DL

Doanh Luong

Senior Software Engineer, SAP

Rugby, UK

Building secure, cloud-native key-management systems for thousands of enterprise tenants — BYOK/HYOK encryption, distributed schedulers, and compliance infrastructure across AWS, Azure, GCP and Kubernetes. PhD in networking protocols before industry.

Summary

Senior Software Engineer with 5+ years building cloud-native distributed systems at SAP, mostly around secure key management and encryption services for thousands of enterprise tenants. Day-to-day work is customer-data-protection infrastructure: Bring Your Own Key / Hold Your Own Key (BYOK/HYOK) cryptographic key lifecycle management, multi-stage approval workflows for security-sensitive operations, and audit/compliance services, running across AWS, Azure and GCP on Kubernetes. Before industry, spent 4 years in postdoctoral research on networking protocols (PhD in Multipath TCP) and applied machine learning — the source of a protocol-level, systems approach to scale, resilience and security. Works mainly in Go, Python and C++, partnering with product, security and QA to get things from design into production.

Experience

Senior Software Engineer · SAP, UK

  • Defined the service architecture and gRPC contracts for HYOK/BYOK enterprise encryption services covering thousands of enterprise tenants, building reusable interfaces other SAP product teams now build on.
  • Architected a distributed scheduler/worker framework for cryptographic key lifecycle management, certificate rotation and platform maintenance, built so each component scales independently across pods.
  • Designed a multi-stage "6-eyes" approval architecture for security-sensitive cryptographic operations like key deletion, including policy-driven automation, voting/threshold logic, notification workflows and tenant-level governance.
  • Led the Audit Log Service integration across cloud landscapes (Canary, Staging, Production), setting implementation standards and deployment strategy and owning end-to-end validation for compliance and data-protection auditing.
  • Wrote the architecture specs and implementation guidance for AWS-based HYOK integrations; selected HSM protection level for BYOK key material in AWS/GCP KMS and integrated with Fortanix for HYOK. Main technical point of contact between engineering, product, QA and architecture.
  • Provides on-call coverage and leads incident triage/remediation for the KMS platform, using Grafana, Prometheus and OpenTelemetry for monitoring, alerting and distributed tracing.
  • Core contributor to the open-source Open Key Chain Manager project, extending its enterprise key-management and secure integration capabilities.

Software Engineer · SAP, UK

  • Designed and delivered the core architecture for SAP's Key Management Service (KMS): scalable REST APIs, cryptographic key lifecycle management and cloud-native integrations across AWS, Azure and GCP.
  • Built the authentication/authorization architecture for a multi-tenant SaaS platform, integrating OAuth2 and OpenID Connect with SAP's Identity Service.
  • Built fault-tolerant asynchronous workflows for key backup and recovery using Python, Celery and AWS SQS, improving scalability and resilience for security-critical operations.
  • Delivered a tiered Data Retention component moving audit data from Aurora (hot) to S3/Athena/Glue (cold), cutting retrieval time by orders of magnitude for thousands of tenants and reducing storage costs.
  • Built secure data-export services for large-scale tenant data extraction, with cloud object storage integration and access controlled through pre-signed URLs.

Postdoctoral Research Fellow · University of Bradford, UK

  • Designed Simulated Annealing and Genetic Algorithm solutions for network link selection, improving application satisfaction by 15% and cutting access failures by 26%; used Deep Reinforcement Learning to cut controller-placement runtime by 65% at 99.3% accuracy.
  • Published fastcli and sdwancli on Cisco DevNet CodeExchange — Python libraries for automating routing-protocol configuration (BGP, OSPF, EIGRP) and SD-WAN management via REST APIs.

Postdoctoral Research Associate · University of Siena, Italy

  • Implemented Random Linear Network Coding (RLNC) in a satellite transport-layer stack (C++), improving power gains by 40%; combined with Multipath TCP, raised TCP goodput by 80% over unreliable satellite links.
  • Designed a multi-stage gateway scheduler architecture for an ESA-funded satellite communications project.

Technical Skills

Security & Cryptography

BYOK/HYOKHSMAWS KMSGCP KMSFortanixKey lifecycle managementOAuth2OpenID ConnectmTLS

Programming Languages

GoPythonC++JavaScript

Distributed Systems

gRPCScheduler/worker frameworksEvent-driven processingCeleryAWS SQS

Cloud & Infrastructure

AWSAzureGCPKubernetesCRDs / OperatorsDockerMicroservicesAnsible

Observability

GrafanaPrometheusOpenTelemetry

Databases

PostgreSQLMySQLAWS AuroraS3 / Athena / Glue

Networking

MPTCPRLNCBGPOSPFEIGRPSD-WANSDN / OpenFlow

Projects

Open Key Chain Manager →

Core contributor — extending its enterprise key-management and secure integration capabilities.

fastcli →

Nornir-based CLI for generating and deploying multi-vendor routing-protocol configuration — published on Cisco DevNet CodeExchange.

sdwancli →

Python CLI wrapping Cisco SD-WAN vManage's REST API for device, template and overlay management — published on Cisco DevNet CodeExchange.

Certifications

Education

PhD, Telecommunications — University of Siena, Italy

Full scholarship. Thesis: Combining Multi-Path Protocols and Network Coding in Mobile Satellite Systems.

B.S.E., Electronics and Telecommunications — Hanoi University of Science and Technology, Vietnam

Ranked 5/507 in the Department; Certificate of Merit for Excellent Graduation.