Product Developer I at BMC Software (2022-06 – Present)
Key Project: True Sight Server Automation (TSSA) — Enterprise platform for automated vulnerability management, patching, compliance, and software deployments across data centers and cloud environments.
- Architected and delivered 20+ Spring Boot 3 REST APIs (Open API/Swagger), improving automation workflow throughput by 20% through optimized Patch Service orchestration and Redis-based caching strategies.
- Led monolith-to-microservices decomposition of patch module; designed scalable distributed services with high availability and fault tolerance, enabling seamless inter-service communication via Spring Cloud.
- Built responsive UI components using Innovation Studio (IS Framework) with real-time Spring Boot API integration across multiple frontend surfaces.
- Engineered and maintained JUnit 5 / Mockito unit and integration test suite (JaCoCo coverage), raising code coverage by 8% and reducing production regressions by 15% across two major releases.
- Built GenAI-powered Release Document Copilot POC using BmcHelix, enabling first-contact automated support and increasing team efficiency by 40%.
- Implemented CI/CD pipelines via Jenkins; deployed services on AWS (ECS/EKS) with Docker and Kubernetes; enforced code quality gates using SonarQube.
- Enforced role-based access control (RBAC) and audit logging across TSSA services, supporting compliance posture for enterprise clients managing CVE remediation and vulnerability patching workflows.
Software Engineer at Mastercard (2020-01 – 2022-05)
Key Project: Mastercard Payment Gateway Services (MPGS) — Secure, high-throughput online payment platform processing millions of transactions globally across credit/debit cards and digital wallets.
- Designed and maintained high-throughput Java microservices (Spring Boot, Hibernate ORM, RESTful APIs) supporting payment processing at scale with 99.9% uptime SLA.
- Engineered web application security layer using Spring Security and JWT tokens — implemented role-based access control (RBAC), stateless session management, token refresh flows, and request-level authorization filters, hardening the payment gateway against unauthorized access and ensuring PCI-DSS compliance across all service layers.
- Reduced mean-time-to-resolve (MTTR) for P0/P1 incidents by 30% through structured triage, feature-flag rollback planning, and root cause analyses, maintaining zero critical data breaches.
- Developed comprehensive unit, integration, and performance tests using JUnit, Mockito, and TestContainers, maintaining production-grade reliability and reducing test flakiness by 20%.