Who is on the other end
# the short version, without the recruiter vocabulary
I build and keep alive the unglamorous middle of software: the API that has to answer in 200 ms, the stored procedure that has been slow since 2019, the deployment that must not drop a session at 2 a.m. Most of my work sits with one long-running client — a multi-site vision-care group — where I am the person who takes a request from “the schedule is wrong” to a shipped fix.
Front end, I am an Angular specialist in the practical sense: I have moved real applications from v2 through v20, one deprecation at a time, without a rewrite. Back end, it is .NET and C# — Web APIs, background schedulers, integration jobs. Underneath, SQL Server: T-SQL, linked servers, query plans, sync jobs that used to take minutes.
The part people do not expect from a full-stack engineer is the platform: IIS and Windows Server configuration, reverse proxies, CodeQL and Dependabot pipelines, secrets pulled out of config files and into a vault. I would rather own a system end to end than hand a ticket across a wall.
- Experience
- 12+ years
- Base
- India
- Employer
- Technovate.One
- Angular since
- v2
- Primary stack
- .NET · Angular
- Also
- SQL · IIS · DevOps
- Remote
- Yes, EU/US overlap
- Status
- Open to work
Stack, by how much I actually use it
$ stack --sort=depth # bars are years in production, not self-assessed percentages
Front end
- Angular v2–v20
- TypeScript
- RxJS
- Standalone APIs
- Angular Material
- SCSS
- Reactive forms
Back end
- .NET / C#
- ASP.NET Core
- Web API
- Entity Framework
- Background services
- Node.js
- Python
Data
- SQL Server
- T-SQL
- Stored procedures
- Query tuning
- Linked servers
- Redis
- StarRocks
Platform
- IIS
- Windows Server
- ARR reverse proxy
- App pools
- Git
- GitHub Actions
- Jenkins
- Docker
Security
- CodeQL
- Dependabot
- Secret scanning
- OWASP remediation
- JWT / OAuth
- HMAC signing
- Keeper Vault
AI tooling
- Claude
- MCP servers
- FastMCP
- LLM workflow automation
- Prompt-driven reporting
Where the years went
$ git log --author=uttam --reverse=false
-
2016 – Present
Senior Full-Stack Engineer
Technovate.One — primary engagement: a multi-site vision-care group
Own an Angular 19 scheduling platform end to end, from provider availability rules to the SQL Server procedures behind them. Alongside it: the production IIS estate, the GitHub security posture (CodeQL, Dependabot, secret scanning), a secrets migration into Keeper Vault, and an internal MCP server that puts operational KPIs in front of an LLM.
-
2015 – 2016
Software Engineer
Viva Softwares
Mobile apps, the web APIs behind them, and .NET desktop applications — the year I moved from mobile-only work into full-stack .NET.
-
2014 – 2015
Software Engineer
Proto+ E Solutions
Started out building Android apps and the web APIs that powered them — first production mobile software I shipped.
Six things I built that are still running
$ ls -la projects/ # client names withheld where the contract says so
drwxr-xr-xoptischedule/Angular 19 · .NET · SQL
An enterprise scheduling platform for a multi-site vision-care group: provider calendars, operational blocks, holiday rules, and the appointment sync that keeps clinic systems agreeing with each other.
- Angular 19 front end on a shared component library, incrementally migrated to standalone components.
- Scheduling logic in .NET with stored-procedure-backed reads (
GetDataFromSppatterns) for the heavy queries. - Appointment sync across two databases via linked server, rewritten from row-by-row to set-based.
drwxr-xr-xkpi-mcp-server/Python · FastMCP · StarRocks
A Model Context Protocol server that exposes operational KPIs as callable tools, so an assistant can answer “how did last week look” against the warehouse instead of a spreadsheet export.
- Built on FastMCP, querying StarRocks with parameterised, read-only tool definitions.
- Deployed and tested against a hosted Claude integration end to end.
drwxr-xr-xsecurity-posture/CodeQL · Dependabot · .NET
Took a large .NET API estate from “no scanning” to a working security pipeline, then worked the backlog it produced.
- Custom CodeQL workflow plus Dependabot and secret scanning across the org's repositories.
- Remediated LDAP injection with a filter-encoding helper, retired SWEET32-era ciphers, tightened service-account permissions, and fixed a JWT validation gap.
- A bot reconciles scanning results into a risk register, so the report is generated rather than assembled by hand.
drwxr-xr-xsecrets-migration/.NET · Keeper Vault
Pulled connection strings and API keys out of configuration files and behind a vault-backed configuration provider, without a flag day.
- Custom
IConfigurationsource resolving secrets from Keeper Vault at startup, with local-development fallback. - Moved scheduled jobs onto a dedicated service account with least-privilege grants.
drwxr-xr-xangular-upgrade/Angular 12 → 20
A seller portal eight major versions behind, upgraded in place while the team kept shipping features.
- Dependency and API audit first, then one major version per merge with a green build at every step.
- Retired deprecated modules and rebuilt the build pipeline on the modern application builder.
drwxr-xr-xsigned-extension-auth/Firefox · HMAC-SHA256
A browser extension talking to an internal API needed a way to prove it was itself, on a platform that reissues extension identifiers.
- Stabilised the install identifier so a reinstall does not orphan the device record.
- Request signing with HMAC-SHA256 over method, path, body hash and timestamp, with replay rejection server-side.
What you can hand me
$ services --list
Angular modernization
Legacy Angular brought current one version at a time — no rewrite, no feature freeze, a green build at every step.
.NET API engineering
ASP.NET Core services, integration jobs and background schedulers built to be operated, not just deployed.
SQL Server performance
Slow procedures profiled and rewritten, sync jobs made set-based, indexes chosen from plans rather than guesses.
Deployment & IIS
Windows Server and IIS configured properly: app pools, reverse proxy, certificates, health checks, repeatable releases.
Vulnerability remediation
Scanning turned on, findings triaged, and the actual fixes shipped — injection, weak ciphers, over-permissioned accounts, exposed secrets.
MCP & LLM integration
Your own data made callable by an assistant through purpose-built MCP tools, with read-only boundaries you can audit.
Tell me what is broken
$ mail -s "project" me@jagruttam.com
A paragraph is enough: what the system is, what it is doing wrong, and when you need it right. If it is not something I should take on, I will say so and point you somewhere better.
> Currently taking on one or two engagements at a time — Angular modernization, .NET API work, or a security backlog that needs clearing.