{"content":"# Zhonghua (Laisky) Cai\n\nOttawa, ON, Canada\n\njob@laisky.com · 873-569-8887 · LinkedIn: https://www.linkedin.com/in/laisky-cai-14237926/  \nGitHub: https://github.com/Laisky · Blog: https://blog.laisky.com/ · CV: https://cv.laisky.com/\n\n## Summary\n\nSenior Software Engineer with 10+ years building Linux-based services, security infrastructure, and developer tooling in Go and Python. Hands-on experience building PKI from scratch, including certificate issuance and revocation, TPM-based integrity measurement, attestation-backed identity, and hardware-protected key management. Delivered production security platforms end to end and led cross-functional engineering initiatives. Background spans confidential computing, distributed systems, and cloud platforms, with remote collaboration across globally distributed teams.\n\n## Skills\n\n- **Languages \u0026 Linux:** Go and Python (10+ years each): secure services, concurrency, CLI tooling, automation, async I/O, and data pipelines. Linux systems engineering, troubleshooting, performance profiling, and operational tooling. JavaScript / TypeScript.\n- **PKI \u0026 Certificate Management:** Root and intermediate CA architecture; leaf certificates; certificate signing requests (CSRs); certificate issuance, validation, and revocation; certificate revocation lists (CRLs); X.509 extensions and OIDs; TLS / mTLS; attestation-backed certificate issuance; zero-trust authentication and authorization.\n- **Hardware-Backed Security:** TPM-based system integrity measurement; remote attestation; confidential computing / TEE (Intel SGX, AMD SEV-SNP, Intel TDX); YubiKey PIV-based administrator authentication; multi-party authorization and key custody; KMS; protection of sensitive credentials and cryptographic material.\n- **Secure Services \u0026 Infrastructure:** gRPC, REST APIs, Protocol Buffers; access controls, tenant isolation, image signing, and secure deployment pipelines; distributed systems, state management, crash recovery, and fault tolerance. SDKs, CLIs, technical documentation, and operational runbooks.\n- **Cloud \u0026 Automation:** AWS, GCP, Azure; Kubernetes, Docker, Terraform, Ansible, CI/CD (GitHub Actions / GitLab CI); observability through tracing, metrics, and logging; infrastructure configuration and automation.\n- **AI / LLM:** Production LLM gateway, agent workflows, MCP servers, and RAG / PageIndex memory systems. Multi-provider routing, streaming, failover, access control, and metered billing. AI-assisted development with Codex, Claude Code, and GitHub Copilot.\n\n## Experience\n\n### Independent Software Engineering Consultant\n\nRemote · Oct 2024 – Present\n\n- Designed and delivered a TEE-hardware-rooted zero-trust platform for financial-services clients on GCP, using Intel TDX Confidential VMs and GKE Confidential Space to cryptographically remove single-operator trust dependencies from production operations.\n- Expanded the platform into a TEE PaaS for heterogeneous confidential workloads, including isolated AI agents, on a shared attested foundation. Owned architecture, implementation, security controls, and operational integration.\n- Re-architected a client's agent platform on GCP Agent Sandbox, replacing always-on runtimes with dynamically scheduled, per-request sandboxes that reduced operating costs while preserving isolation and responsiveness.\n- Maintain [one-api](https://github.com/Laisky/one-api), a production Go LLM gateway with multi-provider routing, MCP aggregation, multi-tenant access control, and metered billing. Built Go / Python agent workflows and a modular RAG / PageIndex memory system.\n\n### Senior Software Engineer, Platform \u0026 Confidential Computing\n\nShanghai BaseBit Technologies · Apr 2022 – Oct 2024\n\n- Built a complete PKI from scratch for a TEE security platform, covering root and intermediate CAs, leaf certificates, CSR processing, certificate issuance and validation, revocation through CRLs, and X.509 extension / OID handling. Issued identity certificates to devices following successful TEE attestation.\n- Implemented TPM-based system integrity measurement and YubiKey PIV-based administrator authentication, with multi-party authorization for sensitive operations and key custody. Integrated hardware-backed trust into authentication and credential-protection workflows.\n- Built a Go SGX SDK and runtime and designed a confidential Kubernetes platform with remote attestation, image signing, RBAC, and safe deployment / upgrade pipelines. Partnered with product and customer-facing teams on regulated financial and healthcare workloads, including code review and threat modeling.\n\n### Senior Software Engineer / Tech Lead, Cloud Security Platform\n\nQihoo 360 (Government \u0026 Enterprise Security Group) · Feb 2019 – Apr 2022\n\n- Tech-led Go microservices delivery for enterprise multi-tenant cloud security SaaS (CWPP / CSPM), covering telemetry pipelines, vulnerability management, and incident-response workflows.\n- Hardened service boundaries, release safety, and on-call tooling; investigated production failures and applied SRE practices to reduce incident MTTR and stabilize customer-facing SLAs.\n- Coordinated delivery across PM, QA, platform, and engineering teams; mentored engineers and supported customer rollouts and post-deployment troubleshooting with globally distributed counterparts.\n\n### Platform Architect, Cloud PaaS\n\nShanghai PATEO (Connected Vehicles / IoV) · Jan 2018 – Feb 2019\n\n- Owned platform reliability for 300+ Go microservices and thousands of containers supporting connected-vehicle services, including observability, capacity planning, release engineering, and on-call operations.\n- Architected go-fluentd, a Go streaming log-ingest middleware sustaining ~1 Gbps, with backpressure, buffering, and crash recovery, feeding downstream analytics, observability, and security-detection pipelines.\n- Standardized CI/CD pipelines and operational runbooks across product teams, improving deployment consistency, troubleshooting, and release efficiency.\n\n### Senior Software Engineer, Python Data Pipelines \u0026 Async Services\n\nMovoto (US Real Estate) · Dec 2016 – Dec 2017\n\n- Optimized Linux-based Python pipelines processing millions of listings and 300M+ addresses through profiling-driven refactors and async I/O, improving ingestion throughput.\n- Built and open-sourced kipp, a Tornado / asyncio developer framework for maintainable Python services and reusable backend tooling.\n- Collaborated remotely with US headquarters across time zones, supporting production delivery through clear technical documentation and asynchronous communication.\n\n### Earlier Roles\n\n- **DevOps Lead**, SAIC Motor E-Commerce · 2015 – 2016 · Led a five-engineer team; Kubernetes adoption; build platform handling ~1,000 builds/day; infrastructure automation.\n- **Python Engineer**, Shanghai Qisense · 2014 – 2015 · AWS fleet automation with Ansible; Linux-based data / ML pipelines.\n- **Research Engineer**, China Meteorological Bureau · 2012 – 2014 · Forecast verification systems and scientific software.\n\n## Education\n\nB.S., Atmospheric Science (Math / Physics concentration), Lanzhou University, 2012","updated_at":"2026-10-08T02:49:56Z","is_default":false}