Who am I?

Toufic Hajj

Senior Full-Stack & Cloud Platform Engineer

FrançaisEnglishMontreal
Toufic Hajj

Introduction

The short version.

Senior Full-Stack & Cloud Platform Engineer with 15+ years owning products end to end — from ideation and architecture through mass deployment across on-premise, cloud, and hybrid environments for public and private organizations.

Earlier in my career I helped shape knowledge-technology platforms for cities, libraries, museums, and institutions (InMédia / BiblioMondo): federated content, DAM, citizen portals, multilingual delivery, accessibility (WCAG), and GDPR-conscious systems serving millions of users worldwide.

My recent work focuses on cloud-native platforms, data-heavy systems, workflow automation, security-conscious architecture, governance/compliance, and AI-enabled engineering tools.

I’ve led teams of 10+ while remaining highly hands-on. I’m especially interested in roles where full-stack engineering, cloud platforms, data systems, automation, and AI integration create measurable business value.

Context

The arena I know best.

A decade inside knowledge technologies (InMédia / BiblioMondo) — platforms for cities, libraries, museums, and institutions that must federate content, respect rights, and survive mass deployment.

01

Cities

Citizen portals, municipal intranets, and public e-services that keep working when the city is online — and when it isn’t.

02

Libraries

Multimedia catalogues, personal spaces, and companion apps that connect physical collections to digital convenience.

03

Museums

DAM, virtual exhibitions, and digital signage across heritage networks — rights-aware media, not just file storage.

04

Enterprises

Private and hybrid deployments for organizations that need the same platform rigor without a public-facing mandate.

Platform

What the stack had to do

Not a marketing site — an open, flexible CMS + DAM platform that creates, manages, and presents information and services to the public.

  • Web portals and personal / citizen spaces
  • Multimedia catalogues and advanced viewers
  • Digital asset management with usage rights
  • Virtual exhibitions and digital signage
  • Mobile apps, newsletters, calendars, and events
  • Forms, surveys, and back-office operations
  • Multilingual delivery with WCAG-minded admin tooling
  • GDPR-conscious handling of personal data

Deployment

Where it had to run

Same product family — different operational realities. Architecture that survives tenders, audits, and city-scale rollout.

  • On-premise: institutional networks and 1,500+ public workstations
  • Cloud: multi-tenant portals and government API integrations
  • Hybrid: public surfaces with secured intranet cores
  • Public organizations: libraries, museums, municipalities, ministries
  • Private organizations: enterprise knowledge and media workflows
  • Mass deployment with uptime, accessibility, and tender scrutiny

From idea to fleet

Ideate

Shape the product

Roadmaps, research (SMESE / MLM harvesting lines), and stakeholder needs before a line of production code ships.

Architect

Make it durable

SPA/mobile fronts, microservices migrations, federated content, and standards that outlast a single release.

Deploy

Roll it out at scale

On-prem, cloud, and hybrid mass deployment for institutions that cannot treat go-live as a demo day.

Career

Work Experience

Knowledge platforms for institutions, then aviation, energy, and product engineering — 15+ years of ownership from ideation through deployment.

September 2025 - PresentMontreal, QC

Full Stack Software Engineer

Wisk.aero

  • Build and evolve an internal workflow-orchestration platform — Argo Workflows on private GKE — so engineering and data teams can run large pipelines without owning the infrastructure underneath.
  • Ship platform infrastructure as code with Terraform and GitOps: GitLab CI/CD, Argo CD ApplicationSets, and ephemeral per-merge-request environments that provision and tear themselves down.
  • Implement the platform's identity and compliance controls — OIDC SSO personas, Kyverno admission policies, Workload Identity for keyless cloud access, and export-control (EAR) data boundaries.
2024 - PresentMontreal, QC

Founder / Full-Stack Product

Technologies Toufic Hajj Inc. — Thirty North

  • Shipped thirtynorthgst.ca: privacy-first GST/HST threshold tracker for Canadian cross-border freelancers.
  • Built dual CRA threshold tests (single-quarter and four-quarter), bilingual EN/FR UX, guides, and paid workflow kits.
  • Designed honest product limits — calculates user inputs, does not classify work or replace tax advice — with local-first data and merchant-of-record checkout.
October 2024 - July 2025Montreal, QC

Full Stack Developer

CWP Energy Solutions

  • Built high-throughput applications to process real-time data for internal and external users.
  • Designed data visualization tools and trading interfaces for executing transactions across electricity markets.
  • Built the data pipeline the trading desk ran on — electricity market feeds ingested through Pub/Sub and Dataflow into GCS and BigQuery, with streaming and batch paths landing in one queryable model.
June 2020 - August 2024Montreal, QC

Full Stack Developer

Freelance

  • Designed and built a comprehensive trading toolkit using React, natively integrated with Electron.
  • Delivered multiple high-quality React projects focusing on micro-frontend and component-based architectures.
  • Refined RLHF reward models to improve French LLM outputs.
September 2017 - February 2020Montreal, QC

Vice President Research And Development

InMédia Technologies / Bibliomondo

  • Owned R&D strategy for an all-in-one knowledge platform (CMS, DAM, catalogues, citizen portals, mobile, digital signage) serving cities, libraries, museums, and institutions.
  • Drove delivery from ideation to production across on-premise, cloud, and hybrid deployments for public-sector and private clients.
  • Established accessibility (WCAG) and privacy-conscious (GDPR-aligned) engineering standards for citizen-facing portals.
  • Ensured 99.8% product uptime through cloud architecture, operational rigor, and risk management.
  • Led technical evaluations for tenders, helping secure $2M+ in contracts.
  • Managed R&D teams of 10+ through major platform transitions while staying hands-on on architecture and delivery.
  • Co-authored research on semantic harvesting, micrometadata, and ML-driven knowledge systems (SMESE / MLM lines of work).
March 2012 - September 2017Montreal, QC

Director Of Research Development

Bibliomondo Technologies du savoir

  • Architected modern SPA and mobile experiences (React, React Native, Redux, Jest) for multilingual knowledge and cultural portals.
  • Led a zero-downtime microservices migration that reduced infrastructure cost while protecting uptime for institutional clients.
  • Advanced platform capabilities spanning federated content, multimedia catalogues, DAM, and rights-aware media distribution.
  • Supported large-scale public deployments across municipal, library, and museum networks.
March 2010 - February 2012Montreal, QC

Lead Software Developer

Bibliomondo Technologies du savoir

  • Directed code reviews, testing, and deployment of J2EE (JSF, REST APIs) and web applications for knowledge-technology products.
  • Orchestrated JSP → JSF front-end migration and EJB → RESTful services transition to improve scalability and maintainability.
  • Deployed and supported systems across 1,500+ workstations in public libraries, museums, and city administrations (on-prem / networked environments).
  • Built foundations for secure public multimedia workstation and resource management in institutional settings.
October 2009 - March 2010Montreal, QC

Software Developer

Bibliomondo Technologies du savoir

  • Developed Java web applications, reducing deployment errors by 50% through automated testing.
  • Guided QA to integrate Selenium, raising automated test coverage by 80%.
  • Established CI/CD pipelines using Jenkins and Maven, boosting developer productivity by 30%.
September 2008 - September 2009Montreal, QC

Founder

HD Firms

  • Completed 30+ freelance projects with a perfect 5/5 client satisfaction rating.
  • Developed PHP/MySQL web applications meeting strict timelines and client specifications.
January 2005 - May 2006Laval, QC

Software Programmer

NetCom

  • Maintained legacy codebases, improving system stability and performance.
  • Migrated backend from VB6 to C#.NET and UI from Classic ASP to ASP.NET.
  • Configured internal infrastructure (Active Directory, Exchange, GPO) for a secure IT environment.

Capability map

Architecture & technical range

Capability-first, not stack-first: pick the shape that fits the constraint — protocol, runtime, and cloud brand are tools, not identity.

01

Platform architecture

End-to-end platform shape across on-prem, cloud, and hybrid — designed to survive real operators and real scale.

  • Cloud-native & hybrid platforms
  • On-prem when the brief demands it
  • Service boundaries (microservices ↔ modular monoliths)
  • Event-driven & async architectures
  • API & integration design (REST, GraphQL, gRPC, …)
  • Serverless, containers, or VMs — fit for purpose
  • Multi-cloud literacy (AWS · GCP · Azure)
02

Application systems

Full-stack product surfaces with durable boundaries — web, desktop, and mobile when the product needs them.

  • TypeScript & modern web platforms
  • React · Next.js and peer ecosystems
  • Node.js & service backends
  • JVM / Spring when enterprise fits
  • Angular · Vue when the codebase calls for it
  • Desktop & mobile (Electron · Flutter, …)
  • Client state & component architecture
03

Data platforms & pipelines

Operational and analytical paths: stores, streams, and processing chosen for the data shape — not a single vendor dogma.

  • Pipeline & data-flow design
  • Streaming & messaging (Kafka and peers)
  • Batch & distributed compute (Spark and peers)
  • Real-time & near-real-time paths
  • Relational stores (PostgreSQL, MySQL, …)
  • Document, search & secondary indexes
  • Analytics-ready modeling
04

SRE & reliability

Architecture that can be operated — uptime, failure modes, and day-2 reality baked into delivery.

  • Reliability engineering
  • Observability & operability
  • Resilient deploy & rollback patterns
  • SLOs / error budgets as design input
  • Incident-aware delivery
  • Institutional uptime track record
05

GitOps & delivery

Release as a controlled system: source-of-truth delivery, promotion paths, and platforms that match the org.

  • GitOps & declarative delivery
  • CI/CD across toolchains
  • Kubernetes & managed clusters
  • Containers & runtime packaging
  • Pipeline platforms (Jenkins, cloud CI, …)
  • Environment promotion & release discipline
  • Infrastructure-aware delivery
06

Security & compliance

Trust constraints treated as product requirements — accessibility, privacy, and governance shaped to the jurisdiction and audience.

  • DevSecOps & secure SDLC
  • Threat-aware architecture
  • Accessibility (WCAG and beyond)
  • Privacy & data protection (GDPR and peers)
  • Privacy by design
  • Public & regulated-sector governance
  • Policy, audit & evidence readiness
07

FinOps & cloud economics

Cost as an architectural signal — right-sizing, tradeoffs, and spend that tracks real value.

  • Cost-aware architecture
  • Right-sizing & efficiency
  • Cloud spend ↔ reliability tradeoffs
  • Infra cost reduction without false savings
  • Vendor & tender evaluation
  • Build-vs-buy judgment
08

Visual systems & UX

Interfaces people can operate under pressure — product UI, data visualization, and multilingual delivery.

  • Product UI / UX
  • Data visualization & visual analytics
  • Operator & trading-style dashboards
  • Information architecture
  • Multilingual / bilingual UX
  • Citizen & institutional portals
  • Design systems & interaction patterns
09

Leadership & delivery practice

Hands-on technical leadership across R&D, tenders, and cross-functional delivery — method follows the mission.

  • R&D leadership
  • Architecture ownership
  • Team leadership (10+)
  • Public-sector tenders & evaluations
  • Adaptive delivery (Agile and beyond)
  • Technical writing & decision records
  • Stakeholder & exec alignment
10

Research & publications

  • Trusted smart harvesting algorithm based on semantic relationship and social networks (SMESE-TSHA) — co-author, InMédia Technologies
  • Traceable and Trusted Smart Harvesting Algorithm from Unstructured and Structured Web (SMESE-TTSHA) — co-author, InMédia Technologies
  • MLM-based learning and boosting model – part 1: multi-sources/rights of digital resources to build universal knowledge repositories — co-author, InMédia Technologies

Background

Education & credentials

Formal studies and certifications — supporting context for the work above.

Studies

  • I.S.I MontréalIntégration de systèmes d’information, Information Technology (2007 - 2008)
  • Université de MontréalComputer Science (2003 - 2006)

Certifications

  • Google Cloud Certified — Associate Cloud Engineer
  • Architecting with Google Kubernetes Engine Specialization (Google Cloud)
  • Cloud Application Development Foundations Specialization (IBM)
  • Python for Data Science, AI & Development (IBM)
  • Introduction to Cloud Computing (IBM)

Let's connect

Schedule a conversation

Open to full-stack, cloud platform, and technical leadership roles — including public-sector and institutional platforms.

© 2026 Toufic Hajj · Senior Full-Stack & Cloud Platform Engineer
Montreal, QC