Skip to content
LR-Gutierrez

Full-stack engineer and team lead.

I build software where security is a design decision, not a final checklist.

Based
Caracas, UTC−4
Coding
Since 2019
Status
Open to remote and relocation
Now
Senior developer, PCI-DSS banking
Before
Information Security Manager, INAC
Stack
ASP.NET Core, NestJS, Angular, Kotlin, PostgreSQL

Selected work

02 projects

AuraOS dashboard: live occupancy against 90 bays, today's revenue, active memberships and shortcuts to branches, exits, kiosk mode and audit

Dashboard · live occupancy, revenue and shortcuts

01 · 2026

AuraOS

Local-first parking access control

Replaces the paper log at a parking lot with an app for the guard on rounds and a self-service kiosk. Keeps working offline through a custom change journal and field-level merge, syncing to a NestJS and PostgreSQL backend; operators sign in with biometrics backed by hardware keys.

  • Kotlin
  • Room
  • NestJS
  • PostgreSQL · Prisma
  • SSE · FCM
  • Android Keystore

Control panel · orders, mileage alerts, finances and inventory by period

02 · 2026

AutoNex

Workshop ERP, from vehicle intake to delivery

Service orders that record mileage, fuel level, prior damage and reported faults; a vehicle history per plate or VIN; inventory with minimum-stock control; mileage-based maintenance reminders over WhatsApp; and official BCV exchange rates scraped, approved and published on schedule.

  • ASP.NET Core
  • PostgreSQL
  • Angular
  • Ionic · Capacitor
  • SignalR
  • wa-notifier · NestJS
  • Biometric auth (mobile)

How I work

Security as a design input

I ran information security at Venezuela's civil aviation authority and now build inside a PCI-DSS banking environment. Authentication, data handling and failure modes are decided with the architecture, not audited after it.

Leading the team, not just the code

I've coordinated development teams end to end: gathering requirements with the people who use the system, planning and tracking work, and reporting progress to leadership.

AI in the development loop

I write Skills and MCP servers and orchestrate agents to speed up the repetitive parts of the cycle, while design decisions and review stay mine.

  • .NET
  • NestJS
  • Laravel
  • OpenJDK
  • JSON Web Tokens
  • Angular
  • TypeScript
  • React
  • Tailwind CSS
  • Kotlin
  • Android
  • Ionic
  • PostgreSQL
  • Prisma
  • SQLite
  • Linux
  • Proxmox
  • GNU Privacy Guard
  • WhatsApp
  • Firebase

Skills

Select one to see where I applied it

Backend

Frontend

Mobile

Data

Infrastructure

Security

Integrations

AI

Leadership

Every skill here links to a project or role where I used it. Nothing listed without evidence.

Experience

  1. Aug 2026 – nowSenior Software DeveloperP&A Asociados Gerenciales · consulting for a universal bank, PCI-DSS
  2. Mar – Aug 2026Software ConsultantFreelance · automotive workshop ERP
  3. 2025 – 2026Information Security ManagerINAC · GPG-based procedure for exchanging sensitive data with external entities
  4. 2023 – 2024Software DeveloperINAC · high-demand REST API with rate limiting, JWT and route-level permissions
  5. 2023Software DeveloperBolivariana de Aeropuertos
  6. 2022 – 2023Development & Systems CoordinatorInmobiliaria Nacional · led the development team; infrastructure on Proxmox

MSc Cybersecurity, CEUPE (expected 2027) · BEng Computer Engineering, UNEXCA

English (B2) · Russian (A1)

Open to remote roles as a senior engineer or team lead

luisangelrgr@gmail.com

02 · 2026

AutoNex

Workshop ERP, from vehicle intake to delivery

Service orders that record mileage, fuel level, prior damage and reported faults; a vehicle history per plate or VIN; inventory with minimum-stock control; mileage-based maintenance reminders over WhatsApp; and official BCV exchange rates scraped, approved and published on schedule.

Problem

The shop this replaces ran on paper: service intake, vehicle history and maintenance reminders all tracked by hand. It needed one tool that worked the same way on Android, in the browser and on Linux desktops.

Role

Sole developer across all three repos — frontend, backend and the messaging service — working directly with the shop that owns and still runs it.

Constraints

  • One developer, so the stack had to favor a single codebase over separate native builds.
  • No official API for the Central Bank's exchange rates, and the numbers feed pricing — they have to match the source exactly, not just be close.
  • Delivery confirmation for WhatsApp messages needed to be real-time, not polled.

Key decisions

Scraped exchange rates with a manual approval gate

There's no public official API for the Central Bank's rates, so the system scrapes the published bulletin automatically. Before a rate takes effect, an admin reviews and approves it — a deliberate manual step to guarantee the rate matches the source exactly, even though the fetch itself is automated. Trade-off: a human bottleneck in an otherwise automated pipeline, but for a number that feeds pricing, an eyes-on override beats fully trusting an unattended scrape.

One Angular/Ionic codebase for web, Android and Linux

Ionic and Capacitor ship the same Angular codebase to the browser, as an Android app and as a Linux desktop build. Trade-off: less native polish and fewer native APIs than three separate frontends, in exchange for one developer being able to maintain all three.

A separate messaging service instead of talking to Twilio directly

WhatsApp delivery goes through a small NestJS service, wa-notifier: the API sends the message over HTTP, and delivery confirmation comes back over SignalR, authenticated with a shared secret — effectively a webhook over a WebSocket instead of Twilio's own webhook model. Twilio is still a dependency in the codebase but disconnected: no credentials configured, dead code from an earlier approach.

Biometric auth, mobile only

Available only on the Android build, where it replaces typing a password — convenience for the shop's staff, not a second factor. It isn't part of the web or desktop login flow.

Architecture

Angular/Ionic client over REST for data and SignalR for real-time updates (WhatsApp delivery status pushes live). Outbound WhatsApp messages go over HTTP to wa-notifier (NestJS), which confirms delivery back over SignalR. ASP.NET Core API backed by PostgreSQL; exchange rates are scraped on a schedule and held for manual approval before publishing.

Outcome

In production and still maintained by me — the shop uses it daily for service orders, vehicle history and WhatsApp alerts.

What I'd do differently

I'd pull the dead Twilio dependency out instead of leaving it installed with no credentials — that's exactly the kind of leftover that confuses whoever touches this code next, including future me.

Stack

  • ASP.NET Core
  • PostgreSQL
  • Angular
  • Ionic · Capacitor
  • SignalR
  • wa-notifier · NestJS
  • Biometric auth (mobile)