Fares Elsadek
Backend Software Engineer
Cairo, Egypt
Backend Software Engineer focused on building scalable APIs, distributed systems, and cloud-native applications. Experienced in designing observable, reliable backend services with a strong foundation in security and DevOps.
Engineering Focus
I build scalable backend systems, focusing on clean API design, distributed communication, and cloud-native architecture. My work spans real-time systems, event-driven architectures, and robust cloud deployments.
I care about the details that keep systems running well: observability with OpenTelemetry and Grafana, cache invalidation strategies, cursor-based pagination, and authentication flows with OAuth2 and JWT. I also bring a security-first perspective from hands-on vulnerability research.
Experience
Software Engineer — Health Insights Group
December 2025 – PresentCairo, Egypt
- Worked on backend modules for a healthcare platform, contributing to feature development and maintenance.
- Helped redesign the real-time notification legacy system to support higher connection counts using SignalR and a Redis backplane.
- Participated in architecture discussions, code reviews, and technical planning.
- Collaborated with clinical and product teams to translate requirements into production-ready features.
- Supported production systems by resolving bugs, improving performance, and contributing to roadmap planning.
Software Engineer Intern — EJADA Systems
July 2024 – September 2024Cairo, Egypt
- Developed application backend features and maintained CRM integrations.
- Designed SQL Server queries for CRM and reporting workflows.
- Automated business processes using JavaScript.
- Built internal dashboards for data insights.
- Implemented role-based security controls.
Web Security Researcher — HackerOne
January 2023 – April 2024Remote
- Identified and responsibly disclosed vulnerabilities for programs including U.S. DoD and AT&T.
- Received Hall of Fame recognition across multiple programs.
- Applied security knowledge to API design, authentication, and architecture decisions.
Cyber Security Intern — ITI
August 2022 – September 2022Cairo, Egypt
- Completed 120-hour cyber security training.
- Studied computer networking fundamentals, Windows Server Administration, RedHat System Administration, and firewall technologies.
Featured Projects
DevTalk
GitHub →A developer social platform with posts, comments, voting, bookmarks, and categorized feeds.
- Built using Clean Architecture and CQRS via the Mediator library.
- Implemented real-time notifications using SignalR with an in-memory message queue for asynchronous processing.
- Implemented end-to-end observability using OpenTelemetry, collecting distributed traces and metrics, exposing them to Prometheus, and visualizing request throughput, latency, and error rates through Grafana dashboards.
- Used Redis caching with event-driven cache invalidation to keep data fresh and responsive.
Limitry
GitHub →A Redis-backed distributed rate limiter in Go supporting Token Bucket and Sliding Window Counter algorithms.
- Implemented Token Bucket and Sliding Window Counter algorithms via atomic Lua scripts.
- Designed dual-mode architecture: transparent reverse proxy and standalone check API, allowing drop-in integration with any stack.
- Implemented per-route configuration with fail-open/closed resilience policy for Redis outages.
- Instrumented full observability pipeline using OpenTelemetry for distributed tracing, Prometheus for metrics, and Grafana for dashboards.
SyncSpace
GitHub →A Discord-style collaboration platform with messaging, notifications, video rooms, and real-time presence.
- Designed as a 6-module modular monolith with clean architecture.
- Implemented OAuth2/OIDC authentication with Keycloak and JWT.
- Applied CQRS read/write separation and Redis caching.
- Used PostgreSQL schema-per-module design with Flyway migrations and indexing.
Other Projects
Technical Skills
Languages
Backend & Frameworks
Databases & Search
Architecture
DevOps & Cloud
Security
Technical Writing
- Sep 20, 2026I Was Looking for a Monitoring Tool. Then I Found One That Could Open the PR.
I’ve used monitoring tools before.Usually, something breaks, I get an alert, open a dashboard, stare at some logs, open another dashboard, stare at that one…
- Aug 19, 2026I Wanted to Build a Rate Limiter. It Turned Into a Distributed Systems Project.
How I built Limitry in Go with Redis, Lua, Kubernetes, OpenTelemetry, and k6 — and what I learned along the way.I originally thought building a rate limiter…
- Feb 12, 2025From Vulnerable to Invincible: Secure Your Web App with SafeLine WAF
IntroductionIt’s been a long time since my last blog post, and during this quiet period, I’ve been diving deep into the world of web security. Today, I want to…
- Aug 22, 2023My First Bug: How I Was Able to Bypass the WAF and Uncover a Reflected XSS
Hello everyone, I’m Fares. Today, I’ll share the story of how I successfully identified a reflected XSS vulnerability within a public bug bounty program.To…
Education & Certifications
Bachelor of Computer Science
Ain Shams University, Cairo, Egypt
September 2021 – May 2025
Certifications
- AWS Certified Cloud Practitioner — Amazon Web Services
- Certified AppSec Practitioner (CAP) — SecOps Group
- Object Oriented Programming in Java — UC San Diego (Coursera)
- Cyber Security Training — 120 hours — ITI
Volunteering
- Web Security Instructor — Cyberus ASU Committee
- Problem Solving Committee — ACM ASCIS
Contact
- Email:[email protected]
- LinkedIn:linkedin.com/in/fares-elsadek
- GitHub:github.com/fares7elsadek