Feb 2026 – Present
Remote
Chief Technology Officer · Automaark
DirectStay (short-term rental marketplace) and its supporting blog/content platform
- Leading a complete, ground-up rebuild of DirectStay's booking, payment, and compliance systems, replacing the earlier implementation end-to-end rather than patching it, while directing a team of engineers across backend and frontend.
- Rebuilt the booking/payment/insurance/tax pipeline from scratch: concurrency-safe booking transactions (Postgres serialization-failure handling, pre-commit price/policy re-validation), a refund-and-cancellation engine with retry/backoff, and real integrations with Forward (payments), Tint (insurance), TygaBank (payouts/ACH), and TaxLodge (tax), taking the platform from unreliable under load to correctness-critical infrastructure it could actually run bookings on.
- Built a merchant-boarding module end-to-end: payment processor application, KYC, webhook, and account-lifecycle APIs, plus a 9-step guided property-listing wizard with resumable draft state.
- Led formal, written code review across the engineering team: five module-level reviews with numbered findings, including two that produced 15- and 17-point security/architecture finding lists tracked to closure.
- Established CI/CD and security posture for the platform: SAST scanning, container/dependency scanning, and automated boot smoke tests gating every merge.
- Rebuilt the auth, authorization, and audit layer of the company's blog platform, including a full ABAC policy engine and a three-tier audit trail, and separately identified and remediated an existing backdoor and an SSRF vulnerability in the same codebase.
- Built the SSO bridge connecting the DirectStay and blog platforms under a shared identity layer.