Senior Software & Security Engineer with 8+ years designing resilient APIs, hardening infrastructure, and architecting data systems at scale — from Oracle-backed cores to modern Node.js services.
I'm Dhali Abir — a senior engineer who spends most days moving between two roles: building the backend systems a product runs on, and making sure they hold up under real-world pressure. Over 8+ years I've shipped REST APIs and service architectures for fintech and healthcare platforms, led Oracle database migrations with zero downtime, and run security reviews that caught what automated scanners missed.
I care about systems that are boring in the best way: predictable under load, clear to reason about, and hard to compromise. That means writing SQL that scales past the demo, designing APIs other teams actually enjoy integrating with, and treating security as a design constraint from day one — not a checklist bolted on before launch.
Robust, well-tested services built on Node.js — from clean domain models to background jobs that don't quietly fail.
Threat modeling, secure code review, and remediation — reducing real attack surface, not just findings on a report.
Architecture that scales on paper and in production — capacity planning, failure modes, and clear trade-off documentation.
Schema design, query tuning, and zero-downtime migrations for systems where the database is the bottleneck no one sees coming.
Predictable, versioned, well-documented APIs — designed for the teams that have to integrate with them six months from now.
An outside senior eye on your architecture, your data layer, or your incident post-mortems — before small issues compound.
Rebuilt a legacy payments API with a zero-trust security model and full audit trail.
Designed an event-driven order system handling regional failover with sub-second recovery.
Led a zero-downtime migration of a 40TB Oracle estate for a healthcare records provider.
Built a company-wide secure-SDLC program: threat modeling, SAST/DAST pipelines, and training.
Designed and shipped a versioned partner API now used by 60+ integrators, with rate-limiting and keys.
Rewrote core reporting queries and indexing strategy, cutting P95 latency on a 2B-row Oracle table.
A look at how point-in-time testing misses the security issues that actually get exploited.
Practical lessons from tuning Oracle tables well past the point where "just add an index" stops working.
Versioning, error shapes, and documentation habits that save the next engineer a bad afternoon.
What actually separates a strong answer from a memorized framework, after running 100+ interviews.