Skip to content
AB

Open to senior & lead engineering roles

Amin Bakhtvar

Telecommunications & Cloud Engineer

Technical Lead — eSIM, Digital Identity & Secure Platforms

I build the secure infrastructure behind connectivity and digital identity — from the applet running inside a secure element to the cloud platform that provisions millions of them.

10+
Years in telecom & cloud engineering
4M+
Subscribers served by platforms I designed
8
GSMA specifications implemented in production
AWS
Certified Developer — Associate

Expertise

Depth across the whole stack, not just the top of it

More than a decade of engineering across the full depth of the mobile ecosystem: smart card and eUICC firmware at one end, distributed cloud platforms at the other, and the GSMA standards that hold the two together.

I lead cross-functional and vendor teams, take ownership of platforms end to end, and translate dense specification work into systems that operators can actually run in production — secure by construction, observable, and built to scale.

eSIM, eUICC & Secure Elements

Deep, specification-level command of remote SIM provisioning across both the consumer and M2M/IoT architectures.

  • GSMA SGP.01/.02/.21/.22/.26/.31/.32 and TCA IPP implemented against real operator deployments
  • SM-DP+, SM-SR and LPA work across the ES2+, ES8+, ES9+ and ES10 interfaces
  • Profile generation, IPP customisation and interoperability resolution down to modem-level behaviour
  • Java Card and S@T applets, ISO 7816 / ISO 14443, proactive commands and Class-2 SMS structures

Cloud Architecture on AWS

Serverless and event-driven platforms designed for regulated, high-availability telecom workloads.

  • Lambda, API Gateway, ECS/Fargate, RDS, DynamoDB, SQS, Athena, Glue, DMS and Organizations
  • Infrastructure as code with AWS CDK, SAM, CloudFormation and Terraform
  • Multi-account landing zones, least-privilege boundaries and cost-aware service selection
  • Migration of legacy on-premise telecom services into managed cloud equivalents

Backend & Distributed Systems

Production services in Java and Go, built around durable messaging and clear domain boundaries.

  • Java with the Spring ecosystem, and Go for high-throughput provisioning services
  • Asynchronous architectures over Kafka, RabbitMQ, ActiveMQ, JMS and SQS
  • REST API design and secure exposure of legacy interfaces to modern consumers
  • Relational and key-value persistence: MySQL, Oracle, DynamoDB, H2

Security, Identity & Cryptography

Access control, federation and secure interconnect designed into the platform rather than bolted on.

  • Role-based access control spanning BSS, entitlement and provisioning endpoints via Keycloak
  • OIDC federation across multiple identity issuers, including enterprise authenticator estates
  • IPsec / IKE site-to-site tunnels for secure operator interconnect
  • Applied cryptography, PKI and key management; mandatory access control with SELinux and AppArmor

Product-Grade Frontend

Operator-facing consoles that make complex provisioning state legible and safe to act on.

  • Next.js and React with TypeScript; Angular for data-dense administrative interfaces
  • Operator portals for activation monitoring, profile transfer, shop and user management
  • Audit views and digital trails built for compliance review, not just for display
  • Native Android clients in Java, using MVVM, Dagger and RxJava

Systems, Embedded & Tooling

Comfortable well below the application layer, where telecom problems usually turn out to live.

  • Custom Linux distributions with the Yocto Project and Buildroot for ARM SoC targets
  • Java Card virtual machine implementation in C and Java
  • Container orchestration with Kubernetes and Docker Swarm; CI with GitLab CI
  • Quality gates with SonarQube, JUnit, Mockito and contract-level API testing

Selected work

Platforms in production, described by what they do

Client and employer names are withheld by preference. What follows is the substance of the engagement: the problem, the architecture, and the part I owned.

  1. 01

    Remote SIM provisioning at operator-group scale

    eSIM Provisioning Platform for Tier-1 Operator Groups

    Delivered the integration between operator business support systems and SM-DP+ platforms over the ES2+ interface, enabling commercial eSIM activation across multiple national markets in Europe and Latin America.

    • GSMA ES2+
    • SM-DP+
    • Entitlement
    • AWS
    • Go

    What I owned

    • Integrated third-party and in-house SM-DP+ platforms behind a consistent ES2+ contract
    • Contributed to device entitlement protocol integration for carrier-managed activation
    • Automated and customised download-order creation to shorten profile installation and delivery
    • Led an external engineering team delivering an eSIM profile generation toolchain
  2. 02

    Commercial operations console

    Operator Portal for eSIM Lifecycle Management

    A management console giving operator staff full visibility and control over eSIM activation, profile transfer, retail channel and user administration — with an audit trail designed to survive compliance review.

    • Next.js
    • TypeScript
    • Keycloak
    • Lambda
    • API Gateway

    What I owned

    • Built the interface in Next.js with TypeScript over a serverless backend
    • Modelled a role-based permission system covering every privileged operation
    • Surfaced activation and transfer state as an operational timeline rather than raw records
    • Integrated push and SMS notification channels into the activation journey
  3. 03

    Over four million subscribers, countrywide

    Nationwide SIM OTA & Key Management Platform

    Designed, built and deployed a remote file management and key management platform operating across a national subscriber base, including steering-of-roaming capability and the surrounding SIM lifecycle tooling.

    • SIM OTA
    • Java Card
    • Key Management
    • Steering of Roaming

    What I owned

    • Owned the platform end to end, from applet behaviour to server-side orchestration
    • Delivered steering-of-roaming as a live commercial capability
    • Maintained the operator's USIM lifecycle and authored technical requirements for procurement
    • Advised virtual operators on SIM strategy and integration
  4. 04

    Local Profile Assistant across shipping devices

    Consumer eSIM Client & Device Integration

    Built and shipped a Local Profile Assistant integrated into consumer handsets and AI wearables, plus the diagnostic tooling used to resolve interoperability defects between the device stack and the eUICC.

    • SGP.22
    • Android
    • LPA
    • eUICC
    • Interoperability

    What I owned

    • Implemented the SGP.22 client-side interfaces and OEM integration surface
    • Traced live device-to-network signalling to isolate LPA and modem-level faults
    • Determined minimum viable profile configurations for specific cellular modems
    • Produced an eUICC validation application used by a semiconductor manufacturer
  5. 05

    Regulated remote customer acquisition

    Digital Onboarding with Identity Verification

    A mobile onboarding journey backed by a serverless function estate, integrating third-party electronic identity verification so customers could be enrolled remotely without compromising regulatory obligations.

    • eKYC
    • Android
    • AWS Lambda
    • Serverless

    What I owned

    • Composed multiple eKYC providers behind a single verification abstraction
    • Built the native Android client and its supporting AWS Lambda backend
    • Designed the failure and retry paths that dominate real-world onboarding funnels
  6. 06

    Cross-organisation platform security

    Zero-Trust Access & Secure Interconnect

    Established the authentication, authorisation and network-layer trust model connecting operator business systems to provisioning and entitlement infrastructure.

    • Keycloak
    • OIDC
    • RBAC
    • IPsec
    • StrongSwan

    What I owned

    • Designed and deployed RBAC infrastructure spanning BSS, entitlement and SM-DP+ endpoints
    • Implemented OIDC integration and adapted the auth flow for multiple federated issuers
    • Configured IPsec VPN tunnels for secure business-system communication

Approach

How I lead, and what I hold myself to

Specifications are only half the job. The other half is the team, the review culture and the decisions that keep a platform maintainable long after the launch.

Team leadership

Lead cross-functional cloud and platform teams, and direct external engineering partners against a delivery contract rather than a task list.

Codebase ownership

Brought an outsourced platform codebase in-house — assessed it, absorbed it, and turned it into something a team could confidently extend.

Standards & procurement

Author technical requirements for tenders, evaluate vendor responses, and advise partner operators on architecture and integration strategy.

Mentoring & quality

Set the engineering bar through review, testing discipline and static analysis gates — because a platform is only as durable as the habits around it.

Toolkit

The technologies I reach for

Tools are chosen for the problem, never for the résumé. This is what I have run in production long enough to know the sharp edges.

Languages
Java Go TypeScript JavaScript C Java Card
Frameworks
Spring Next.js React Angular Android
Cloud & IaC
AWS CDK SAM CloudFormation Terraform Kubernetes Docker
Data
MySQL Oracle DynamoDB H2 Athena Glue
Messaging
Kafka RabbitMQ ActiveMQ SQS JMS
Standards
GSMA SGP.21/.22 GSMA SGP.31/.32 TCA IPP ISO 7816 ISO 14443 UMTS AKA Diameter SMPP SIP OIDC IPsec / IKE
Security
Keycloak PKI & EJBCA SELinux AppArmor StrongSwan Hardware security
Quality
SonarQube JUnit Mockito GitLab CI Postman Bruno

Credentials

  • AWS Certified Developer — Associate

    Amazon Web Services

  • M.Sc. Telecommunications — Cryptography

    Malek Ashtar University of Technology

  • B.Sc. Engineering

    Islamic Azad University, Najafabad

Languages

  • English Fluent
  • Persian Native
  • Spanish Proficient

Contact

Let's talk about what you're building.

Whether it's remote SIM provisioning, a cloud platform that has outgrown its architecture, or a team that needs a technical lead — I'd be glad to hear about it.