • Production operations: real incidents found live and root-caused, not assumed — Kafka SASL authentication misconfiguration, a config-server packaging bug that left every service running on empty configuration, JVM startup tuning under constrained CPU — each diagnosed from actual logs and fixed the same session.

Technical skills

Backend / Systems: Java 21, Spring Boot 3, Spring Cloud (Eureka, Config Server, Gateway), Apache Kafka, PostgreSQL + JPA/Hibernate, OAuth2/OIDC (Keycloak), Resilience4j, REST API design, microservices architecture.
Cloud-Native / DevOps: Docker (multi-stage builds), Kubernetes (GKE), Helm, GCE HTTPS load balancers with Google-managed TLS, Cloud DNS, Secret Manager, IAM.
Prior credential (Rust): async Rust (axum), post-quantum cryptography (ML-DSA/FIPS-204), distributed consensus design, hash-linked verifiable data structures, Cloud Run, Firestore, CI/CD (GitHub Actions, OIDC Trusted Publishing).
Data Engineering: Apache Spark 3.5 (PySpark & Spark SQL + Scala), advanced SQL, Apache Iceberg, Delta Lake, medallion architecture, SCD Type 2, structured streaming, data-quality gates, performance tuning.
ML / AI: MLflow, XGBoost (GPU), scikit-learn, SHAP, drift monitoring, RAG/embeddings, AI-agent orchestration.
Cloud & Storage: GCP (Cloud Run, Cloud Build, Firestore, Secret Manager, IAM, Dataproc, BigQuery, GCS, CMEK) — primary, production hands-on. AWS (S3, EC2, IAM, KMS) — certified at Associate level.
Platform & Ops: Docker, Prometheus + Grafana, CI/CD, Git, Kafka/Redpanda, Linux, Python, SQL.
Governance & Security: data lineage & catalogs, HIPAA/HITRUST, SOC 2, IAM least-privilege, SIEM/EDR.

Certifications & recognition

Full Credly profile →

Other projects

Open lakehouse platform

github.com/aimozart/MegaMart

Intentionally-dirty multi-source retail data through Bronze → Silver → Gold on Apache Iceberg, then ML (churn/fraud with MLflow + GPU XGBoost) and a Streamlit dashboard layer. Runs locally and on GCP.

Production containerized lakehouse

Apache Spark 3.5 + Delta Lake + object storage + Kafka + automated code-quality gating, real-time event streaming, medallion pipelines. Functional Scala.

Professional experience

Backend / Data Engineer — Independent Projects & Continuous Practice

Remote · December 2022 – Present

Progression from lakehouse data engineering into systems/backend engineering, with AI/ML and AI-agent orchestration integrated throughout. Designed and built two complete lakehouses; directed the design and build of Entropa, first as a Rust consensus engine and cryptographic core, then migrated to its current Java/Spring Cloud microservices architecture on Kubernetes; trained and tracked ML models with MLflow; directed and safety-gated a Claude-driven AI-agent decision pipeline in production.

Senior IT Analyst & Security Administrator

Enterprise manufacturing, global fleet · June 2019 – August 2022

Governed enterprise EDR across a global fleet; administered PAM for zero-trust credential security; engineered automated OS imaging and patch-management, neutralizing zero-day exposure.

Desktop & Systems Support Engineer

Enterprise IT services, retail client · April 2018 – June 2019

Led rapid remediation during mission-critical outages, restoring 24/7 retail application uptime; authored SOPs and remediation documentation.

Information Security & Compliance Analyst

Healthcare chart-retrieval, HITRUST-certified org · April 2014 – October 2017

Co-authored the enterprise security-policy framework, drove remediation resulting in official HITRUST certification and continuous HIPAA compliance; managed secure PHI chain of custody.

Level 3 Linux Systems Engineer

Web hosting infrastructure provider · July 2012 – February 2014

Managed technical escalations for 120+ enterprise accounts; server hardening, VPS security, database optimization on Ubuntu/RHEL.

Education

Coursework toward B.S., Information Technology — network security, systems administration, database management, enterprise architecture. 2008 – 2011.

Get in touch

Opens your email client, addressed directly to aimozart.