Skip to main content
HimalayasHimalayas logo
JS
Open to opportunities

John Suriaga

@johnsuriaga

Senior software engineer specializing in production AI, secure cloud platforms, and compliance-ready systems.

Philippines
Message

What I'm looking for

I’m looking for a team where I can build AI that stays trustworthy in production—secure LLM gateways, permission-aware RAG, and audit-ready systems on AWS/GCP—while shipping with strong DevSecOps practices and measurable reliability improvements.

I’m a senior software engineer with 10+ years of production experience across healthcare, enterprise insurance, cloud security, consumer products, and applied AI, with consistent depth in compliance—HIPAA-regulated systems, SOX-adjacent audit infrastructure, GDPR-aligned data handling, and enterprise AI governance.

I specialize in making AI reliable in production, building LLM gateways and RAG pipelines with permission-aware retrieval, rate limiting, prompt-injection defenses, PII redaction, and structured enterprise audit logging.

I build and operate cloud platforms on AWS and GCP using Kubernetes and Terraform, and I focus on secure delivery by hardening services against adversarial inputs and standardizing security reporting through SAST findings normalization.

In my most recent role, I maintained an AI Gateway and improved access control by ~30%, delivered sub-200ms p95 retrieval latency with project-level ACL enforcement, and introduced CI-gated evaluation harnesses to prevent silent quality degradation. Earlier work includes backend platforms at Canva and compliance-focused audit-log and HIPAA verification patterns at eClinicalWorks.

Experience

Work history, roles, and key accomplishments

GitLab logoGI
Current

Senior Backend Engineer

Apr 2024 - Present (2 years 2 months)

Maintained and extended an AI Gateway on Google Cloud Run, adding per-feature entitlement checks, JWT tenant isolation, and rate limiting to cut unauthorized API access by ~30% via telemetry. Built permission-aware RAG pipelines for GitLab Duo Chat with sub-200ms p95 retrieval and implemented prompt-injection detection, PII redaction, and audit logging for enterprise compliance.

Education

Degrees, certifications, and relevant coursework

Becker College logoBC

Becker College

Bachelor of Science, Applied Computer Science

2011 - 2015

Bachelor of Science in Applied Computer Science from Becker College (2011–2015), focused on building reliable systems, securing data, and measuring AI in production.

Find your dream job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan