
Software Architect at StumbleUpon
San Francisco Bay Area

Software Architect at StumbleUpon
San Francisco Bay Area
Systems architect with hands-on experience on desgin & development of scalable, secure systems with high availability and performance.
Application stack bottleneck analysis and scalability consultant. Hands-on architect in Scrum based development teams employing Web 2.0 popular products and technologies.
- Ruby, Python, PHP web application frameworks.
- Apache, lighttpd, nginx and Mongrel HTTP service layers.
- Linux, Solaris and OpenBSD operating environments.
- Xen and Virtuozzo based virtualization platforms.
- Amazon S3, CloudFront, EC2, SQS and SimpleDB.
Hands-on solution architect for porting existing systems to modern distributed computing platforms for horizontal scaling and high availability.
- Hadoop Map/Reduce clusters.
- HDFS distributed storage and HBase DB.
- Terracotta based JVM clusters.
Enterprise Systems S/I/S Consultant:
- J2EE Application Systems and RDBMS bottleneck analysis. (Oracle iAS, WebSphere, JBoss, Oracle, MySQL)
Enterprise integration architect with experience on SOA adaptation, ESB implementations and legacy to open systems integration.
Information security consultant: Security policy development, awareness and incident handling trainings, business continuity and disaster recovery planning, ISO/IEC 27000-series ISMS.
Security engineer: Penetration tests, hardening, incident handling, managed security services.
Product development for network border defense, DoS mitigation, load balancing and cryptography border appliances based on OpenBSD.
- Instant PoC capable hands-on architect.
- Long time UNIX and network programming skills in C.
- Code Security Auditor, Incident Handler, Computer Forensics Investigator.
- Technical speaker with non-conventional presentation skills.
- ISO 27001 Lead Auditor [Mar, 2007]
- CISSP (Certified Information Systems Security Professional) [Apr, 2007]
- CISA (Certified Information Systems Auditor) [Sep, 2008]
(Privately Held; Internet industry)
October 2009 — Present (2 months)
Generic monkey in charge, working on things StumbleUpon do.
(Privately Held; Information Technology and Services industry)
August 2005 — September 2009 (4 years 2 months)
• Scalability
- Principal architect for design and implementation of massively parallel application systems.
- Bottleneck analysis and refactoring of multi tier application systems on J2EE, .NET and LAMP stack.
- RDBMS optimization on MySQL and Oracle via engine tuning, v/h sharding and query refactoring.
- Migrating existing systems to modern distributed computing platforms for horizontal scaling and high
availability with Hadoop MapReduce clusters, column-oriented distributed databases with HBase and
JVM clusters with Terracotta.
- Design, implementation and integration of geo distributed content delivery networks and caches.
Anycast and multicast content delivery networks.
• Integration
- SOA adoption consultant, designing and developing service end-points, adapters and proxies based on SOAP, XML-RPC web services and RESTful web applications with XML/JSON.
- ESB implementations with Oracle Fusion, BEA AquaLogic and Apache ServiceMix.
- Message Queue, Business Process Mgmt. and Data Services Platform integrations to ESB.
- Intra-system integration with Thrift and Google Protobuf based binary serialization and RPC services.
• Security
- Security architect (CISSP & CISA) for software product line and customer proprietary IS projects.
- Black box/white box vulnerability assessment, penetration testing and audit automation.
- MSSP operations lead for homeland security, armed forces, law enforcement and finance sector.
• Business Continuity and Disaster Recovery Planning & Compliance (2006-2007)
- Full life cycle BC & DR implementation in government and multi-enterprise level projects.
- Full life cycle ISMS standards compliance auditor for ISO-27000 and PCI-DSS.
• Product Development (2004-2006)
- DDoS Mitigation Appliances, Crypto Border Gateway Load Balancers.
- Kernel level development for OpenBSD based, embedded network security appliances.
(Public Company; 11-50 employees; Internet industry)
July 2003 — August 2005 (2 years 2 months)
(Self-Employed; Myself Only; Computer & Network Security industry)
October 1999 — June 2003 (3 years 9 months)
- Contract agent with Andersen Consulting.
- Enterprise risk assessments, penetration tests, incident handling, computer forensics and technical speaker.
- UNIX migrations, HPC and high availability clusters.
(Privately Held; 11-50 employees; Internet industry)
August 1996 — June 1999 (2 years 11 months)
M.Sc. Candidate , Software Engineering , 2004 — 2009
B. Sc. , Computer Engineering , 2000 — 2003
Started as an incoming sophomore from Electrical and Electronics Engineering.
B. Sc. , Electrical and Electronics Engineering , 1999 — 2000
Dean's List
Photography, Italian Cusine, Wine, Postmodern Literature, MapReduce clusters, Column-oriented DBs, JVM scalability, Scala, Python, Ruby.
IEEE, IEEE Computer Society, (ISC)², ISACA
- ISO 27001 Lead Auditor [Mar, 2007]
- CISSP (Certified Information Systems Security Professional) [Apr, 2007]
- CISA (Certified Information Systems Auditor) [Sep, 2008]
>> Both CISSP and CISA certifications are approved as “Information Assurance (IA) Professional” designations by US Department of Defense (DoD) 8570.01-M "Information Assurance Workforce Improvement Program"