Available for backend & cloud architecture

Hello, my name is Aldo Lushkja

I am a senior backend engineer based in Milan, designing distributed event-driven systems that stay resilient as traffic, concurrency, and complexity grow.

Distributed SystemsCQRS & Event SourcingAWS Cloud ArchitectKafka & Outbox PatternProduction Ownership
Aldo Lushkja
Milan, Italy
8+ YearsDistributed Systems
99.99%SLA Reliability
Cloud NativeEvent-Driven & CQRS
Architectural Case Studies

Selected System Architectures & Projects

Engineering case studies, high-throughput backend services, IaC definitions, and technical writing.

Core Engineering Domains

Architecture & System Capabilities

Specialized domains in distributed transaction processing, resiliency engineering, and production governance.

01

Distributed Systems & Event Streams

Designing event-driven backends, command-query responsibility segregation (CQRS), outbox patterns, and idempotent event consumers.

CQRS & Event SourcingKafka & Event StreamsTransactional OutboxIdempotent ConsumersSaga Orchestration
02

System Scalability & Resiliency

Building fault-tolerant architectures with rate limiting, circuit breakers, zero-downtime migrations, and horizontal partitioning.

High-Throughput IngestionCircuit Breaker PatternModular MonolithsZero-Downtime ShardingBackpressure Management
03

Cloud Architecture & Security

Declarative infrastructure as code, multi-tenant edge gateways, mTLS zero-trust communication, and end-to-end distributed tracing.

AWS Infrastructure (CDK)mTLS & Zero-TrustBFF Edge GatewaysOpenTelemetry TracingMulti-Tenant Isolation
04

Production Ownership & Delivery

Establishing continuous delivery governance, automated release pipelines, operational SLAs, and low-latency financial transaction guarantees.

Production Incident ManagementAutomated CI/CD Pipelines99.99% Availability SLAsFintech SLA Enforcement
Architectural Design Pattern

Event-Driven Distributed Systems & CQRS Topology

How I design fault-tolerant backend services for zero data loss, idempotency, and high-throughput execution.

Production-Grade Architecture
01 · Edge & Security
API Gateway & Auth

mTLS termination, OAuth2/OIDC token verification, WAF rate-limiting, and schema validation at the edge.

02 · Distributed Core
Transactional Outbox & CQRS

Decoupled domain boundaries, command-query segregation, idempotency caches, and ACID local transactions.

03 · Event Stream
Kafka & CDC Pipeline

Asynchronous event streaming via Debezium CDC, Saga orchestration, and OpenTelemetry distributed tracing.

Architecture Sequence & Data Flow (Mermaid Diagram)
Event-Driven Distributed System Topology Diagram
View Mermaid Architecture Source
graph TD
    subgraph Edge ["1. Edge & Security Gateways"]
        Clients["Mobile & Web Clients"] -->|HTTPS / mTLS| Gateway["AWS API Gateway / WAF"]
        Gateway -->|OAuth2 / JWT| Auth["Cognito / OAuth2 Service"]
    end

    subgraph Core ["2. Distributed Microservices Core"]
        Gateway -->|REST / gRPC| OrderSvc["Subscription & Billing Engine"]
        Gateway -->|REST / gRPC| LoyaltySvc["Loyalty Engine"]
        OrderSvc -->|Idempotency Key| IdemCheck{"Idempotency Cache"}
        IdemCheck -->|Cache Miss| Outbox["Transactional Outbox (DB)"]
    end

    subgraph EventStream ["3. Asynchronous Event Pipeline"]
        Outbox -->|Debezium / CDC| Kafka["Apache Kafka Event Bus"]
        Kafka -->|Loyalty Events| LoyaltySvc
        Kafka -->|Audit Logs| Analytics["Elasticsearch / OpenSearch"]
    end

    subgraph Storage ["4. Persistence & Observability"]
        OrderSvc -->|ACID Transactions| Postgres[("PostgreSQL Cluster")]
        LoyaltySvc -->|Key-Value Ops| DynamoDB[("DynamoDB / Cache")]
        Analytics -->|OpenTelemetry| Grafana["Grafana / Datadog Tracing"]
    end
Operational Resilience Foundation
OpenTelemetry TracingZero-Downtime MigrationmTLS Zero-Trust SecuritySLA 99.99% Availability
STAR Method Track Record

Production & Career Track Record

8+ years of engineering leadership across high-stakes environments — from fintech & digital trust platforms to enterprise monolith modernization.

2025 — present1 yr

Satispay

Milan, Italy

Senior Backend Engineer & Production Owner

Architecting high-throughput subscription lifecycle and payment loyalty engines with zero data divergence.

Context & Challenge

Rapid user growth on recurring payment flows led to potential concurrency bottlenecks and state divergence risk across merchant loyalty services.

System Mandate

Re-architect subscription lifecycle handling and loyalty points calculations into a fault-tolerant, idempotent system capable of sustained peak transaction volumes.

Architectural Execution

Implemented CQRS patterns, transactional outbox messaging via Kafka, and strict idempotency key enforcement across distributed payment boundaries.

Measurable Impact

Achieved 99.99% operational availability, zero double-charging anomalies, and reduced P99 subscription checkout latency by 40%.

CQRS & Event-DrivenTransactional OutboxDistributed IdempotencyZero-Downtime Release
2021 — 20254 yrs 2 mos

Namirial SPA

Milan / Remote

Senior Software Engineer — Digital Trust Systems

Engineered mission-critical cryptographic timestamping (RFC 3161) and CRL validation pipelines.

Context & Challenge

Legacy timestamp verification engines experienced performance degradation under spike loads, risking strict EU eIDAS compliance SLAs.

System Mandate

Modernize the cryptographic pipeline, eliminate database contention, and execute seamless runtime infrastructure migrations.

Architectural Execution

Debuilt monolithic bottlenecks into async event streams, introduced zero-downtime database sharding, and optimized cryptographic signing threads.

Measurable Impact

Reduced P99 signature verification latency by 65% while handling over 10 Million daily cryptographic operations with 100% audit compliance.

Cryptographic PipelinesHigh-Volume IngestionDatabase ShardingeIDAS Compliance
2022 — 20252 yrs 10 mos

Digipax

Remote

Software Architect — Identity & Logistics

Designed multi-tenant edge authentication and Backend-for-Frontend (BFF) gateways for hybrid logistics platforms.

Context & Challenge

Enterprise logistics clients required custom deployment models across on-premise and cloud infrastructure with strict tenant isolation.

System Mandate

Deliver a unified microservices BFF architecture supporting multi-tenant OAuth2/OIDC token exchange and edge security.

Architectural Execution

Designed a modular monolith architecture with isolated domain boundaries, mTLS edge termination, and automated infrastructure as code.

Measurable Impact

Reduced new enterprise tenant onboarding time from weeks to hours and eliminated cross-tenant deployment friction.

BFF PatternMulti-Tenant IsolationModular MonolithmTLS Edge Security
2018 — 20212 yrs 8 mos

Spindox SPA

Milan, Italy

Software Engineer — Enterprise Systems

Led backend modernization for tier-1 enterprise platforms (SIAE, TIM, Intesa Sanpaolo, Fastweb).

Context & Challenge

Legacy core monoliths at high-volume telecom and banking clients caused release delays and high operational downtime risks.

System Mandate

Decompose monolithic services into resilient microservices while maintaining uninterrupted 24/7 SLA obligations.

Architectural Execution

Applied Strangler-Fig migration patterns, integrated central distributed tracing (OpenTelemetry), and standardized CI/CD deployment automation.

Measurable Impact

Accelerated release deployment velocity from monthly cycles to daily releases and reduced critical production incident rollback rates to zero.

Strangler-Fig MigrationDistributed TracingSLA EnforcementCI/CD Automation
Engineering Mindset

The Engineer Behind the Systems

Engineering matters most to me when it combines sound architectural judgment, explicit trade-off decisions, and production accountability after release.

01

Make the System Explicit

Clear service boundaries, explicit data contracts, and transparent trade-offs move engineering teams faster than complex abstractions.

02

Own the Production Outcome

Delivery is complete when observability, idempotent retries, safe deployments, and low incident MTTR are active in production.

03

Automate Infrastructure & Governance

Infrastructure as Code (IaC) and CI/CD pipelines remove operational toil while maintaining auditability and security compliance.

Family & PerspectiveFather

My daughter brings grounding, energy, and long-term purpose to every endeavour.

HouseholdPets

A lively household with two cats and a dog that keeps daily life active.

Martial ArtsKarate Practitioner

A long-term discipline centered on continuous refinement, focus, and patience under pressure.