Aryan KapoorBangalore, India

Architecting the invisible.
Scaling the impossible.

Software engineer working on distributed backend systems and platform infrastructure — event-driven architecture, service authorization, multi-region delivery, and the networking underneath all of it.

Open to backend, platform, and infrastructure roles

6+
Years building production systems
01

Experience

Platform work with real operating constraints.

Distributed state, secure remote access, multi-region delivery, and the networking underneath it.

Nov 2021 — PresentCurrent

Software Engineer III

Ericsson

Owns platform-level systems across remote diagnostics, secure access, event-driven data distribution, and authorization for Ericsson's enterprise networking products — several of which became foundational frameworks adopted across the wider microservice platform. Work spans the device data plane, the platform substrate, the multi-region deployment fleet, and more recently LLM-based operator tooling.

01

Speedtest Framework

Led a team to own end-to-end design and delivery of a remote diagnostics platform processing over 2 million speedtest runs per month to assess WAN performance across Ericsson devices. Drove expansion into a full troubleshooting suite — ping, traceroute, packet capture — with inbuilt automation enabling customers to perform preemptive network monitoring. Routed test traffic through AWS Global Accelerator so ~100 individually addressable measurement servers gained stable public reachability without changing an already-deployed probe fleet.

02

Remote Connect

Architected and delivered a secure remote access system supporting 10,000+ concurrent sessions across HTTP, SSH, RDP, and VNC with sub-5-second connection times, deployed as part of Ericsson's SASE solution. Drove design decisions on session brokering (Apache Guacamole) and automatic device discovery via DHCP, reaching machines on private customer networks through a device-originated reverse tunnel with no inbound firewall change.

03

Core Facts

Designed and implemented a distributed, event-driven framework that eliminated direct database dependency — streaming entity state via Kafka into per-service Redis caches, with atomic Lua-backed indexing, freshness guardrails, and replay-based cache rebuilds. Adopted across a large number of microservices on the platform.

04

Roles and Permissions Framework

Built a fine-grained, multi-tenant RBAC framework using Open Policy Agent (OPA) for declarative, AWS IAM-style policy enforcement, letting 20+ microservices define their own roles and enforce authorization consistently at the API, account, and individual-object level across three languages.

Explore more work at Ericsson6 workstreams
05

AI-Based NetCloud Assistant (ANA)

Contributed to an LLM-powered agentic troubleshooting system using LangGraph and AWS Bedrock (Claude), featuring tool-use orchestration, RAG-based knowledge retrieval (OpenSearch), and a dual-pipeline Rasa NLU chatbot with custom LLM intent classifiers and real-time WebSocket streaming.

06

Remote Task Execution Framework

Owned the response-correlation and worker-decoupling path of an asynchronous RPC framework that lets any cloud workflow run commands on intermittently connected devices behind NAT — without the caller knowing which gateway process owns the device socket. Backend logic moved off the connection tier, so backend and schema changes stopped disturbing live device connections.

07

Common Data Platform

Worked on the streaming funnel service, Avro schema-contract enforcement, and the data-lake ingest path of a Kafka-backed platform that treats data as the first-class component. Normalized raw device telemetry into 20+ schema-managed topics and used Kafka Streams windowing to compute 15-minute and hourly rollups, with a lake path from raw events to partitioned analytics.

08

Regional Stack Sharding

Owned service infrastructure delivery into a fleet of whole-stack regional shards — each tenant assigned to a complete deployment with its own AWS account, VPC, cluster, and data stores. Wired dependencies, state, and capacity across production-class shards in the US, Europe, and Australia, lifting the monolithic database ceiling and meeting data-residency requirements.

09

SD-WAN Overlay Dataplane

Worked on a DPDK userspace forwarding path doing GRE encapsulation, DSCP-aware WAN bonding, packet duplication, reordering, and forward error correction across unreliable links. Traced a structural GRE MTU fragmentation problem to the tunnel interface and addressing model, then redesigned the per-tunnel receive and shared transmit split that removed it.

10

Single-VM Private Deployment

Contributed the device stream server, cloud-abstraction layer, and on-premise network design that let an eight-service, seven-datastore cloud product ship as one self-contained air-gapped VM appliance — installable in about fifteen minutes with no outbound internet access, from the same codebase as the cloud build.

July 2020 — Oct 2021

Software Engineer

Codehall

Built a high-traffic B2B coding assessment platform used by companies to run technical interviews and online assessments at scale.

01

Online Coding Portal (OCP)

Built a high-traffic B2B coding assessment platform used by companies to conduct technical interviews and online assessments at scale, supporting 3,000+ active interview sessions with collaborative code editors, session recording (audio, video, chat), code playback, and data-driven insights for evaluating candidate performance.

02

Code Execution Engine

Implemented the sandboxed multi-language code execution engine behind the portal, along with the real-time collaborative editor and the live session monitoring and playback path that reviewers used to evaluate candidates after the fact.

02

Independent builds

Learning the mechanism, not just the interface.

Emulators, network simulators, kernels, games, and small products—built to understand where the abstraction ends.

03

About

Backend, platform, networking, and the systems underneath them.

I am a senior software engineer based in Bangalore with six years of experience building backend and platform systems for large-scale SaaS products. My work sits where distributed state, networking, security, and infrastructure meet: event-driven data platforms, multi-tenant authorization, remote access and diagnostics, and evidence-grounded AI systems.

I care about explicit trade-offs, observable failure modes, and keeping claims grounded in what actually shipped. I am open to conversations about backend, platform, distributed-systems, and infrastructure engineering roles.

Based in
Bangalore, India
Strongest at
Backend · Platform · Networking
Working style
Explicit trade-offs and observable failure modes
Find me
GitHub · LinkedIn
01

Design for recovery.

Retries, replay, cleanup, and restart behavior belong in the first design.

02

Make failure legible.

A system is easier to trust when its decisions and degraded states are visible.

03

Name the trade-off.

The best architecture is contextual. State what it buys and what it costs.

04

Capabilities

The toolkit follows the problem.

A focused view of the languages, platforms, and protocols I use to move from design to production.

Languages

Go · Java · Python · JavaScript · TypeScript · SQL · C

Backend & APIs

Django · Spring Boot · FastAPI · REST · WebSocket · SSE · JWT · gRPC

Streaming & Data

Kafka · Kafka Streams · CDC · Avro · Schema Registry · RabbitMQ · Spark · S3

Databases & Search

PostgreSQL · Cassandra · Redis · Elasticsearch · DynamoDB · MongoDB · Redshift · OpenSearch · RocksDB

Cloud & Platform

AWS · Kubernetes · Terraform · Terragrunt · Helm · Docker · Cilium · GitHub Actions

Networking & Security

Linux · TCP/IP · TLS · GRE · IPsec · NAT Traversal · DPDK · OPA · Rego

AI & Retrieval

AWS Bedrock · LangGraph · RAG · OpenSearch · Rasa NLU · vLLM · Hugging Face · BM25 · RRF · Reranking

Frontend & Real-Time

React · React Native · WebAssembly · WebRTC · Socket.IO · Leaflet

Observability & Quality

Datadog · OpenTelemetry · Prometheus · Grafana · EFK · Unit Testing · Integration Testing

Strongest in distributed backend systems — event-driven architectures, service authorization, and the networking layer underneath both. Recent work has pulled toward LLM application infrastructure: retrieval, agentic tool orchestration, streaming interfaces, evaluation, and grounded answer generation.

Credentials

Certified Kubernetes Administrator (CKA)

Cloud Native Computing Foundation (CNCF)

April 2026

Education

R.N.S Institute of Technology

Bachelor of Technology in Computer Science

2016 — 2020 · Bangalore, India

Away from the terminal

Basketball

Basketball is one of my favorite ways to stay active, spend time with friends, and switch off from work for a while.

Trekking

I enjoy trekking and the change of pace that comes from spending time outdoors, away from screens and everyday routines.

Video games

I enjoy video games both as entertainment and as systems to understand. That curiosity also shows up in projects such as GoNES and Pixel Souls, where playing and building games meet.