14+ years building and running software systems, and 10+ years in technical leadership roles across mobile, frontend, backend and platform. I own technical strategy and architecture while staying hands-on enough to challenge designs, lead architecture and code reviews, and resolve production issues myself.
My work spans high-concurrency consumer platforms, media delivery infrastructure, transactional and financial systems, and enterprise ERP — built on distributed services, event-driven architecture, relational data, caching and cloud infrastructure across AWS and GCP.
Also open to CTO conversations at earlier-stage companies, where the role is engineering leadership and technology strategy in the same seat.
Production code, architecture reviews and code reviews. I stay technical enough to challenge a design and debug a live incident, not just approve a plan.
Distributed services, event-driven workflows, relational data, caching and cloud infrastructure — designed around where failure is actually expensive.
Team structure and ownership boundaries, hiring and onboarding, mentoring, delivery practice, engineering standards and release governance.
Build versus buy, technical roadmap, infrastructure cost, reliability and security trade-offs, and delivery forecasts that executives can plan against.
The systems behind the products — scale, constraints and the decisions they forced.
Traffic was never evenly distributed — the majority of votes arrived inside live-broadcast windows, so the platform had to be designed for burst absorption rather than average throughput. Synchronous accept-and-acknowledge on the write path, asynchronous tallying over Kafka, duplicate-vote prevention in Redis.
End-to-end architecture across mobile clients, backend microservices, media ingestion and transcoding, multi-bitrate packaging, CDN delivery, and DRM playback gated by short-lived authorisation tokens. The real constraint: deliver protected video across devices while controlling egress cost and preventing unauthorised extraction of licensed content.
Built on a double-entry ledger whose entries and admin logs are insert-only, enforced at the database level with row-level security — an application bug cannot rewrite history. Integer-VND monetary arithmetic, transactional multi-step mutations, idempotent write endpoints and role-scoped access control across contribution, penalty and disbursement lifecycles.
Budgeting, procure-to-pay, contract management, accounting, HRM and helpdesk. Camunda-driven approval workflows enforce segregation of duties and multi-level authorisation, while entity-scoped access control keeps company data isolated and still supports group-level consolidated reporting.
Search and booking workflow with third-party airline and GDS integration. The engineering problem is consistency: keeping bookings and transactions correct against external providers that are slow, flaky, or occasionally wrong.
Products I design, build and release end-to-end as sole developer — using the same AI-assisted practice I introduced to my team.
Smart app for managing class schedules and student members. Attendance tracking, statistics, export, and cloud sync.
Drawing & coloring app for kids ages 3-11. Step-by-step lessons, coloring pages, free-draw canvas, and AI on device.
Scan rooms for hidden cameras and spy devices using phone sensors. AI-powered detection, offline-first, privacy-first.
AI-powered nutrition tracker. Snap a photo for instant calorie & macro estimates, AI coaching, and progress charts.
Digital ROSCA platform. Manage hui groups, auto payment reminders, transparent transactions for organizers & members.
The principles I actually run teams by — and where each one came from.
Not everything needs microservices. I put complexity where failure is expensive and keep everything else boring and simple. The question is never "what's modern" but "what breaks, and what does it cost when it does".
In practice: HuiHappy runs as a monolith with strict service boundaries — a small team and a domain still taking shape did not need distributed-system failure modes on day one.Money is integers, never floats. Ledgers are append-only. Multi-step mutations are transactional. Audit trails are immutable by construction rather than by convention, because conventions are what break under deadline pressure.
In practice: HuiHappy's ledger and admin logs are insert-only, enforced with row-level security at the database — an application bug cannot rewrite history.Observability, alerting, backup and incident response are planned engineering work, not after-hours heroics. If reliability is not on the roadmap, it is being paid for in on-call burnout instead.
In practice: capacity planning ahead of live-broadcast peaks, so a voting platform absorbs bursts instead of rejecting users at the moment they matter most.Every service, pipeline and repository has one named owner. Shared ownership is no ownership — it is the state where everyone assumes someone else is watching the dashboard.
In practice: defined team structure and ownership boundaries across 3 concurrent product streams and up to 20 engineers.Lead time, deployment frequency, change failure rate, MTTR, escaped defects. Coverage is a proxy, not a goal — what matters is whether defects reach users, and how fast the team recovers when they do.
In practice: test coverage moved from under 10% to ~70%, and typical review turnaround from about a working day to ~30 minutes.I run AI adoption as controlled experiments with explicit boundaries — what it may touch, what it must never touch, and how quality, security and cost get measured. Human review stays mandatory: the tool changes how fast a reviewer reaches a decision, not whether one is made.
In practice: introduced across the team with measured outcomes, and used end-to-end on a product I shipped to the App Store alone.Team building & hiring · Mentoring & career development · Architecture and code review · Delivery governance · Vendor & external partner management · Engineering standards
Distributed systems · Microservices · Event-driven architecture · API design · Relational data modelling · Caching · Async processing · High-concurrency design
Observability · Incident response & root-cause analysis · Capacity & performance · Backup and recovery · Release control · CI/CD · Infrastructure as code
Secure SDLC · Identity & access control (RBAC, JWT/RS256) · Least privilege · Segregation of duties · Encryption & secrets management · Immutable audit trails · Transactional consistency · DRM & token-authorised access
Technical roadmap · Build versus buy · Infrastructure cost & unit economics · Risk management · Delivery forecasting · Executive and cross-functional stakeholder communication
Open to Head of Engineering, Engineering Director, Engineering Manager and Technical Lead roles — and to consulting on architecture, delivery and engineering organisation. Based in Da Nang, Vietnam, working with teams and stakeholders worldwide.