Gautam
Cloud & Backend Engineer, security-first.
I design and run the backend and infrastructure behind production systems. My path ran backwards through the stack — networking first, then security, then Linux, then the application layer — which means I tend to see a system as servers, permissions and traffic before I see it as code.
I came to software from the network side.
I started with CCNA and networking fundamentals, moved into security through CEH and web application penetration testing, and then into Linux administration — which is where the theory stopped being theory. Securing and administering other people's systems is what made me want to build my own.
Today I'm Co-Founder and Technical Architect at MartialXPro, where I'm responsible for the backend, the database and the Ubuntu server the whole thing runs on. The platform is a 150+ endpoint REST API over a relational Postgres model, with three-role access control, deployed behind Nginx and PM2 on infrastructure I set up and maintain.
The security background shows up in the way I build. Role-based access control, least-privilege permissions and hardened server configuration aren't features I add at the end — they're the shape of the system from the first migration.
Build it, then break it
Almost everything here was learned by implementing it — provisioning the VPC, running the migration, fixing the reverse proxy at 1am — rather than by reading about it.
Bottom of the stack first
Networking, then security, then Linux, then the application. When something fails in production, that order is usually how I find it.
Own the whole path
Schema to endpoint to server to DNS. I'd rather understand the full route a request takes than be fast in one layer of it.
Seven steps, in the order they happened.
Each stage was a prerequisite for the next one, not a detour. This is the actual sequence.
Networking foundations
Started at the wire, not the framework. TCP/IP, routing and switching, DNS, HTTP/HTTPS and VPNs — how packets actually get from one machine to another.
TCP/IPRouting & SwitchingDNSVPNCCNA certification
Formalised the networking work with CCNA training and certification through Indian Cyber Security Solutions.
CCNACyber security
Moved into offensive and defensive security through CEH and Web Application Penetration Testing — vulnerability assessment, network security, and how authentication and authorisation get broken.
CEHWAPTVulnerability AssessmentLinux administration
Learned the operating system that everything else would end up running on. Services, permissions, logs, SSH.
UbuntuSSHPermissionsServicesBackend development
Started building the systems I had been securing. Node.js and Express, REST API design, relational schema design in PostgreSQL with Prisma.
Node.jsExpress.jsPostgreSQLPrismaAWS cloud, hands-on
Worked through IAM, EC2, custom VPCs, S3 and the observability stack in real accounts rather than slides — including breaking things and fixing them.
IAMEC2VPCS3CloudWatchShipped MartialXPro
Took a platform from empty schema to live production on an Ubuntu server behind Nginx, and have been running it since.
ProductionNginxPM2Deployment
Systems I've built, deployed and had to fix.
Each of these has a write-up covering the architecture, the decisions and what actually went wrong.
MartialXPro
martialxpro.comA tournament management platform for martial arts organisations — registration, category management, fixture generation, certificates and analytics. I'm responsible for the backend, the database and the server it runs on.
- 150+ REST API endpoints
- Three-role RBAC: admin, organiser, player
- Automated fixture generation
- Deployed and maintained on Ubuntu + Nginx + PM2
AWS Cloud Practical Labs
Built and broke real AWS infrastructure in a live account — identity, compute, storage, custom networking and the governance layer. Every service here was configured by hand, not watched in a video.
- Custom VPC with subnets, IGW and route tables
- IAM users, groups and policy-based permissions
- S3 bucket policies and versioning
- CloudTrail + CloudWatch + SNS alerting path
Linux in Production
The server side of shipping software: administering the Ubuntu host that serves a live application, and hardening it afterwards. Reverse proxy, process supervision, permissions, environment config and a security baseline.
- Nginx reverse proxy in front of a Node.js service
- PM2 process supervision with restart on boot
- Least-privilege permissions and SSH hardening
- Environment-variable driven config, no secrets in the repo
What I work with.
Grouped by layer. Anything I'm still learning is marked as such — no padding.
Cloud
12Backend
07Database
05Linux & DevOps
08Networking
06Security
06Certifications
- CEHEthical Hacking (CEH)Indian Cyber Security Solutions
- CCNANetworking (CCNA)Indian Cyber Security Solutions
- WAPTWeb Application Penetration TestingIndian Cyber Security Solutions
- AWSAWS Cloud PractitionerSelf-study, hands-on labs · in progress
Currently learning
Deepening the infrastructure side — containerisation, infrastructure as code and orchestration on top of the Linux and AWS work already in production.
Where I've worked.
Co-Founder & Technical Architect
MartialXPro
2026 — Present
Bathinda, Punjab
- Lead backend development for a tournament management platform serving organisers, admins and athletes.
- Led the build of a REST API spanning 150+ endpoints on Node.js, Express.js, Prisma ORM and PostgreSQL.
- Administer the Ubuntu production servers — Nginx, PM2 and SSH.
- Defined the multi-role authentication and role-based access control model across admin, organiser and player roles.
- Designed the relational schema and manage migrations through Prisma.
- Planned and provisioned AWS infrastructure for scale-out — EC2, VPC, IAM and S3.
Finance Intern
IDFC Bank
2023 — 2024 · 6 months
Bathinda, Punjab
- Supported internal audit and compliance reviews across accounts and records.
- Handled secure processing of financial records under the bank's data-handling policy.
- Prepared documentation and internal reports used by the compliance team.
Education
Bachelor of Arts
D.A.V. College, Bathinda
2020 — 2022
Open to backend, cloud and infrastructure work.
If you're building something that has to stay up, I'd like to hear about it. Fastest way to reach me is email.