Available — Funchal, Portugal Principal Eng · AI R&D · CTO

Build. Break. Harden.

I’m Ihor — a principal engineer and founding CTO who turns ambiguous zero-to-one bets into shipped systems, then puts on the white hat and breaks what I built before attackers can.

13+ years shippingSecurity-minded by defaultPrototype → production, fast
13+
years building software
100K+
users on systems I’ve shipped
70%
dev overhead cut as CTO at NOSH Guide
15+
portfolio companies backed through R&D
(Operating mode)

I live at
zero → one.

I join at the earliest, messiest stage — ambiguous problem, speed deciding everything — and I’m gone before a company hardens into long, pointless process. The repetitive process work that bogs teams down? I hand it to agents and stay up front, where it’s still a genuinely hard problem.

  1. 0 → 1where I plug in — fast & decisive
  2. Scalehanded off, foundations already laid
  3. Process theater← offloaded to agents, not people

Field operations.

(Flagship + selected builds)

Products and systems built from unclear starting points — where speed, uncertainty and technical depth all show up at once.

(Operating principle)

If I built it,
I’ve already tried
to break it.

The same instinct that ships a prototype by Friday is the one that asks how it falls over on Monday. I design for the attacker in the room — threat-model early, fail closed, leave nothing easy. White hat, always.

Two hands,
one keyboard.

(Capabilities)

Most of my work lives in the tension between moving fast and not getting owned. Here’s both halves.

Build

// ship it
  • Rust · primary — systems, speed & safety
  • Autonomous AI agents & orchestration
  • RAG systems & retrieval pipelines
  • Rapid prototyping, prototype → production
  • System architecture & microservices
  • Full-stack & serverless cloud infrastructure
  • Payment systems & API design
  • Database & performance optimization
  • Technical leadership & mentoring

Break

// then harden it
  • Threat modeling & attack-surface mapping
  • Security analysis & real-time monitoring
  • Secure-by-design architecture
  • Auth, access control & least privilege
  • SOC 2-oriented engineering practices
  • Adversarial code review / red-team mindset
  • Incident-minded, fail-closed defaults
  • AI agents pointed at finding the holes

Track record.

(2013 → present)
2025 — now

Research & Development Lead · VC portfolios

Build AI prototypes, validate venture hypotheses and stand up technical infrastructure for portfolio companies and early product bets.

2025 — now

Board Advisor · NOSH Guide

Fractional technical leadership on hiring, product architecture and business-aligned technology decisions.

2022 — 2025

Chief Technology Officer · NOSH Guide

Founding CTO. Built lean serverless infrastructure, held engineering capacity together under severe constraints, and cut development overhead by 70%.

2022 — 2025

Senior Software Engineer · Maximize Capital

Delivered fintech platform foundations — authentication, document signing, integrations, notifications — under SOC 2-oriented engineering practices.

2013 — 2024

Full-Stack Engineer & Technical Lead

Marketplaces, real-time industrial monitoring, B2B travel, payment systems and frontend platforms — scalable product infrastructure across the board.

Put me to work.

(Engagements)

Three ways to hire me — ship a bet fast, or come at your product the way an attacker would. Clear scope, clear terms.

ENGAGE-01Build

Rapid hypothesis testing

$200/ hour

Turn an unproven idea into a working MVP you can put in front of real users — lean, hands-on, no ceremony.

  • Prototype → working product in a few days, almost always
  • 0 → 1 builds: AI agents, RAG, full-stack, payments
  • You see the bet get real before committing big
ENGAGE-02Security

In-depth source code review

from$14,000

I read your codebase like an adversary — architecture, auth, data flows, trust boundaries — and hand back a prioritized report of what’s wrong and why it matters.

  • Priced by what I find — class and count of issues
  • Floor of $14,000; capped at a number we agree up front
  • Every finding reproduced, rated and ranked by risk
ENGAGE-03Security

Black-box testing

$1,000one-time + bounty

A first external probe of your live product — I come at it like an outside researcher hunting bug-bounty-class holes. Source optional.

  • Flat $1,000 one-time fee to set the engagement loose
  • Plus a bounty per bug I find — paid by severity, like a private program
  • Black-box by default — works with or without source
(Say hi)

Let’s
talk.

Building something early and ambiguous, chewing on a security problem, curious about agents, weighing an advisory call — or you just want to trade ideas. No pitch required, no agenda. My inbox is open.