SURYA.L
sys:nominal IST --:--:--
Staff AI Platform & Cloud Engineer · PayPal 12.97°N 80.22°E · Chennai, India

> I build the control plane for enterprise AI

Thirteen years across cloud, data, and enterprise systems — now focused on agentic enablement at production grade. I design the governed, auditable paths that let teams wire LLMs and agents into backend systems: MCP server frameworks, tool-use SDKs, and the middleware that absorbs identity, data governance, and guardrails.

RoleStaff Engineer · PayPal
FocusAgentic AI · MCP · AIOps
BaseGoogle Cloud · Kubernetes
Uptime13 yrs in production
StatusBuilding in public
Inspect services
Trace — what a governed tool call looks like
trace_id: gov-tool-call live
Agent / LLM Tool-use
MCP Server FastMCP
Federated Identity SAML · OAuth
Guardrails Governance
Enterprise Systems Databases · APIs
agent.request ·········· tool: system_health ·········· RECEIVED
mcp.route ·········· fastmcp runtime ·········· OK
identity.assert ·········· saml → oauth ·········· VERIFIED
guardrail.check ·········· policy: governed-query ·········· PASS
backend.exec ·········· enterprise api ·········· 200
audit.log ·········· full trail persisted ·········· WRITTEN
01 — Service Registry

Platform work,
in production.

01 Governed AI-to-Backend Integration (MCP) MCP · Federated Identity · Enterprise Backends prod

Defined an MCP → federated-identity → enterprise-systems topology, now the org-standard pattern for agentic workloads. First proven across SAP HANA, OData, and SaaS landscapes — cutting new integration build time from weeks to days.

AI Enablement
02 End-to-End MCP Framework & Reusable SDKs FastMCP · Python · SAML / OAuth · Guardrails prod

Shipped an MCP framework with shared SDK libraries that absorb federated auth, query governance, and security guardrails — so consuming teams inherit production-grade safety by default instead of rebuilding it per system. Pioneered the FastMCP runtime in production.

AI Enablement
03 AIOps Agent Fleet LangGraph · n8n · RAG · Vector DBs building

Architecting AIOps across three agentic domains — Monitoring & Alerting (triage, Dataproc/BigQuery monitoring, vulnerability tracking), Operations (change coordination, patch-day automation, system-health analysis), and Knowledge & Query (L1 knowledge and troubleshooting agents).

AIOps
04 Conversational Health-Monitoring Agent LLM Tool-Use · Embeddings · OpenTelemetry prod

Productionized an agent giving SRE and platform teams natural-language access to system health, sessions, and workload analytics on the HANA platform — now the reference implementation other agents are built from.

AIOps
05 FinOps Governance Program BigQuery Slots · GCP CUDs · Rightsizing active

Drove FinOps governance delivering verified, recurring cost savings — BigQuery slot reservations, GCP committed-use discounts, rightsizing, and quota management — with no performance degradation.

Cloud & FinOps
06 Self-Service Platform & Terraform Frameworks Terraform · GKE · CLI Tooling · GitOps prod

Built Terraform provisioning frameworks that eliminated ~80% of manual ClickOps and self-service platforms that offloaded ~70% of L1/L2 tasks — plus CLI-generated, production-ready MCP servers and an interactive docs site that turns one-off builds into a repeatable authoring path.

Platform
07 Real-Time Streaming Platform PySpark · Dataproc · Pub/Sub · BigQuery prod

Architected Apache Spark / Dataproc platforms processing 200M+ events per day — PySpark pipelines over Pub/Sub streaming and batch ingestion at multi-terabyte scale, with GKE-based orchestration and capacity monitoring.

Cloud & Data
02 — Lab · Building in Public

Experiments,
in the open.

Side-of-desk research, run in public — benchmark harnesses, live dashboards, and evals. Code on GitHub, every number reproducible; the write-ups live in the logs.

exp-001 live

mlx-lab — how far can one Mac go?

A benchmark harness for local LLMs on Apple Silicon (MLX): a model ladder from 3B to 123B on a 128GB M5 Max — decode, TTFT, the real memory ceiling (spoiler: not where Apple says), and the 14-inch thermal tax. Live dashboard, every number reproducible from the repo.

MLX · Apple Silicon · Local LLM · Benchmarks
exp-002 queued

Local tool-routing eval

Next in the series: can a local model pick the right tool for an operations alert? The number that actually matters for autonomous ops — eval design in progress, same build-in-public rules.

Local LLM · Tool-Use · AIOps Evals
exp-003 beta

Resident agent — a real LLM in your browser

The little bot in the corner of this page. Scripted telemetry by default — but click load real brain and it boots a ~0.6B local model on your own GPU via WebGPU. No server, no API key, nothing leaves your machine.

WebLLM · WebGPU · Local LLM · This Very Site
exp-004 live

MCP access to a database — as the user, not a service account

This site's thesis as a runnable lab: an AI agent reaches a Postgres banking database carrying the end user's verified identity — not a shared service account — with authentication, authorization, and audit enforced at the data source. Role-based PII masking, per-tool RBAC, and a Postgres-18 path where the database itself denies unauthorized columns.

MCP · OIDC · Keycloak · PostgreSQL · OAUTHBEARER · Audit
More on GitHub ↗
03 — Subsystems

What I work in,
concretely.

A

AI & Agentic

The platform layer for agentic workloads — governed, auditable, and reusable across teams.

  • Model Context Protocol (MCP)
  • FastMCP
  • LLM Tool-Use Frameworks
  • LangGraph
  • n8n
  • RAG & Vector DBs
  • Guardrail / Policy Design
B

Cloud & DevOps

Multi-cloud platforms with a deep Google Cloud foundation — provisioned, shipped, and operated as code.

  • Google Cloud (GCP)
  • AWS & Azure
  • Kubernetes & GKE
  • Terraform & Ansible
  • CI/CD · Jenkins · Harness
  • Linux · Git · GitOps
  • FinOps Governance
C

Data & Streaming

Big-data platforms supporting streaming and batch ingestion at multi-terabyte scale.

  • Apache Spark
  • Dataproc
  • BigQuery
  • Pub/Sub
  • Apache NiFi
  • SAP HANA
D

Reliability & Security

Observability, chaos engineering, and InfoSec collaboration for audit-ready systems.

  • OpenTelemetry & Prometheus
  • Cloud Monitoring · Datadog
  • Chaos Engineering · MTTR
  • IAM · SAML / SSO / MFA · OAuth
  • DLP · TLS · Vuln Management
  • SOX · PCI-DSS Audit Readiness
Daily Tooling
mcp google-cloud kubernetes terraform docker helm sap spark datadog prometheus grafana opentelemetry python ansible github-actions jenkins harness
04 — Uptime Log

Thirteen years,
one through-line.

  1. 2017 — now

    PayPal

    Staff System & Cloud Engineer

    Leading AI & agentic platform engineering (MCP) and AIOps — plus large-scale GCP migrations, Spark/Dataproc data platforms, FinOps governance, and SRE.

  2. 2015 — 2017

    DXC Technologies (formerly CSC India)

    Application Delivery Engineer

    Ansible-based automation for patch management; SAP/Linux hardening for audit mandates; HA/DR with Pacemaker and SAP HANA clusters for Fortune 500 clients.

  3. 2012 — 2015

    Wipro Technologies

    Senior Project Engineer

    System automation and DR setups for global SAP clients; contributed to the HANA Center of Excellence on performance tuning and migration assessments.

Certifications

  • Google CloudProfessional Cloud Architect
  • Google CloudProfessional Cloud Network Engineer
  • Google CloudProfessional Cloud DevOps Engineer
  • Google CloudAssociate Cloud Engineer
  • CNCFCertified Kubernetes Administrator (CKA)
  • HashiCorpTerraform Associate
  • Red HatCertified Engineer (RHCE) & RHCSA
  • SAPHANA DBA & Integration Developer
06 — Open Channel

Always up for a
good systems conversation.

If you're working on agentic platforms, MCP, or AIOps — or just want to compare notes — say hello. Email is the surest way to reach me.

suryal.k90@gmail.com