What I do
My focus is the backend and the security layer around it: REST APIs, OAuth2 and OIDC, secrets and token handling, containerised deployment. I have spent the last years on federated systems – independent sites that exchange sensitive data and need every approval to be traceable afterwards.
I work terminal-first with a screen reader, which makes me precise about the things that are easy to skip: readable architecture documentation, reproducible builds, and interfaces that survive without a mouse.
Selected work
-
ITCC Federated Data Hub
International integration of paediatric cancer data across clinical sites. I was technical lead and designed and documented the federated architecture: FHIR and genetic data ingestion, pseudonymised central storage, Kubernetes deployment.
Rust · Axum, Tokio, aws-sdk-s3 · Apache Iceberg, S3, Kubernetes
-
Accessible Job Manager
My own project, and the one I would show first. A job application manager for blind users, where screen reader operation is the premise the architecture is built on rather than a layer added afterwards. A posting is imported from a link and extracted into structured fields by a local language model. The cover letter is written as text and comes out as a DIN 5008-compliant PDF: the page geometry is a server-side guarantee, so nobody has to arrange an address block by hand.
The part I find most interesting is the role model. Advisors and reviewers can support an applicant – suggest openings, read a letter before it goes out – but every document access is granted by the user and can be revoked again. MIT licensed and built to be self-hosted, so vocational rehabilitation providers can run their own instance.
Java, Spring Boot · Spring Security OAuth2, JPA · Angular · docx4j, Gotenberg · PostgreSQL, Garage (S3), Authentik · Docker, Azure Container Apps
-
secret-sync
Authentication component for the Bridgehead deployment. I contributed the OAuth automation and server-side token rotation: application and user enrolment against Authentik and Keycloak through their APIs, so component access is provisioned without manual secret handling.
Rust · Axum, Tokio, reqwest · Authentik, Keycloak, OAuth2
-
Samply Exporter – authentication layer
Secured an existing Java service that exports FHIR data into several formats. I implemented multiple Spring Security filter chains side by side – JWT resource server, browser login and API key – plus group-based authorization via OIDC claims.
Java · Spring Boot, Spring Security 6, OAuth2/OIDC
-
Workspace booking system
A reinterpretation of the classic meeting room booking system as a web service: booking, administration, and OAuth login. Built end to end by me as a way to work through an ORM-heavy domain in Rust.
Rust · Loco, SeaORM · Angular, OAuth2
-
Architecture diagrams with a screen reader
Diagrams are usually the least accessible artefact in a project. PlantUML is text, so it is the exception – a collection of ERDs, class diagrams, process flows and network views I write and read without ever seeing them rendered.
PlantUML · NeoVim, terminal workflow
Technical profile
- Rust – production, around two years Axum, Tokio, SeaORM, Loco, Tauri
- Java and Spring Boot Spring Security (OAuth2/OIDC), Hibernate/JPA, Gradle
- Identity and access OAuth2, OIDC, Authentik, Keycloak, token rotation
- Infrastructure Kubernetes (CKAD certified), Docker, Helm, GitLab CI, GitHub Actions, Linux, S3
- Also used Go (project level), Python (Flask, SQLAlchemy), Angular, Svelte, PostgreSQL
Trained as IT specialist for application development (IHK Fachinformatiker Anwendungsentwicklung) at the German Cancer Research Center in Heidelberg.
Contact
I am open to backend roles – remote, or within commuting distance of Karlsruhe.
Email: access.job.manager@gmail.com
GitHub: github.com/Martin1088