Senior Software Engineer · SAP, UK
Jan 2024 – Present- Defined the service architecture and gRPC contracts for HYOK/BYOK enterprise encryption services covering thousands of enterprise tenants, building reusable interfaces other SAP product teams now build on.
- Architected a distributed scheduler/worker framework for cryptographic key lifecycle management, certificate rotation and platform maintenance, built so each component scales independently across pods.
- Designed a multi-stage "6-eyes" approval architecture for security-sensitive cryptographic operations like key deletion, including policy-driven automation, voting/threshold logic, notification workflows and tenant-level governance.
- Led the Audit Log Service integration across cloud landscapes (Canary, Staging, Production), setting implementation standards and deployment strategy and owning end-to-end validation for compliance and data-protection auditing.
- Wrote the architecture specs and implementation guidance for AWS-based HYOK integrations; selected HSM protection level for BYOK key material in AWS/GCP KMS and integrated with Fortanix for HYOK. Main technical point of contact between engineering, product, QA and architecture.
- Provides on-call coverage and leads incident triage/remediation for the KMS platform, using Grafana, Prometheus and OpenTelemetry for monitoring, alerting and distributed tracing.
- Core contributor to the open-source Open Key Chain Manager project, extending its enterprise key-management and secure integration capabilities.