KA Khaled Aldahish
Munich, Germany · Available full-time — December 2026

Khaled Aldahish Backend engineer building secure distributed systems.

I work where backend architecture, reliability, and product security meet — particularly in payments, fintech, and digital trading platforms.

Selected engineering work

Systems, not just titles.

A few systems and engineering problems that better explain how I work than a list of technologies can.

SYSTEM / 01

Event-driven notification platform

Independently architected and built a Kotlin/Spring Boot service that isolated notification traffic and provider failures from a core energy-trading platform.

KotlinSpring BootEventBridgeSQS FIFODynamoDBECS
Designed aroundOrdering · bounded concurrency · retries · dead-letter recovery · failure isolation
Platform eventsThe core platform emits events without becoming coupled to the downstream notification provider.
SYSTEM / 02

Multi-tenant payment transaction platform

Co-designed backend services for banks and merchants, integrating multiple payment processors and handling transaction flows across payment rails.

JavaSpring BootjPOSISO 8583RedisKafka / RabbitMQ
Designed aroundIdempotency · distributed locking · multi-tenancy · processor integration · payment-switch failover
ChannelsBank and merchant channels enter a shared platform while remaining logically separated across tenants and use cases.
SYSTEM / 03

SoftPOS security architecture

Led security architecture and PCI compliance for a SoftPOS platform, translating security requirements into application, cryptographic, mobile, network, and Kubernetes controls.

PCI MPoCPCI PINHSMDUKPTmTLSKeycloak / RBAC
Designed aroundKey lifecycle · service identity · least privilege · secrets · cryptographic boundaries · certification controls
Mobile securitySensitive mobile-side key material and payment flows were protected through controls including white-box-protected keys.
How I think

Engineering principles I keep returning to.

The recurring concerns behind my design decisions across payments, cloud services, and security-critical platforms.

01

Idempotency first

Retries are normal in distributed systems. Duplicate side effects should not be.

02

Isolate failure

External providers, queues, and downstream dependencies should fail without dragging core workflows down with them.

03

Identity over trust

Security boundaries should rely on explicit identity, scoped authorization, managed secrets, and verifiable service relationships.

04

Model the domain

Architecture is easier to keep correct when the code reflects transaction rules and real business boundaries.

Experience

A career across backend systems and security-critical products.

From payment cryptography and SoftPOS to distributed backend services for digital energy trading.

Oct 2024 — Present

enmacc · Munich

Java Backend Engineer · part-time during M.Sc.

Build and secure core-platform features in Java/Kotlin and Spring Boot, remediate application/cloud security findings, and independently delivered the event-driven notification service shown above.

Jul 2022 — Oct 2024

Fikr Jadid

Senior Java & Security Engineer · Security & Compliance Lead

Co-designed payment-platform backend architecture and led security architecture and PCI compliance for a SoftPOS platform, while remaining hands-on in production services and transaction processing.

Sep 2021 — Jul 2022

Business Solutions for Advanced Systems

Full-Stack Software Developer · HSM Engineer

Worked on the same SoftPOS product and engineering team before the transition to Fikr Jadid, with a strong focus on payment integrations and HSM-backed security work.

2017 — 2026

Computer Engineering → Informatics

GUC B.Sc. · TUM M.Sc.

Computer Engineering at the German University in Cairo, followed by an M.Sc. in Informatics at the Technical University of Munich.

Current research

Collusion mitigation in RFQ-based digital wholesale energy trading

My M.Sc. thesis at TUM studies how structurally characterized forms of collusive market manipulation can be mapped to mitigation mechanisms through the traces available to digital RFQ platforms.

DegreeM.Sc. Informatics · TUM
FocusRFQs · platform traces · market integrity
ExpectedDecember 2026
Technical stack

The tools behind the systems.

Kept compact on purpose — the case studies above show how I actually use them.

Backend

Java · Kotlin · Spring Boot · Spring Data JPA · Hibernate · Spring Security · Spring Cloud Gateway · JUnit · Mockito

Architecture

Microservices · distributed systems · event-driven architecture · REST · concurrency · fault tolerance · idempotency · multi-tenancy

Cloud & delivery

AWS ECS · SQS · EventBridge · DynamoDB · IAM · Secrets Manager · Docker · Kubernetes · OpenShift · Istio

Data & messaging

Oracle · PostgreSQL · MySQL · DynamoDB · Redis · Kafka · RabbitMQ

Security

TLS/mTLS · OAuth2/JWT · Keycloak/RBAC · HSM · DUKPT · Vault · white-box cryptography · zero-trust architecture

Payments

SoftPOS · ISO 8583 · nexo / ISO 20022 · PCI MPoC · PCI PIN · PCI DSS

Contact

Interested in backend systems that have to be correct when things go wrong?

I’m based in Munich and available for full-time opportunities from December 2026.

Email me
Email copied