Sasha Malahov

Principal Engineer · compsci.boutique

data platforms · identity & security · distributed compute · autonomous systems

WHO I AM

20+ years taking ambiguous problems to production — architecture, implementation, and operation. A decade at a Fortune 500 lighting company building self-service platform, security/identity, governed analytics, and petabyte-scale data infrastructure on AWS. My most recent work is autonomous agent systems that run the full delivery lifecycle with humans in the loop.

10K+
req/s — OIDC SSO cache under load
10+ PB
scanned under $30K compute
~900
Mbit/s — Elasticsearch indexing
150K+
lines of AI-written prod code
WHAT I BUILD

Data Platforms & Lakehouse

2022 – 2026
Apache IcebergAthenaNeptune / Brick / SPARQLDynamoDBKinesisSparkplug B

Semantic IoT lakehouse: Sparkplug B telemetry → serverless fan-out → Iceberg on S3, with a sub-10ms metadata store and a CDC-synced Brick ontology graph — SQL and SPARQL joined on one stable key, 10–60s device-to-queryable, zero warehouses. Case study →

Data contracts as a governance layer: unified Glue tables, versioned validation (JSON Schema / Avro / Protobuf), cross-account metadata search, OpenMetadata (contributor), Lake Formation row-level policy.

Identity, Security & Platform APIs

2018 – 2021
OIDC / SSOtoken delegationJava / MicronautForgeRockTerraform

Designed and implemented an OIDC SSO + token-delegation service that became the reference implementation every other team adopted; read-through DynamoDB cache scaled to 10K+ req/s in load testing, offloading AWS Cloud Directory.

Externally-consumed platform APIs: governed query/search services, authorization integrated into analytics tooling from a shared identity model — plus global delivery (Hong Kong launch, AWS-to-China replication patterns for an external cloud).

Distributed Compute at Scale

2022 – 2026
EKS / Karpenter spotFargateLambda / event-drivenDocker

A distributed compute framework — Pydantic-validated jobs, PostgreSQL work ring, DynamoDB state, ephemeral EKS workers on spot with auto-recovery — applied to malware scanning across 10+ PB under $30K.

The pattern I reach for: serverless and event-driven (Streams / Firehose) for the async data path, long-running services on Fargate where cache state and latency budgets demand it. Cost, reliability, and correctness are design constraints, not afterthoughts.

Autonomous Systems

2025 – now
agent algebraA2A / RAGcomputer-use & visionvoice pipelinesRL

An AI agent orchestrator running autonomous coding agents through the full GitHub lifecycle — issue → PR → review → merge → release — with per-agent scoring and self-healing; author of four, an agent algebra where every agent composes four functions over shared evaluation — the loop built its own toolchain →

150K+ lines of AI-written code shipped at enterprise scale — I practice what I build. Local-first LLMs (llama.cpp / vLLM), vision and screen automation, and Pipecat voice pipelines.

WHAT THIS MEANS FOR YOU

I'm a senior engineer for hire — contract or consult — who owns systems end to end: the API contract, the data contract, the identity policy, the cost envelope, and the on-call reality. Send me a hard platform problem and I'll tell you honestly whether it's a fit — and how I'd solve it.

HIRE / HIRE-OUT SEE THE ICE GRAPH CASE STUDY SEE FOUR — THE AGENT ALGEBRA ALLOC — RL PORTFOLIO ENGINE PERSONAL-INDEX — WEB SEARCH ENGINE