SM
Portrait of Suleyman Musayev

Suleyman Musayev

Fraud & Abuse Engineer · Anti-Fraud, Account Security & PKI

I build fraud detection and account-security systems for attack-prone products: bot mitigation, insider threat detection, device fingerprinting, session defense. Sole architect at a top-10 certificate authority. Open to senior security roles.

  • Available now
  • Ashgabat, Turkmenistan (UTC+5)
  • Remote · global
  • Open to relocation · visa sponsorship

Experience

Where I've built and shipped.

Writing software since 2014, shipping production systems since 2022. Before engineering: quantitative trading and five years of government relations at an oil major. Each role taught me a different way to think about risk under pressure.

  1. Software Engineer · SSL.com

    Remote · top-10 global certificate authority

    Aug 2023 — Present

    Sole architect and lead engineer of the authentication, identity, and certificate- issuance platform at a top-10 global certificate authority. I design the distributed services, scale issuance through 10x growth, and, because attackers come with the territory, run the fraud and abuse defense too.

    • Sole architect of the company-wide authentication and identity platform (OAuth2, OIDC, SAML, session-based flows, external IdP integrations) serving tens of thousands of daily users; scaled the backend through 10× growth in TLS, code signing, and identity certificate issuance.
    • Distributed-systems work: extracted authentication into its own service with cross-service sessions, built multi-perspective certificate validation (MPIC) with quorum across vantage points, and designed the API servers, async workers, and audit pipelines around them.
    • Performance at scale: cut backend latency up to 5× and fixed slow API paths by eliminating N+1 queries, a hot-path regex, and a write storm, and by reworking batch polling into per-record jobs.
    • Correctness in money and state: idempotent billing, atomic multi-step writes, and APIs that stay backward-compatible as they grow.
    • Fraud, security & abuse: shut down months-long attacker reconnaissance before exploitation; bot defense at 1,000+ fake signups/day incl. CAPTCHA-farm countermeasures; stopped a $2,500/day SMS pumping attack in 4 days ($0 losses since); and defeated a persistent session hijacker who survived password resets, 2FA resets, and endpoint forensics.
    • Also built insider-threat and identity-theft detection, pairing LLM-augmented pattern matching with human-led forensics to go from detection to mitigation in minutes, not days.
    • Ruby on Rails
    • PostgreSQL
    • Redis
    • OAuth2
    • OIDC
    • SAML
    • PKI
    • Sidekiq
    • AWS
  2. Software Engineer · Midstay

    Remote · early engineer, 5-person team, ~1k DAU

    Nov 2022 — Jan 2024

    Early engineer on a 5-person team building a consumer product with ~1k DAU (joined as an intern in Aug 2022). Owned end-to-end features across the Rails stack and led incident response. Final 5 months were a contract wind-down with gradual transition of responsibilities while ramping up at SSL.com.

    • Closed authorization flaws surfaced in a live penetration test, including a broken access control that let the tester join private two-person chats as a third participant; led incident response against advanced attackers.
    • Reduced backend latency by up to 5× through query optimization, indexing, and caching.
    • Improved user retention by 15% through targeted performance and product improvements.
    • Shipped 4 major product features in 12 months, supporting multiple product pivots.
    • Ruby on Rails
    • PostgreSQL
    • Redis
    • JavaScript
    • Stimulus
    • AWS
  3. Quantitative Trading Operations · Private Trading Firm

    Built and managed automated hedging across brokers, markets, and instruments

    Mar 2020 — May 2021

    Built and managed automated hedging strategies across multiple brokers, markets, and financial instruments. Risk modeling under adversarial market conditions is the same discipline as fraud detection: spotting anomalies early, capping losses, and acting fast when the numbers move against you.

    • Reduced hedging costs by up to 35% through strategy optimization and execution improvements.
    • Managed a large leveraged portfolio with rigorous risk control and capital efficiency.
    • Self-taught Ruby in parallel during this role, transitioning to engineering by mid-2022.
    • Python
    • C++
    • SQL

Open source

Code I've put in the world.

Libraries I built or maintain. Most live at the intersection of authentication, cryptography, and security tooling for Ruby.

Writing

Notes from the field.

Practical write-ups on the security and authentication problems I've solved in production.

Stack

The tools I reach for.

Ruby on Rails is home, but the job is to pick the right tool. I've shipped production code in everything below.

Languages
  • Ruby
  • JavaScript
  • Python
  • C
  • C++
  • SQL
Backend & Distributed Systems
  • Ruby on Rails
  • Sinatra
  • Hanami
  • Service Architecture
  • REST APIs
  • Async Jobs
  • Caching
  • Rate Limiting
  • Hotwire
Data
  • PostgreSQL
  • Redis
  • Elasticsearch
  • Sidekiq
  • Kafka
Auth & Identity
  • OAuth2
  • OpenID Connect
  • SAML
  • JWT
  • Session-based
  • mTLS
  • WebAuthn
Security & PKI
  • PKI
  • Certificate Lifecycle
  • MPIC
  • X.509
  • TLS
Cryptography
  • Post-Quantum (ML-DSA)
  • Memory-hard Hashing
  • ASN.1/DER
  • Digital Signatures
Fraud & Abuse
  • Fraud Detection
  • Bot Mitigation
  • Device Fingerprinting
  • Behavioral Analytics
  • Account Takeover Prevention
  • Insider Threat Detection
Infrastructure
  • Docker
  • Linux
  • Nginx
  • AWS
  • GitHub Actions
  • Datadog

Contact

Let's build something secure together.

I'm currently open to senior/staff backend, distributed systems, platform, and security engineering roles. The fastest way to reach me is to book a 15-minute intro call. Email and LinkedIn also work.

Download résumé

Choose the variant that matches the role you have in mind.