About
I build backend systems for environments where getting access control, data integrity, or encryption wrong is the whole risk: health platforms, fintech, legal tech. I design schemas, APIs, infrastructure, and deployment from scratch, and I build security into the architecture itself rather than adding it as a layer on top afterward. AI tooling is part of how I work now, both for coding and as a thinking partner when working through architecture decisions. Most of this work lives in private repositories, but the systems are running in production at banks, clinical labs, and estate planning companies. I'm writing up some of the architecture and security decisions behind that work as case studies, linked below.
Experience
Health tech platform turning lab biomarker data into personalized medical reports and action plans.
- Integrated with legacy German lab systems over DFÜ, parsing LDT files, routing results through a queue-based pipeline, and storing them as normalized, age- and gender-adjusted biomarker records in PostgreSQL
- Built a scoring engine that weights each biomarker result against its reference range and feeds a rules system for personalized action plans (nutritional, supplements, exercise). The rules were developed with AI: drafted, tested, and refined over time using patterns drawn from user data and external medical sources.
- Enforced Row-Level Security at the database layer so no application code can bypass access controls on sensitive medical data
- Structured the pipeline as isolated services (ingestion, analysis, report generation) so each step can fail, retry, or scale without affecting the others
- Added a medical professional review step before results reach users; the system holds notifications until a doctor approves the report
iPaaS platform for building event-driven automation workflows across external systems, without writing code.
- Built the integration layer connecting 15+ external systems, each with its own API quirks and failure modes
- Used dead-letter queues for failed events; each workflow could be configured to retry or abort on integration failure, depending on what the user had defined
- Provisioned all infrastructure as code with AWS CDK: IAM roles, queues, databases, per-environment config
- Designed the PostgreSQL schema to store workflow definitions as structured configuration rather than code, so users could build and modify flows without touching deployments
Digital estate planning platform for banks and insurers, built from zero and acquired in 2023.
- Designed the core encryption model: user data is encrypted with a key only the user holds (Ninebarc has no access), with a split-key trustee system for post-mortem access by beneficiaries
- Built a dead man's switch: if a user stops responding to periodic check-ins after repeated attempts, the system initiates a death-verification flow and contacts trustees to retrieve their key halves
- Generated legally valid estate documents, some requiring Qualified Electronic Signatures (QES) under eIDAS, others (like notarised wills) producing the exact legal template and wording users must sign physically
- Took the architecture from zero to acquisition. The same encryption and trustee model was still running unchanged when the company was sold
- Post-acquisition: integrated our APIs and data models into the acquiring company's platform without service interruption or data loss
Backend systems serving 10,000+ users across multiple countries; built internal tooling for a team spread across timezones.
Embedded Strands' product into the internal systems of multiple banks, adapting to each bank's proprietary architecture and constraints; designed Oracle DB schemas for high-volume transactional data. Led teams of up to 7 engineers across development, code review, and technical pre-sales, and also ran the Buenos Aires office.
Case Studies
Deeper writeups on architecture and security decisions from the work above. New ones added as they're written.
Zero-access by construction: encryption and posthumous release at Ninebarc
A layered key-wrapping model and a four-gate release flow, designed so Ninebarc had no way to read its own users' data, and why the design held through a cloud migration and an acquisition.
Read the case study →Row-Level Security for medical data at aescolabComing soon
A threat model and access control writeup for the RLS design that keeps biomarker data isolated at the database layer, including what it does and doesn't protect against.
Projects
Self-contained builds, outside of client work, exploring specific architecture problems.
A standalone OpenID Connect provider and Express middleware for role-based access control, built to keep identity and authorization separate: the provider only knows users and roles, and each API owns its own role-to-permission mapping and checks it locally, with no runtime call back to the provider (the Keycloak/Entra pattern, not Auth0's centralized permissions). Authorization Code + PKCE flow, JWT access tokens, refresh token rotation that revokes the whole token family on replay, codes and tokens stored as hashes. Memory, SQLite and Postgres stores, 42 tests, CI and npm release pipelines. Includes a working example stack: a documents API behind the middleware and a console app that shows the token exchange hop by hop.
Skills
- Languages
- TypeScript, Node.js, Java, Python
- Databases
- PostgreSQL, Oracle
- Infrastructure
- AWS (CDK, IAM), serverless, infrastructure as code
- Security & Compliance
- Row-Level Security, encryption and key management, split-key/trustee designs, eIDAS/QES compliance, medical-data access controls, secure API design
- Systems
- Event-driven architecture, queue-based pipelines, service decoupling, dead-letter queues
What I'm looking for
I'm looking for staff or principal backend and architecture roles in domains where the engineering actually matters: complex data models, regulated environments, systems that can't afford to get it wrong. Berlin-based or remote. If that sounds like a fit, hit me up.
Get in touch →Education
Systems Engineering
National University of Technology, Buenos Aires, 2009 – 2014