Gopiraj Dorairaj · Principal Engineer
Engineering Platform & Infrastructure AI & API Platform Architecture
Available for principal & staff engineering roles

Gopiraj Dorairaj

Principal Software Engineer — AI & API Platform Architecture

Toronto, ON, Canada 20 years experience gopiraj.dorairaj@gmail.com (416) 399-3310 github.com/doraig

Overview

Principal engineer and architect with 20 years building enterprise platforms across healthcare, logistics and finance. I design and ship the full stack of a modern API business: the gateway and authorization layer that fronts it, the multi-tenant developer platform that sells it, the observability that proves it works, and — most recently — the AI layer that makes it self-serve.

Recent work centres on production AI systems with real security boundaries: an MCP server with OAuth 2.1 dynamic client registration and deny-by-default RBAC across every dispatch surface, a retrieval-augmented assistant with guardrails and semantic caching, an agent platform with short- and long-term memory, interactive MCP UI apps that let partners complete real workflows inside the AI client, and a TimescaleDB-backed audit analytics stack that agents query under permission-scoped, PHI-aware controls. Equally comfortable modernizing legacy estates — I led a Java 25 / Micronaut framework upgrade using agentic AI workflows, cutting a multi-quarter migration to weeks while raising security-scan and code-quality compliance.

What you get

The short version
  • An AI platform that passes a security review. I build agent surfaces with real authorization — deny-by-default permissions, parameter-scoped grants that separate PHI from aggregates, and audit that cannot be bypassed — not demos that get blocked before production.
  • End-to-end ownership. Gateway policies, multi-tenant portal, data model, CI/CD, infrastructure-as-code and observability. I have shipped and operated every layer, so designs account for what happens at 3am.
  • Legacy modernization that actually lands. A Java 25 / Micronaut / Gradle upgrade driven with agentic AI workflows, compressing a multi-quarter migration while raising Sonar and container-scan compliance.
  • Polyglot depth, not a single stack. Java, PHP, TypeScript, Rust and Lua in production — chosen for the problem, including a Rust rule engine for HIPAA-compliant data filtering.
  • Healthcare-grade compliance instincts. HIPAA, PHI governance, federated identity across 20+ partners, mTLS trust chains and FHIR — built in from the first design, not retrofitted.
  • A force multiplier for the team. I mentor through peer programming and tooling, and write the documentation that lets the next engineer make the change safely.

Experience

Principal Software Engineer
June 2017 – Present
PointClickCare · Mississauga, ON

Technical lead and architect for PointClickCare's public API platform — the Apigee gateway, the partner developer portal, the configuration services behind them, and the AI layer now built on top.

AI platform & agentic systems
  • Designed and shipped a production MCP (Model Context Protocol) server exposing the API platform to AI clients such as Claude Code — tools, resources, prompts and streamable-HTTP transport, served by a dedicated long-running secure worker alongside the in-app HTTP surface.
  • Built an interactive UI layer on top of that server, so partners complete real workflows inside the AI client instead of being handed instructions. The UI is served by the platform and rendered in a sandboxed frame, delivered separately from the conversation so the markup never consumes the model's context window.
  • Shipped the flagship app — an interactive developer-application creation form (app name, dev/production purpose, callback URL, target platforms, contact and support details) with conditional validation for production requests, built in Vue 3 + TypeScript + Tailwind and bundled by Vite as a single self-contained HTML artifact.
  • Made that UI a first-class participant rather than a static panel: it calls platform tools directly, submitting through the same RBAC gate as any agent call, inherits the host application's theme and typography for native light/dark rendering, and feeds results back to the assistant so it can plan the next step — with host capabilities feature-detected so partially-supporting clients degrade gracefully instead of breaking.
  • Versioned UI assets by content hash so a rebuild reliably reaches users rather than leaving the long-running server advertising a stale asset, and supported UI-only tools that drive the interface without cluttering the model's tool list.
  • Wrote a cross-platform Rust installer CLI (plus shell and PowerShell bootstrappers) that registers the MCP server with Claude clients across macOS, Linux and Windows, turning partner onboarding into a single command.
  • Implemented OAuth 2.1 Dynamic Client Registration (RFC 7591) for agent onboarding: PKCE-only public clients, initial-access-token authorization, strict HTTPS redirect-URI validation with domain allow-listing, per-user client caps, registration rate limiting and full audit logging — plus RFC 9728 Protected Resource Metadata discovery so agents resolve authorization servers and scopes without hardcoded configuration.
  • Built a deny-by-default RBAC model for MCP tools: a 16-permission vocabulary, a tool → permission enforcement table, five inheriting roles, and parameter-scoped authorization where a single tool spans multiple risk tiers — separating PHI-bearing raw audit reads from pre-aggregated metrics so they can never share a grant. Enforced identically across all four dispatch surfaces with an off / shadow / enforce staged rollout, and made permission changes a database operation rather than a deploy.
  • Made authorization and audit inseparable through a single gate: every tool call is recorded at the permission layer rather than the tool layer, so an aggregated metrics read is distinguishable from a patient-linked one.
  • Built a RAG-based assistant for partner and developer self-service — vectorized API documentation and platform knowledge, retrieval grounded on an Apache AGE property-graph knowledge model queried through Cypher over PostgreSQL, with tenant and user identity propagated into every retrieval call.
  • Added guardrails, semantic caching and full auditability to the AI surface: input/output policy enforcement, embedding-similarity response caching to cut latency and token spend on repeated API questions, and end-to-end tracing and evaluation via self-hosted Langfuse (web + worker) and Arize for model and retrieval quality.
  • Built an agent platform for deploying purpose-built agents with short-term conversational memory and long-term persistent memory, multi-step tool loops over read-only MCP tools, per-step token and trace capture, and structured chart extraction for analyst-facing answers.
  • Stood up a TimescaleDB API audit and traffic-analytics stack — hypertables plus 15-minute continuous-aggregate rollups by flow, application and organization/facility — and exposed it to Claude via MCP for internal analytics: an allow-listed, read-only query tool with column allow-lists, heavy-column exclusion, bounded row limits, validated ordering and a preview mode, so analysts and support get natural-language traffic forensics with no direct database access.
  • Architected an earlier AI-powered virtual assistant for partner onboarding using RAG over a PostgreSQL AGE graph database.
API gateway & platform engineering
  • Own the Apigee Edge estate: 15+ API proxies and shared flows across six environments, with a Java/Maven automation harness that deploys proxies, products, developers, apps, target servers, keystores, virtual hosts and KVMs as versioned, CI-driven configuration.
  • Engineered the gateway's security perimeter — OAuth 2.0 two- and three-legged flows, OIDC callbacks, two-way TLS with certificate validation, IP allow-listing, JSON threat protection, spike arrest, and per-app/per-org quota with proactive breach notification.
  • Designed and delivered the UAP public API routing path, moving user-provisioning and directory endpoints onto the developer portal as a first-class Apigee target — with cached client_credentials tokens from KVM-held credentials, route-rule precedence and feature-flagged rollout per environment.
  • Maintain the gateway root truststore and partner mTLS chains, keeping certificate trust current for 20+ integrating healthcare partners.
  • Led design of a scalable multi-tenant API platform and a developer program portal for Open API vendor onboarding, built on PHP/Laravel with a Vue 3 TypeScript SPA, Hasura GraphQL over PostgreSQL, OpenResty front-controller routing, Redis and Laravel Horizon queues.
  • Architected a GraphQL abstraction layer that reduced API complexity by 60%, and implemented event-sourced aggregates and projectors for auditable partner lifecycle state.
  • Established federated authentication across 20+ healthcare partners (OIDC / SAML 2.0) and built an SSO integration framework for third-party marketplace applications.
  • Engineered a high-performance rule engine in Rust for HIPAA-compliant health data filtering.
  • Implemented global routing for vendor integrations using Lua / OpenResty, and designed micro frontends with module federation.
Cloud, modernization & reliability
  • Led the Java 25 / Micronaut 4.10 / Gradle 9.7 upgrade of the Chapeau configuration API, using Claude Code and agentic workflows to drive dependency analysis, code migration, test generation and Sonar remediation — compressing a large framework migration and resolving virtual-thread / APM class-circularity failures that blocked the runtime upgrade.
  • Improved that service's performance and security posture in the same programme: replaced JPQL join-fetches with native projections on hot paths, retuned the webhook queue's timing invariants to stop drain loops on slow partner endpoints, introduced GraalVM native-image and AOT-optimized builds, and wired Wiz container scanning plus SonarQube quality gates into every release.
  • Re-architected background processing into a single artifact with server and CLI run modes, so outbox delivery, webhook drain and reconciliation run as Kubernetes Jobs instead of unconditional in-process timers — with recovery for abandoned rows and bounded reconciliation sweeps.
  • Migrated solutions to Azure with Terraform Infrastructure as Code, delivered AKS and Azure Container Apps workloads with managed-identity Key Vault secret injection, and built CI/CD across GitHub Actions and Jenkins.
  • Developed Azure serverless solutions for FHIR data standardization and Apigee-to-portal synchronization.
  • Engineered observability with OpenTelemetry, OpenObserve, Grafana, Micrometer and Azure Log Analytics, including synthetic health probes for identity-path monitoring.
  • Built and mentored the development team through the transition from bare-metal products to cloud services.
Java · PHP/Laravel · Node.js · TypeScript · Rust · Vue 3 · React · Spring Boot · Micronaut · GraphQL/Hasura · PostgreSQL/TimescaleDB · Apigee Edge · Azure · Kubernetes · Terraform · MCP · Azure OpenAI · Claude · LangChain · Flowise
Technical Solutions Architect
Aug 2015 – June 2017
NTT Data (consulting for McKesson Pharmacy Solutions) · Markham, ON
  • Translated business strategy into system architecture requirements and multi-team delivery plans.
  • Introduced Docker containerization to legacy pharmacy delivery pipelines.
  • Designed data architectures and architectural improvements for long-lived pharmacy systems.
  • Built microservices and middleware pipelines in Java / Spring.
  • Modernized Java Swing applications with Angular and Ember single-page front ends.
Java 8 · JSP · Java Swing · Ember.js · Spring · SQL/PL-SQL · Oracle · Docker
Senior Principal Consultant
Aug 2011 – June 2015
NTT Data (consulting for McKesson Pharmacy Solutions) · Michigan & Pittsburgh, USA
  • Owned architecture analysis and project scoping with explicit performance benchmarks.
  • Designed data architectures and built Java / Spring microservices and middleware pipelines.
  • Delivered clinical system integrations using the Rhapsody integration engine.
Java · JSP · Java Swing · Spring · Oracle · C++
Software Engineer
Aug 2006 – Dec 2010
NTT Data · Bangalore, India
  • Delivered full-SDLC business process implementations, from UML sequence and class design through release.
  • Built plugin-based frameworks with EJB / MDB and used JMX for server-side cache management.
  • Developed Swing presentation layers, custom JSTL tag libraries and stored procedures for data migration; optimized SQL reporting.
  • Wrote unit tests with JUnit and EasyMock.
Java 5 · JavaScript · JSP · Spring · Oracle · C++

Published work

On LinkedIn

Education

Bachelor of Technology, Information Technology
Anna University, Chennai, India
May 2006