Pedram Khoshnevis

Full-Stack Engineer · Building Audit-Ready Systems

Full-Stack Engineer specializing in building compliance-grade, audit-ready systems in regulated environments.

At Morgan Stanley and previously with the Government of Canada (CRA), I contribute to secure, high-availability platforms where auditability, traceability, data integrity, and regulatory compliance are critical.

My work focuses on:

  • Designing systems with clear data lineage
  • Structuring applications for audit transparency
  • Building secure cloud-based infrastructure
  • Implementing automated testing for reliability
  • Ensuring production stability in high-risk environments

I am currently exploring how structured software design can simplify audit-readiness for small and medium-sized businesses.

If you work in accounting, audit, or compliance and are open to sharing insights, I welcome thoughtful conversations.

Email pedramkhoshnevis@gmail.com

Address Montréal, Québec, Canada

Social

pedram khoshnevis portfolio

Programming Languages

Java, JavaScript/TypeScript, Python, SQL — applied in regulated, compliance-sensitive environments.


Frameworks & Architecture

Angular, Spring Boot, Laravel, Node.js — structured for traceability, maintainability, and audit transparency.


Database & Data Integrity

MySQL (ACID compliance), NoSQL (MongoDB), ORM design, migration & seeding — ensuring data consistency and audit-ready state management.


Cloud & Infrastructure

AWS (EC2, Route 53, Elastic Beanstalk, Elasticsearch), CloudFormation — secure cloud architecture with CI/CD governance via GitHub and Jenkins.


Testing & Production Stability

Automated testing (Cypress, Playwright), unit & integration testing, TDD — continuous validation for production monitoring and reliability.


Security & Access Control

SSL/TLS, password hashing (salt, pepper), CSRF protection, encrypted cookies, secure session handling, audit logging — designed for regulatory compliance.

Auditability

Log trails, traceable state changes, and structured event histories — ensuring every action can be reviewed and verified.


Data Integrity

ACID-compliant transactions, validated inputs, consistent data models — protecting accuracy across the entire system lifecycle.


Role-Based Access Control

Granular permission models, role separation, and least-privilege principles — restricting access to sensitive operations and data.


Secure Authentication

Encrypted session management, token-based auth, identity verification — building trust at the authentication layer.


Regulatory Documentation Support

Structured system documentation, clear data lineage, and reproducible workflows — supporting audit and compliance review processes.


Production Resilience

Continuous monitoring, automated testing pipelines, failover strategies — maintaining uptime in high-stakes, regulated production environments.

Full-Stack Developer — Risk & Compliance Platform

Morgan Stanley – Montréal, CA

April 2025 – Present

  • Develop and maintain Angular-based front-end applications for the firm's Risk and Compliance Monitoring (RCM) platform used by internal brokers and control teams.
  • Build and maintain Java/Spring Boot backend services with emphasis on platform reliability, stability, and continuous availability in a regulated financial environment.
  • Handle end-to-end feature implementation including requirement discussions, API development, data modeling, and production issue investigation.
  • Contribute to CI/CD governance pipelines using GitHub and Jenkins, ensuring secure and auditable deployment processes.
  • Ensure quality and production resilience through automated testing with Cypress and Playwright.
  • Coordinate with stakeholders to drive secure, compliant, and dependable releases.

Full-Stack Developer — Secure Government Platform

Federal Government of Canada (CRA) – Ottawa, CA

May 2021 – March 2025

  • Developed and maintained two Angular applications integrated with Amazon Connect API for the CRA Online Chat project, serving over 10 million conversations.
  • Designed and implemented the Agent Interface and the taxpayer-facing Chat Widget with strict security and privacy requirements.
  • Led the development of an Authenticated Online Chat feature with SIN-based identity verification, ensuring regulatory compliance for sensitive taxpayer data.
  • Implemented Python-based AWS Lambda functions for real-time data processing with audit-ready logging.
  • Worked extensively with AWS cloud services to support scalable, secure, and compliant applications.
  • Served as Team Lead and Scrum Master, coordinating secure deployment processes across the team.

Full-Stack Developer & Applied AI Engineer

DaTALab – Lakehead University

May 2019 – May 2021

  • Developed an AI-powered text-simplification platform using Python and NLP to enhance document accessibility for the CRA.
  • Built a predictive analytics platform using deep learning models for resource forecasting and data-driven decision support.
  • Designed and implemented full-stack applications with structured data pipelines for government-backed research projects.
  • Published five peer-reviewed research papers on applied AI methods and data modeling.
  • Created a React Native mobile application published on App Store and Google Play.

Full-Stack Developer — Cloud Infrastructure Platform

Apposha.io

Jan 2017 – Feb 2019

  • Developed a cloud-based database-as-a-service (DBaaS) platform with emphasis on data integrity, atomicity, and consistency.
  • Optimized MySQL performance and built scalable, secure back-end systems handling multi-tenant data isolation.
  • Architected infrastructure using AWS Elastic Beanstalk, Elasticsearch, and CloudFormation.
  • Contributed to securing $600,000 in venture capital and government startup funding.

IT Director & CTO

UBU Today (Non-Profit)

Jan 2014 – Present

  • Manage website development and IT infrastructure for a federally registered non-profit organization.
  • Acquired federal grants to support digital outreach and operational technology.
  • Implemented secure, accessible, and compliant web solutions.

Independent Full-Stack Engineer

WebPrinciples.com

Jan 2014 – Present

  • Designed and developed web applications for businesses and organizations with focus on reliability and security.
  • Integrated APIs and built scalable, standards-compliant systems.
  • Ensured projects followed W3C standards and accessibility compliance.

Master of Computer Science

Lakehead University, Ontario, Canada.

Specialized in Artificial Intelligence

May, 2019 – May, 2021

Conducted extensive research in regards to implementing methods of computational intelligence that help mitigate problems faced in the social sector.

Recipient of multiple scholarships.


Master of Computer Science

University of Seoul

Specialized in Computer Networking

Mar, 2013 – Mar, 2015

Studying at the university gave me extensive experience and understanding of engineering documentation as well as becoming a Full Stack developer.

Honors in General Scholarship. GPA 95%.


Bachelor of Computer Science

University Science Malaysia

Jan, 2005 — May, 2009

My studies in Computer Science with a Minor in Management has familiarized me with Customer Relationship Management (CRM), Enterprise Resource Planning (ERP) systems, Project Management, and Business Analysis. My degree gave me excellent overall working knowledge of many aspects of Computer Science and Information Technology (IT). This includes software, hardware, networking, distributed systems, and desktop support.

Portfolio

Comparison of Moderated and Unmoderated Remote Usability Sessions for an AI-Supported Simulation and Modeling Software

24th HCI International Conference, HCII 2022


Design, Development and Usability Evaluation of a Web-based AI-supported Simulation And Modeling Software

Journal Informatics for Health and Social Care, 2021


Role of Computational Intelligence and IoT in Smart Cities

IEEE Internet of Things Magazine, 2021


Smart City Response to Homelessness

IEEE Access, 2020


Aerial Canopy Data from UAVs for Measuring Neighbourhood Competition Effects

Elsevier: Forest Ecology and Management, 2020


An Adaptive Network Coding Scheme for Unreliable Multi-hop Wireless Networks

International Conference on Big Data and Smart Computing (BigComp), 2016

Competitions

Interested in discussing audit-readiness software

If you work in accounting, audit, compliance, or regulated industries and would like to explore how structured software design can support audit-readiness — I welcome professional inquiries.

Email pedramkhoshnevis@gmail.com