available · New York is work, Delhi is home, open to relocate

Software engineer building privacy-safe community products, and the tools around them.

Vaibhav Garg is a software engineer at ThotExperiment. He scales chat, discovery, and moderation for Headero, and his public work includes a real-time log viewer, offline-first Android apps, and a blood-donation system.

prod — what I carved out of the monolith
$ kubectl get deploy
NAME           LANG     STATUS
gateway        node     Running
chat           go       Running
discovery      go       Running
sessions       spring   Running
views-notify   go       Running
global-feed    go       Running
admin          node     Running own HPA

$ ls lambda/
expiry-cron  deletion-cron  otp-cron

$ _
Role-fit modeHiring for… the page re-orders around your role.

fit › Go and Spring Boot services on Mongo and Redis at 10 ms p50, a fintech real-time API that replaced Hadoop batch jobs, and a Go + WebSocket log console on the side.

Impact, as a dashboard

every tile cites where the number came from
LATENCY●
10 ms
p50 at the service
src: Go discovery · Spring sessions
LATENCY●
1.5s→50ms
discovery feed latency
src: Mongo aggregations · Redis scoring
ENGAGEMENT●
9 → 20
weekly minutes in app
src: Firebase · view→notify loop
OPEN SOURCE●
16
public repos since 2017
src: github.com/vgarg1998
TEACHING●
350+
students mentored in DB design
src: Northeastern TA
SECURITY●
0
S3 keys held by pods
src: IRSA on EKS
SECURITY●
9
services de-vulnerabilised
src: Checkmarx · Black Duck
SHIPPED●
2
production Flutter features
src: Travel mode · Global Feed
01 · Lead case study · Mar 2025 — presentThotExperimentHeadero is ThotExperiment’s production platform: a forward dating app for adults, built around safety and privacy. Made in New York.Discovery, chat, and moderation for Headero, in production.
  • 1 › Split the hot APIs into Go and Java services behind a Node gateway
  • 2 › Isolated chat and admin on Kubernetes with HPA, probes, GitLab CI/CD
  • 3 › Discovery on Mongo aggregations + Redis scoring: 1.5 s → 50 ms feed
  • 4 › Rekognition moderation on EKS, and Travel mode shipped in Flutter
flutter→node gateway→chat · godiscovery · gosessions · springviews · go

Public work

three picked for Backend · all case studies →

git log --career

a1f09e2 (HEAD → next) open to backend / platform roles
9c3d4b7 2025 feat: split Node monolith into Go + Spring services @ ThotExperiment
7e21aa0 2024 docs: MS Computer Science, Northeastern · TA for 350+ students
55b8c1d 2020 feat: batch → real-time gRPC orchestrator @ TransUnion
3a0f6e9 2019 chore: Student Achiever Award · hackathon podium · 3 research papers
0000001 2016 init: B.Tech, VIT Vellore

Work

bright = relevant to Backend
ThotExperimentSoftware Engineer03/2025 — present · NYC, USA
  • ▸Split the Node monolith: chat, discovery, sessions and views extracted into services behind a Node gateway; admin isolated on its own K8s HPA; expiry, deletion and OTP crons moved to Lambda — chat spikes and nightly jobs no longer stall user APIs.
  • ▸Built Go discovery (Mongo aggregations, Redis ranking) and Spring Boot sessions (Mongo source of truth, Redis cache-first) — 10 ms p50 at the service, 50 ms p50 end-to-end on scroll.
  • ▸Shipped a Go view → notify → profile-open loop (TTL + WebSocket) that doubled weekly time-in-app (Firebase: 9 → 20 min), and a Rekognition worker that replaced hours of manual photo review with near-real-time approval.
  • ▸Developed Travel mode in production Flutter — map destination pin, travel-aware discover/profile APIs, free preview vs paid full access.
  • ▸Pushed Global Feed in production Flutter — nearby, preference-matched public posts (Go geo feed, 24h TTL) with tap-through to profile.
  • ▸Hardened AWS on EKS: IRSA for Rekognition (pods hold no S3 keys), internal NLB + security groups so Lambdas reach session APIs only inside the VPC, presigned S3 so the media bucket stays private.
Northeastern UniversityGraduate Teaching Assistant09/2023 — 12/2024 · Boston, USA
  • ▸Mentored 350+ students in 3NF database design, integrity constraints and complex SQL.
  • ▸Wrote 10+ advanced ERD scenarios applying full database-design principles, lifting scores by 10%+.
  • ▸Resolved Android questions on layout distortion across screen sizes, touch responsiveness vs the main thread, and activity state.
TransUnionSoftware Developer · Fintech11/2020 — 12/2022 · Remote
  • ▸Built a Java + gRPC orchestrator on Apache Camel that folded several Hadoop batch jobs into one real-time API, with pluggable, parallel routing across SOAP/REST/gRPC — near-instant results and lower infra cost.
  • ▸Built a universal validation library so REST APIs validate against XML-defined rules with no code changes.
  • ▸Built a Spring Boot API gateway with JSON sanitisation, validation, rate limiting and retries at 70%+ JUnit coverage.
  • ▸Evaluated Kuma Mesh for traffic management and observability; recommended against adoption over weak community support.
  • ▸Mitigated Maven library vulnerabilities across 9 services through reviews and Checkmarx / Black Duck scans.
TransUnionSoftware Intern02/2020 — 04/2020 · Chennai, India
  • ▸Built a REST gateway for tracking transit events on JPA, with the Strategy pattern for role-specific data and paginated queries for large datasets.

Stack

LANGUAGES
GoJavaTypeScriptJavaScriptPythonDart
CLIENTS
FlutterAndroidReactSwing
SERVERS & DATA
Node gatewayGo / Java microservicesSpring BootExpressgRPCMongoDBRedisPostgreSQLMySQLFirebaseRoom / SQLite
PLATFORM
Kubernetes / EKSHPAGitLab CI/CDAWS LambdaRekognitionIRSADocker ComposeNginxPrometheusGrafana
EARLIER
OpenCVTensorFlowFace detectionPageRank

How I work

Principles, each backed by a decision I actually made.

01 / isolate the blast radiusChat traffic and nightly crons shouldn't share a fate with login. So chat got its own Go service, admin its own HPA, crons went to Lambda.
02 / say no to shinyI evaluated Kuma Mesh for traffic management and recommended against it — community support was too thin to bet production on.
03 / no keys in podsIRSA over static credentials, internal NLBs over public endpoints, presigned URLs over public buckets. Least privilege by default.
04 / config over codeA validation library driven by XML rules meant new API checks shipped without a deploy.
05 / measure the user, not the box10 ms at the service is nice; 50 ms end-to-end on scroll and 9 → 20 min time-in-app is what mattered.
06 / own it end to endTravel mode and Global Feed: the Go API and the Flutter screen, both mine, both in production.

Writing

1 published · 2 in draft
Splitting a Node monolith without stalling user APIsGateway-first extraction, one service at a time.architecture · read →
Cache-first sessions: Mongo as truth, Redis as speedHow sessions hit 10 ms p50 without lying to users.spring · redis · draft
No keys in pods: IRSA, internal NLBs and presigned S3Locking down AWS on EKS without slowing the team.aws · security · draft

/now

looking › backend / platform roles, remote or relocating from Delhi
building › Discovery, chat and moderation for Headero at ThotExperiment

Beyond code

GOLDNational gold medal — archerySame skill as p99 tuning: calm, repeatable, small corrections.
68Three research papers · 68 citationsPublished during B.Tech at VIT
3RD2nd runner-up, HelloWorld 2.0 hackathonGravitas tech fest, VIT
2019Student Achiever Award, VITUniversity Day
EDUM.S. CS, Northeastern · B.Tech, VITCS5520 Mobile Apps · CS5500 · CS5010 Program Design · CS5200 Databases
verified certs ›Java · HackerRankPython · HackerRankSQL · HackerRankData Analysis w/ Python · IBMIntro to Data Science · U-M
$ echo "let's talk" | mail vaibhav

Have a system that's
outgrown itself?