Brian Oktavec
OPEN TO OPPORTUNITIES

I build secure platforms, automation, and AI-powered systems that hold up in production.

I started in DevOps, automating VM provisioning and Kubernetes checks — work that teaches you fast that most outages are a process problem before they're a technical one.

Full-stack engineering, platform automation, and security-minded systems design, with hands-on experience building RAG and agent tooling. Open to senior software, platform, and security engineering roles.

ingest → normalize → detect → respond
locationCanton, GA · remote
focusplatform · security · AI
stackPython · TypeScript · AWS
statusopen to opportunities
01

Featured work

All projects →

Atlas

AI / LLMPERSONAL
self-hosted RAG knowledge assistant

A privacy-focused Retrieval-Augmented Generation platform that turns private documents and notes into a searchable AI assistant. An ingestion pipeline extracts and normalizes metadata, chunks content, generates embeddings, and stores them in Qdrant; queries are matched via semantic search and answered by a locally hosted LLM, with intelligent routing to external sources when more context is needed.

n8nQdrantVector EmbeddingsLocal LLMsDocker
Case study →
Pipeline
ingest documents
chunk + embed
store in Qdrant
semantic search
generate answer

Inspectra

PLATFORMWORK
full-stack inspections/compliance SaaS

A customer portal, staff back office, and offline-capable inspector PWA on an AWS/Kubernetes backend. Built a shared JWT/OIDC auth package with RBAC, a Puppeteer + React PDF reporting framework, and an offline-first PWA with service worker sync and conflict resolution.

AWSKubernetesPostgreSQLTerraformNext.js
Case study →

Keyveil

SECURITYPERSONAL
local-first secrets management for developers & AI agents

A macOS secrets management ecosystem built around Apple Keychain: a native app, a CLI, an MCP bridge that lets AI agents reference secrets without seeing raw values, and a Raycast extension — designed around least-privilege, local-first access.

SwiftApple KeychainMCPRaycastCLI
Case study →
Selected impact, 2024 – 2026
$8.3M$3.5M
annual operating cost, after consolidating tooling and automating delivery
5728
team size required to run the same platform, with higher output
2.22×
application scanning and remediation throughput
02

Experience

Full history →
Jul 2026 — Aug 2026
Threat Research Engineer· Sublime Security
Refactored legacy routing patterns and migrated services from regex-based routing to Hono, improving maintainability and consistency across internal web applications.
Used AI-assisted development extensively with Claude to accelerate refactoring, including custom repository-specific AI guidance and conventions.
TypeScript · Hono · Claude
Aug 2024 — Jul 2026
Lead Cybersecurity Engineer· AT&T
Technical lead and primary platform owner for a Sensitive Data Discovery platform spanning onboarding, scanning, validation, remediation, reporting, and compliance across thousands of enterprise applications.
Helped cut annual operating cost from $8.3M to $3.5M and team size from 57 to 28, while increasing scanned/remediated applications 2.22×.
Lead developer for a full-stack SPA (React/TypeScript + Fastify), owning Azure integration with Service Bus, Redis Cache, and secrets management.
Python · React · TypeScript · Fastify · Azure · Kubernetes
Jul 2022 — Aug 2024
Software Engineer II· Endava
Built full-stack web applications and SDK integrations for Financial Services and IT Consulting clients using React, TypeScript, Node.js, AWS, and PostgreSQL.
Led backend development for a prototype merchant application integrating a corporate client's SDK; built automated test coverage to ~90% with Mocha and Chai.
React · TypeScript · Node.js · PostgreSQL · AWS
Jan 2022 — Jul 2022
Software Developer· Techquidation Inc.
Led development of a label-printing SaaS using Python, SQL, NiceLabel, and VBScript, reducing processing time by 90%.
Troubleshot and improved Next.js application functionality while contributing to feature planning and technical documentation across client-facing projects.
Python · SQL · NiceLabel · Next.js
Aug 2019 — May 2021
DevOps Co-op· Georgia Tech Research Institute
Automated application provisioning with Ansible, reducing deployment time from VM creation to a fully functioning application by 80%.
Maintained and troubleshot virtual machines and Kubernetes clusters supporting application availability and reliability.
Built Ansible and Bash automation for Kubernetes cluster validation and remediation, reducing validation from hours to minutes.
Ansible · Bash · Kubernetes · Linux
03

Currently building

Keyveilnative app, CLI, and MCP bridge
MailForgeAI-powered email classification, self-hosted
DevIndexthis site, and the AI assistant on it
04

About

I started in DevOps, automating VM provisioning and Kubernetes checks — work that teaches you fast that most outages are a process problem before they're a technical one. That's shaped how I build ever since: automate what repeats, and design for the person who has to run it at 2am.

These days that's platform engineering, security tooling people actually use, and treating AI systems as components with a contract — not a magic layer bolted on top.

Read the full story →
Ask AI

Interview my portfolio instead of reading it.

Answers are grounded in my projects, roles, and writing, and every claim links back to the page it came from.

Start a conversation
What projects best demonstrate AI experience?
Atlas is the clearest one — a self-hosted RAG platform with automated ingestion, embeddings, and semantic search over private documents. MailForge also uses a locally hosted LLM to classify and route email.
01 · Atlas02 · MailForge
What backend systems has Brian built?What security automation experience does he have?
OPEN TO OPPORTUNITIES

Hiring for platform, security, or AI systems work?

Happy to talk through the work in detail. Email is fastest.