● Open to AI Architect / Staff+ Engineering roles

Sudipta Aich

AI Architect  ·  Generative AI & RAG Systems  ·  Secure Enterprise Architecture

17+ years architecting secure, large-scale enterprise systems, and 2+ years building production Generative AI platforms — RAG pipelines, MCP servers, and AI agent integrations — for regulated financial services. I bring security and compliance rigor to applied AI system design.

17+Years Engineering
2+Years in GenAI / RAG
4Fortune-100 Employers
2Certifications
About

Bridging enterprise security and applied AI

I'm an AI Architect and engineering leader with a background most GenAI builders don't have: nearly two decades designing identity, authentication, and API security systems for regulated financial institutions (U.S. Bank, JPMorgan Chase, FedEx, Citi). Over the last two years I've applied that same architectural discipline to Generative AI — designing Retrieval-Augmented Generation pipelines, MCP servers, and AI agent integrations that are grounded, auditable, and safe to run against sensitive enterprise data.

I partner closely with product, security, compliance, and architecture stakeholders to ship platforms that are both intelligent and enterprise-safe — favoring reusable, versioned, well-governed building blocks over one-off solutions.

RAG Architecture MCP Servers Anthropic Claude OpenAI CIAM / OAuth2 / OIDC Enterprise Architecture Spring Boot / Java AWS / Azure

Snapshot

  • Current RoleLead Software Engineer, U.S. Bank
  • FocusGenAI / RAG & CIAM Architecture
  • LocationIrving, TX
  • EducationM.S. CS & Cybersecurity
  • CertificationsAnthropic · AWS SA-Associate
Core Expertise

What I architect and build

A blend of applied AI systems and the enterprise security foundations that make them safe to deploy.

Generative AI & RAG Architecture

RAG pipeline design, embeddings, vector & semantic search, prompt orchestration, grounding, evaluation, and guardrails using Anthropic Claude and OpenAI.

MCP & AI Agent Integration

Designing MCP servers that expose enterprise APIs, databases, and knowledge sources to AI assistants through controlled, auditable interfaces.

Enterprise & Security Architecture

CIAM, OAuth 2.0, OIDC, SAML, JWT, SSO, MFA, federation, RBAC/ABAC, entitlements, and secure API patterns.

Platform Engineering

Reusable SDKs and identity libraries, Micro Frontends, versioning and backward-compatibility strategy.

Engineering

Java, J2EE, Spring Boot, Spring Security, REST, SOAP, JPA, Hibernate, React JS.

Cloud, DevOps & Leadership

AWS, Azure, Docker, Kafka, Cassandra, CI/CD; engineering management, design reviews, and mentoring.

Selected Work

Flagship projects

High-level views of recent architecture work. Full case studies with diagrams and code samples are being prepared from private repositories — check back soon.

📌 These write-ups are based on production work; detailed case studies (architecture diagrams, code excerpts) are in progress and will be added shortly.
Generative AI · RAG

Enterprise RAG Knowledge Platform

Problem: Engineering and support teams couldn't efficiently find answers across scattered internal documentation and knowledge sources.
Architecture: Ingestion & chunking pipeline → embeddings → vector/semantic retrieval → authorization-aware grounding → prompt orchestration → response-quality evaluation.
Role: Architected the end-to-end design and led the build.
Anthropic Claude Embeddings Vector Search
Case study coming soon · source private
MCP · Agent Integration

MCP Server Framework

Problem: AI assistants needed controlled, auditable access to internal APIs and data without bypassing existing security controls.
Architecture: MCP servers exposing approved enterprise APIs, databases, and tools through governed, auditable interfaces with access controls.
Role: Designed and built the framework end to end.
MCP Claude / OpenAI API Gateway
Case study coming soon · source private
Identity · Platform

Reusable CIAM Platform

Problem: Duplicated identity implementations were slowing onboarding of new products, partners, and merchants.
Architecture: Centralized OAuth 2.0 / OIDC / JWT / SSO / MFA services, reusable SDKs, and Micro Frontend identity components with versioned APIs.
Role: Own architecture, technical direction, and platform strategy.
Spring Security OAuth2 / OIDC Micro Frontends
Live in production · U.S. Bank
Experience

Career timeline

Lead Software Engineer 07/2023 – Present
U.S. Bank · Merchant Payment Services · Irving, TX
Leading CIAM platform architecture and Generative AI initiatives — RAG pipelines, MCP servers, and responsible-AI guardrails for enterprise knowledge and identity systems.
Senior Software Engineer 06/2020 – 07/2023
JPMorgan Chase & Co. · Digital Verification & Customer Platforms · Plano, TX
Designed Home Loan Digital Verification architecture, Spring Security OAuth 2.0 frameworks, and high-throughput Kafka/Cassandra pipelines.
Technical Consultant 12/2018 – 06/2020
FedEx Services · Customer Experience Services · Irving, TX
Led secure, scalable enterprise application architecture; enhanced OAuth 2.0 frameworks; built Jenkins/Docker CI/CD pipelines on AWS.
Senior Software Developer 01/2009 – 12/2018
Citi Bank Inc. · Digital Banking · Kolkata, India & Irving, TX
Built customer-facing digital banking capabilities — payments, fraud detection, credit card rewards — with FFIEC-aligned authentication controls.
Certifications & Education

Credentials

A
Anthropic Certification

Applied Generative AI

AWS
AWS Certified Solutions Architect

Associate

M
M.S., Computer Science & Cybersecurity

Colorado Technical University

Let's talk

Open to AI Architect, GenAI platform, and Staff+ engineering conversations. Reach out directly — I'll follow up promptly.

LinkedIn & GitHub links to be added.