Identity and Java engineering, AI‑assisted, part-time.

A senior engineer with 12+ years on Java systems, the last five in identity and access management, for 15–20 hours a week, more by arrangement. I do most of my work with AI coding agents, Claude Code and Codex. They draft; I design, review and own what ships.

{  "iss": "delmisoft.hr",  "sub": "Ante Radoš",  "roles": [    "ai-assisted-iam",    "ai-assisted-engineering"  ],  "stack": "keycloak openfga java spring-boot",  "agents": "claude-code codex",  "availability": "15–20 h/week, more by arrangement",  "available_from": "now",  "timezone": "CET, flexible for US hours"}
Availability, written as an ID token.

Two ways to work with me

  • AI-assisted IAM

    Identity security reviews, CIAM platforms on Keycloak, migrations off legacy identity providers, Okta or Auth0, custom Keycloak extensions, authorization on OpenFGA, and identity for AI agents and MCP servers.

    Fits when the identity layer was bolted on and is now the bottleneck, or AI agents are about to touch real customer data.

    Identity in detail

  • AI-assisted engineering and architecture

    Hands-on Java and Spring Boot work in your codebase, legacy modernisation, AI-assisted development set up for your team, AI features in your product, and architecture assessments documented to the standards (ISO/IEC/IEEE 42010, arc42, C4, decision records).

    Fits when the team has more work than people, or a large change is coming.

    Engineering in detail

How the AI part works

The same in both offers.

Where I use it
A telecom operator’s customer identity platform, in a major Keycloak migration now in testing: data and session migration scripts, test suites and the new proxy. A SaaS company’s identity application, APIs and OpenFGA model. A Norwegian ERP software company, where I set up the team’s Claude Code workflow. And keycloak-otp, where 25 of 44 commits are co-authored with Claude Code.
What the agents do
Draft code, tests, Keycloak configuration, migration scripts and Java extensions. Read an unfamiliar codebase quickly. Draft decision records, arc42 sections and C4 diagrams. Give a first-pass review of code and designs.
What stays with me
Design and security decisions, a line-by-line review of everything that ships, and responsibility for the result.
Guardrails
Tests with every change, static analysis and dependency scanning in CI, small pull requests.
Your rules
I follow your policy on which tools may see your code, use your approved accounts where you have them, and work without agents where you ask. Secrets and real user data stay out of prompts.

What it produced

Clients are anonymised. Three engagements in full.

Under 5 minutes
of user-facing downtime on each of three major Keycloak upgrades.Web platform operator, several hundred sites
10,000+ users
moved from in-house authentication to Keycloak with no planned downtime.SaaS company
3 services
extracted from a monolith over 6–12 months, with no planned downtime.SaaS company
15 days to 25 minutes
for one business process, after automating it.Telecom operator
Around 10–15%
less cloud spend, from rightsizing and optimising applications and data processing.SaaS company

How I work

Time and materials, or a fixed-scope project. Fifteen to twenty hours a week, more by arrangement, remote from Zagreb, with flexible overlap for North American hours.

DelmiSoft is a Croatian business and invoices in EUR. Cross-border B2B invoices use EU reverse charge. Rates on request.

Claude Code, Codex, Java, Spring Boot, PostgreSQL, Kafka, RabbitMQ, Camunda / BPMN, Docker, Kubernetes, AWS, GCP, Keycloak (including custom SPIs), Okta, Auth0, OIDC, OAuth 2.0, SAML 2.0, SCIM, FIDO2 / WebAuthn, token exchange, OpenFGA.

Send a short description of the problem and the timeline.

[email protected]

Or find me on LinkedIn.