
Douglas Okolaa
Senior Software Engineer
I have spent seven years responsible for production systems, and the responsibility has kept moving. First building them. Then operating them. Then being the name on the escalation path when they broke, on platforms carrying ISO, GDPR, NDPR, SOC 2 and CASA obligations. Now I maintain a package that other people put in production, which is the same responsibility pointed the other way.
That last step is where most of my attention goes at the moment: the integrity of what ships. Bills of materials, signing and provenance, and a vulnerability process a downstream vendor can actually rely on. From September 2026 the EU Cyber Resilience Act puts commercial vendors on a reporting clock and requires machine-readable bills of materials for what they put on the market. The regulation is indifferent to language. The work is the same shape wherever the dependencies come from, and most teams have not started.
I have not stopped doing the rest. I still take the tier-3 seat, still open the production traces that bounce off everyone else, still write the fix and the short note that keeps it from recurring. The supply-chain work is not a change of career. It is what you end up caring about after enough years of being the person who gets called.
How I work
- I draw the boundaries before I write the code. Where the data lives, what crosses the network, what fails first under load, what the rollback looks like. That hour pays for itself every time.
- I own the thing end to end. Design, build, deploy, monitoring, and the awkward conversation when scope is slipping. I do not hand off and hope.
- I treat compliance as design, not paperwork. Regulatory constraints are just constraints. They are easier to satisfy in the architecture than to bolt on at the end, and I have shipped under enough regimes to know which is which.
- I say what a thing does not do. The limits are the useful part of any technical claim. If I sign an artifact and the package manager still will not verify it, that goes in the documentation.
Some evidence
- Named tier-3 escalation engineer on a regulated SaaS platform, through dozens of critical production incidents.
- Cut average support response time from twelve hours to seven by fixing recurring bugs in the code rather than in the tickets.
- Linux fleets provisioned and hardened behind high-traffic applications, holding 99.9% uptime.
- Provisioning and backup automation that removed roughly 60% of the manual maintenance load from the team.
- Maintainer of an open-source package other teams run in production, around 1,650 installs, now publishing a CycloneDX SBOM, SLSA provenance and Sigstore signatures on every release.
If you are hiring for senior engineering, a serious tier-3 seat, or someone to get your supply chain into a state your customers can audit,let's talk.