Resume

Samuel Kaoma

Software Engineer

Lusaka, Zambia

0762112817

samuelkaomaa@gmail.com

github.com/Samuelkaoma

Professional Summary

Final-year Computer Science student at the University of Zambia, currently building a universal SaaS platform at AVEC Technologies. The work in this archive spans a sovereign real-time gross settlement platform, a calibrated forensic linkage engine, a regulatory compliance and generative design engine, a production Go/PostgreSQL commercial suite, and national infrastructure monitoring — across Go, Java 21, Python, and TypeScript. Every figure quoted here is measured by a run, not taken from a README.

Experience

Software Engineer

AVEC Technologies

March 1, 2026 - Present

Building a universal multi-tenant SaaS platform for Zambian parastatal bodies, government agencies, and higher-learning institutions — middleware-driven tenant scoping, role-and-permission RBAC with per-user overrides, audit logging, and workflow automation.

Built the clinical, pharmacy, billing, and onboarding modules of IntelliHealth, a multi-tenant hospital platform on a Go/Echo/PostgreSQL service layer with a React 19 operator front end, working alongside a colleague who owned the tenant-provisioning plane.

Own end-to-end delivery: domain modelling, API contracts, schema migrations, front-end implementation, and production deployment for low-bandwidth institutional users.

ICT Intern - e-Government Division

Smart Zambia Institute (Office of the President)

November 2025 - February 2026

Completed an ICT internship with direct exposure to enterprise government infrastructure, systems development, networking, planning workflows, ICT support, and confidential operational handling.

Formally attached to the Office Equipment and Maintenance Services Unit at national headquarters.

Rotated through Systems Development, Networking, and Planning while handling sensitive technical data with care.

Selected Projects

SKACE Settlement Platform

Sovereign Real-Time Gross Settlement | 79 of 79 features passing

2026

A national payment-system settlement core built around the Bangladesh Bank failure mode: above a value threshold, funds move only when t independent authorisers have each signed that specific transfer — so a compromised endpoint yields one signature and settles nothing.

Implemented the core as a single-writer deterministic state machine — no wall-clock reads, no floating-point money, no order-dependent map iteration — making event-sourced replay byte-reproducible; all three prohibitions are enforced by architecture tests rather than convention.

Delivered an ISO 20022 participant gateway over mTLS with idempotency and signature verification, a multi-tenant React bank portal with in-browser Merkle inclusion and consistency proofs, and a C#/WPF operator console with two-person emergency suspension.

Backed 79 delivered features with a measured 1,059 core tests and 74 portal tests — zero failures, zero skips — plus 280 mutation probes. Each probe edits one production line and requires the suite to fail; surviving probes exposed an entirely untested browser session layer and a gridlock-resolution path that bypassed the settlement check.

Java 21C# / .NET 8ReactTypeScriptC (PKCS#11)PostgreSQLISO 20022mTLS

VIFLAP

Calibrated Forensic Evidence Fusion | Doctoral research artefact

2026

A case-linkage engine that reports how much the available evidence shifts the odds that two incidents share an actor — as a calibrated likelihood ratio that always carries its prior, and with no vocabulary for asserting identity.

Implemented the full speaker-evidence stack from first principles — GMM-UBM by EM, i-vector total-variability extraction, LDA/WCCN, and two-covariance PLDA with the exact closed-form log-likelihood ratio — against NumPy and SciPy alone, with no deep-learning framework required. A borrowed pre-trained extractor sits behind an optional dependency and an architecture boundary, benchmarked against the reference stack rather than replacing it.

Built the DSP front end (MFCC/LFCC, VAD, LPC formant estimation, YIN pitch tracking, jitter/shimmer/HNR), an analysis-by-synthesis CELP narrowband channel model, and an LFCC/GMM spoofing countermeasure with an explicit out-of-domain indicator.

Encoded three guarantees in the type system: absence carries its reason instead of collapsing to LR = 1, a likelihood ratio cannot exist without an explicit justified prior, and uncalibrated scores are unreportable. A build-time check fails if the vocabulary of identification appears in any emittable string.

PythonNumPySciPyHypothesisFastAPI

Arcus Investments Platform

Production B2B Commercial Suite | Built and deployed to Railway

2026

A two-product platform on one identity and permission system: a training and admissions pipeline, and a full commercial CRM running leads to deals to quotations to contracts to payments — with document versioning, contract signing, an aged debtor book, and value-based approval controls.

Extended it through the buy side — sourcing, purchase orders, goods receipt, landed-cost allocation and per-deal margin — over a stock ledger with transaction-scoped, self-rolling-back database tests.

Secured sessions with JWT access tokens plus rotating refresh tokens in httpOnly cookies, pluggable S3-compatible storage, and per-route permission enforcement documented route by route.

Diagnosed a silent-CI class of failure and reproduced it on demand: without DATABASE_URL, 69 of 145 tests skip while all seven packages still report ok and the command exits 0 — precisely the approvals, stock-ledger, landed-cost and payables tests. CI sets the variable, so CI has always run the full suite; it is local runs that quietly do not.

GoEchoGORMPostgreSQLReact 19TypeScriptViteDockerRailway

SKACE Architect

Compliance and Generative Design Engine | Doctoral research artefact

2026

A compliance engine that turns Zambian building regulation into executable rules and returns a citation-carrying, byte-reproducible verdict — then generates layouts against those same rules and re-judges every candidate before offering it.

Made provenance a type invariant: a GroundedValue cannot be constructed without a ValueOrigin, so no verdict can rest on an unscaled or unsourced measurement, and a customary boundary cannot support a violation asserted inside its own positional error.

Compiled applicable rules plus a household brief into CP-SAT constraints that each carry the rule that produced them, then re-judged every generated layout with the compliance engine — which caught the solver placing buildings on the very setback they were generated to satisfy.

Designed the orchestration grounding layer so a language model cannot originate a number: tools return registered value references, the facade refuses raw numeric arguments, and a validator rejects any draft containing a numeral the session never obtained.

PythonGoogle OR-Tools CP-SATShapelypytest

IntelliHealth

Multi-Tenant Clinical and Pharmacy Platform | Shipped at AVEC Technologies — team build

2026

A tenant-scoped hospital operations platform covering patient records, visit queues with triage priority, clinical diagnosis capture, ICD-10 and CPT coding lookups, WHO benchmarking, pharmacy stock, and invoicing.

Built the pharmacy and revenue side: stock receipt and adjustment ledgers, dispensation history, low-stock and expiry alerting, FDA drug lookup, drug-interaction checking, and invoice finalisation into a billing cycle.

Built the tenant onboarding lifecycle on top of a colleague's ControlHub provisioning plane — document submission with timeline tracking, activation emails, admin setup links, and the admin review flow — over middleware-enforced tenant scoping. It is the only module in the codebase carrying its own tests.

Layered RBAC with per-user permission overrides and audit logging on every state change, with a React 19 operator front end over the Go/Echo service layer.

GoEchoPostgreSQLJWTReact 19TypeScriptViteTailwind CSS

SmartFarmer SKACE

Multi-tenant Agritech Trust Platform | Flagship build

2026

The heaviest build in the archive — a multi-tenant platform that turns everyday Zambian farm activity into evidence a lender can trust: GPS-verified attendance, cadastre-verified location, and satellite-verified crop growth, folded into a cryptographically signed farm track record and transparent credit score.

Built as four cooperating services in one repo — a Go/Echo API, a React + Vite dashboard, an Expo mobile app for field workers, and a Python/XGBoost yield-prediction service.

Verifies farm claims against independent, hard-to-fake sources: Sentinel-2 NDVI (Copernicus), the ZNSDI cadastral geoportal, and GPS geofencing — surfaced as a signed, QR-verifiable lender report.

Enforces tenant isolation at two layers — request-scoped middleware plus PostgreSQL Row-Level Security that fails closed — with Go, Vitest, and Python test suites all passing.

GoEchoPostgreSQLReactExpoPythonXGBoost

Education

Bachelor of Science in Computer Science

University of Zambia

Expected Graduation: 2026

Relevant coursework: Data Structures and Algorithms, Database Systems, Operating Systems, Computer Networks, Software Engineering, Numerical Analysis, and Discrete Structures.

Skills and Certifications

Languages

Go, Java 21, Python, TypeScript, JavaScript, C#, C, SQL

Backend and APIs

Echo, FastAPI, Node.js, Express, NestJS, GORM, REST design, ISO 20022

Frontend

React 19, Next.js, Vite, Tailwind CSS, Radix UI, Framer Motion

Data and Storage

PostgreSQL, Row-Level Security, InfluxDB, MySQL, Supabase, Prisma, Drizzle ORM, Alembic

Architecture

Event sourcing, Hexagonal / ports and adapters, Multi-tenancy, Deterministic state machines, Monorepos

Security

mTLS, PKCS#11 / HSM, Threshold signatures, Merkle transparency logs, JWT with rotating refresh, RBAC, Hash-chained audit

ML and Numerics

scikit-learn, XGBoost, NumPy, SciPy, Pandas, GMM / i-vector / PLDA, Calibration, CP-SAT

Verification

Mutation probes, Property-based testing, Architecture tests, pytest, Vitest, Go test, JUnit

Infrastructure

Docker, Docker Compose, Nginx, Railway, GitHub Actions, Linux, Git

Networking

TCP/IP, OSI model, Routing and switching, CCNA

Certifications

Cisco Linux Program

Cisco IT Essentials

CCNA