Curriculum Vitae

Tomáš Štěstí

Senior Software Developer  /  Java · Kotlin · TypeScript · Cloud

A senior developer who has been building software since 2015 — starting as a verification engineer in telecom, writing his first professional Java in Unicorn's Java Hatchery trainee program. Since then he has shipped production software across industries: a crypto exchange and the CZKC Czech stablecoin, global logistics at DHL, scanless retail in Germany, RCS messaging for Vodafone UK, and a booking platform for Der Touristik. He is usually the one handed the integration nobody wants — blockchain, payment rails, real-time tracking.

Along the way he has worn several other hats — besides back-end development he has worked as a DevOps Engineer, Scrum Master, Java competence lead, and PO / PM on projects built on the Tabidoo low-code / no-code platform.

Today he works as a full-stack developer with an architect's reach. He develops and modernizes a fintech / crypto platform — moving a long-running core into current technology piece by piece, without stopping production. Alongside that he builds and runs his own SaaS product end to end, from architecture to production, including infrastructure as code on AWS and an LLM-backed AI service.

At a glance

11
Years shipping · since 2015
9
Client engagements
3
Countries delivered in
4
Own products

Skills

Languages & platforms

Java 17 Kotlin 2.0 TypeScript Python 3.14 JavaScript SQL Bash

Backend

Spring Boot 3 Spring Security / OAuth2 JPA + Hibernate 6 Apache Kafka RabbitMQ JMS / MDB Apache Camel WebFlux (Reactor) gRPC + Protobuf FastAPI Ktor MapStruct OpenAPI (Swagger)

Cryptography & security

OpenPGP (BouncyCastle / PGPainless) OAuth2 / JWT Jasypt RLS & multi-tenancy PCI DSS scoping GDPR

Frontend

React 18 / 19 Next.js 16 Vite TanStack Query v5 React Hook Form + Zod Tailwind CSS v4 shadcn/ui (Radix) i18next Angular Vue HTML5 / CSS3

Mobile

Kotlin Multiplatform Compose Multiplatform (Android / iOS / Wasm) Android (Kotlin)

Cloud

AWS: EC2 · VPC · ECR IAM + OIDC · KMS Secrets Manager · SSM CloudTrail · CloudWatch Amplify · Lambda · SES · DynamoDB GCP Azure Cloudflare: Workers · Pages · D1 Supabase

DevOps / IaC

Terraform Ansible Docker & Compose Kubernetes OpenShift Jenkins GitHub Actions GitLab CI CircleCI Maven Gradle nginx Caddy Git

Data

PostgreSQL pgvector Redis MinIO Cloudflare D1 Cassandra Databricks

AI / LLM

LangChain (provider-agnostic) Anthropic Claude API Embeddings & RAG Qwen2.5-VL (Ollama / vLLM) MRZ / OCR pipeline AI-assisted SDLC

Observability & quality

ELK / Kibana SonarQube Uptime Kuma JUnit Vitest Playwright pytest Pyright Ruff

Legacy-system modernization

Java 8 Spring 5 Hibernate 5 WildFly React 16 Webpack 3
Java 17 Spring Boot 3 Hibernate 6 Kotlin 2 React 18 Vite

Working with production systems built on versions that are no longer supported. The job is not to extend those technologies, but to keep the system running while moving it into the current stack piece by piece: carving functionality out into new services, running the old and new interfaces side by side, migrating live with no downtime.

In other words: gradual replacement, not a big-bang rewrite.

Domains & practices

Microservices Domain-Driven Design Event-driven architecture ADRs Append-only ledger Double-entry bookkeeping Bitcoin Core RPC · Ethereum AML / KYT Travel Rule (VASP↔VASP) KYC ISO 20022

Languages

Czech — native English — advanced

Experience

03/2023
— nowPrague / hybrid
Inventi Development s.r.o.
Senior software developer
wBTCb — BIT Plus (crypto exchange), CZKC (Czech stablecoin)
Kotlin 2.0 · Java 17 · Spring Boot 3 · Hibernate 6 · PostgreSQL · React 18 · TypeScript · Vite · shadcn/ui · TanStack Query · Docker · Maven / Gradle
  • Development and gradual modernization of a multi-module banking platform (Java / Kotlin) and its React front end — from the ledger core to the admin console. The work is keeping production running while carving functionality out into newly written services.
  • A new admin application built on Spring Boot 3 + Kotlin 2.0 + Java 17 and React 18 / Vite: migrating functionality off the older console step by step. Designed and implemented the whole stack, including the backend API contract.
  • Regulatory work: AML / KYT, Travel Rule (VASP↔VASP) and KYC — from design to production, including audit traceability and reporting for the Czech National Bank.
  • Treasury and exchange operations: tooling for balance management, account statements, and internal book entries.
  • Data protection: encrypting personal data with OpenPGP (BouncyCastle / PGPainless) — an app-side implementation that allows migrating from database-level encryption into the application layer.
  • Third-party API integrations: Tatum (detecting Ethereum transactions on chain), Alchemy (validating them), ThePay and ComGate (CZK / EUR gateways), CitFin and FIO (bank statement ingestion in ISO 20022), BankID, Bitcoin Core RPC.
  • CZKC (Czech stablecoin): services around buying and selling the ERC-20 token (Spring Boot, OAuth2 resource server).
  • Prototypes and internal tooling: a mobile client in Compose Multiplatform (Android / iOS / Wasm from one codebase), and a local OCR / MRZ service for reading ID documents with an auto-accept / manual-review gate (Python, Docker, local vision model — no cloud calls).
  • Real-time production incident response and hot-fix deployment; coordinating versioning and DEV / TEST / PROD releases with the front-end team.
CK Fischer (Der Touristik)
Angular · Vue · Java · Spring · SQL · Docker · Jenkins · Gradle
  • Front-end and back-end development on the booking platform used by travel agencies.
2023Prague / hybrid
IBM
Software developer · part-time
Java · Maven
2022
— 2023Germany
GK Software SE
Software developer — GK GO (scanless shopping store)
The project started while at Neon IT and continued after the move to Inventi; it led on to the CK Fischer engagement.
Java 8 / 11 · Spring Boot · Apache Kafka · Tomcat · JPA · SQL · MapStruct · Maven · OpenAPI (Swagger) · Jenkins · Kibana · SonarQube
  • Designed and built microservices for the cloud backend that processes the customer journey end to end — from shop check-in through to checkout and payment.
01/2020
— 02/2023In parallel with the DHL Global Forwarding engagement.
Neon IT s.r.o.
Java competence lead · Software developer · Product owner
NeonApp, internal processes (screening, training, digitization)
Java 11 · Spring Boot · Apache Kafka · JPA (Hibernate) · SQL · Maven · Docker · Kubernetes · GCP · Azure · ELK · Jenkins · JUnit · WebFlux · React · HTML5 / CSS3
  • Led the Java competence and ran hiring interviews.
  • Trained and onboarded junior developers, prepared them for projects, and supported internal knowledge sharing and talks.
  • Tabidoo low-code / no-code platform — internal development: analysed internal processes and data flows; designed solutions, prioritized the backlog and ran delivery of individual modules and their integrations (HR, inventory, tasks, finance). TLDR: from filing cabinets to monitors…
  • Tabidoo low-code / no-code platform — client work: digitized company processes and data; gathered requirements from customers and formalized them into a backlog; prioritized tasks, allocated developer time and verified the output; presented solutions to stakeholders and collected feedback.
01/2020
— 12/2021In parallel with Neon IT s.r.o.
DHL Global Forwarding
DevOps engineer — GAPI / ERC (Edge Response Cache)
Java 11 · Spring Boot · WebFlux (Reactor) · Apache Kafka · Apache Camel · Maven · SQL · Docker · Kubernetes · OpenShift · Google Cloud · ELK stack · Jenkins · SonarQube
  • Designed, built, deployed and ran reactive microservices running in the cloud.
  • Processed and served real-time package-tracking data aggregated from many DHL backend systems under one unified API.
10/2018
— 12/2019Madrid, Spain
Hewlett Packard Enterprise
Java EE developer — Message+ (RCS as a sub-delivery for Vodafone UK)
Java 8 · Spring · SQL · Hibernate · Maven · ELK · gRPC · Protobuf 3 · Jenkins · Tarantella
  • Designed, built, tested, deployed and supported new microservices for an asynchronous multimedia-messaging platform.
  • Supported the RCS standard implementation in Message+.
2018Prague
T-Mobile
Java developer
Java
2015
— 2017Brno
Mavenir · acision · Unicorn
Verification engineer and internships
Java · telecom
  • Where it started: software verification engineering at Mavenir (formerly Comverse / Xura) and telecom internships in Brno.
  • Wrote his first professional Java in Unicorn's Java Hatchery trainee program.

Own products & projects

Alongside client work he builds and runs his own products, in a role that amounts to CTO of a small product team — architecture, implementation, infrastructure, security and operations in one person. Product names are deliberately omitted; what matters is the domain and the technical solution.

SaaS platform for facility management and cleaning services

2025 — now
Architect and lead developer — end to end, from design to production with real customers
React 18 / 19 · Next.js 16 · Vite · TypeScript · Tailwind v4 · Supabase (PostgreSQL, Auth, Storage, Realtime, Edge Functions, RLS) · Python 3.14 + FastAPI + LangChain · AWS (EC2, ECR, VPC, KMS, Amplify, Secrets Manager, CloudTrail) · Terraform · Ansible · Docker · GitHub Actions · Uptime Kuma
  • Domain: planning and supervising cleaning work — an admin SPA for the FM company, a QR flow for staff on site, a separate portal for the end client, real-time monitoring, alerting, shift management and workforce management.
  • Multi-tenancy and security: ownership of the database schema, RLS policies, separate least-privilege DB roles, tenant ID always taken from the verified JWT (never from LLM output).
  • AI backend for natural-language analytics: FastAPI + WebSocket, provider-agnostic LLM via LangChain, rate limiting on an append-only usage ledger, read-only DB role with RLS enforced.
  • Infrastructure as code: Terraform and Ansible, CI/CD via GitHub Actions, monitoring run from a different AWS region than the services it watches.
  • Localization into 4–6 languages, plus integration of an external attendance API as a standalone microservice.

Search across Czech legislation and court decisions

PoC, 2026
Designed and implemented the whole solution
FastAPI · PostgreSQL + pgvector · Anthropic Claude API · Terraform (local Docker) · nginx
  • Domain: legal search for non-lawyers — the user describes their case in plain language and gets back the relevant in-force laws and the rulings that touched them.
  • Solution: ingest of legislation and decisions from public sources with a change-capture manifest, linked by citation, retrieval over full-text search with a layer ready for semantic embeddings, and LLM synthesis of the answer.

Serverless web platform and micro-apps

2026 — now
Design, implementation and operations
Cloudflare Pages + Workers + Pages Functions + D1 · Terraform · GitHub Actions · Wrangler
  • Domain: a set of independently deployed micro-apps (quizzes, games, tools) sharing one domain.
  • Solution: the domain is split between a Pages project and several Workers owning their own routes — each app is developed and deployed in isolation. Terraform provisions the infrastructure; CI ships content and idempotent D1 migrations.

E-commerce for a digital product

2026
Design, implementation and operations
Cloudflare Pages + Pages Functions + D1 · Python (PDF generation) · Wrangler
  • Domain: selling a digital product to end customers — sales page, qualifying quiz, and a lead magnet in exchange for an email address.
  • Solution: a serverless backend on D1 acting as a small in-house CRM (contacts, quiz results, feedback, events), product typesetting to PDF from Markdown sources, and a custom design system.

Education & courses

Brno University of Technology (VUT)

2012 — 2016  ·  Information Technology

Robot Dreams — Cloud Application & Data Architecture

2026

A cloud-architect course on designing complex cloud solutions. Topics covered: VM to serverless, container orchestration (Kubernetes, Helm, Kustomize), blue-green and canary deployment, API gateways, hub-and-spoke enterprise networking, design patterns (orchestration vs. choreography), observability, storage types and performance trade-offs, redundancy and consistency (Cassandra), distributed data processing and lakehouse (Databricks), machine learning, Infrastructure as Code and SRE, chaos engineering and SLOs, CI/CD and DevSecOps with GitOps (ArgoCD).

Final thesis: the architecture of a cloud-native transaction system.