About Me
Hello! I’m Chen Xi, a Staff Software Engineer at Uber in the Greater Seattle Area, where I’ve been driving critical security infrastructure initiatives since October 2019. I’m passionate about building secure, scalable systems that protect and empower millions of users worldwide.
My Journey
I specialize in building and securing Uber’s core platform through sophisticated secret management systems, key management services, and zero-trust security architectures. My work encompasses the full spectrum of modern security engineering—from implementing secrets rotation and access control to deploying identity solutions using SPIRE/SPIFFE, JWT tokens, and internal PKI infrastructure.
Some of my key achievements include:
- Identity Provider Migration: Led the migration from OneLogin to Okta, introducing passwordless authentication across the platform
- Security Infrastructure: Built resilient systems with cross-region replication, raft consensus, and high-availability architectures
- Innovation in AI Security: Currently pioneering identity observability initiatives by developing knowledge graphs for AI agents to enhance Uber’s security posture
With deep experience in both GCP and AWS environments, I combine security best practices with scalable infrastructure design to protect one of the world’s largest technology platforms.
What I Do
My expertise spans several key areas:
- Security Infrastructure: Designing and implementing zero-trust architectures, secrets management, and identity solutions at massive scale
- Distributed Systems: Building resilient, high-availability systems that can handle millions of requests with strong consistency guarantees
- Cloud-Native Engineering: Leveraging Kubernetes, Docker, and cloud platforms to create scalable, maintainable infrastructure
- DevOps & Automation: Using tools like Terraform, ArgoCD, and GitOps practices to enable reliable, repeatable deployments
- Identity & Access Management: Implementing SPIRE/SPIFFE, PKI infrastructure, and modern authentication patterns
Technical Interests
I’m particularly excited about:
- Security Technologies: Zero-trust architectures, workload identity (SPIFFE/SPIRE), and policy-as-code (OPA)
- Distributed Systems: Consensus algorithms, distributed databases, and building systems that scale globally
- Cloud-Native Ecosystem: Kubernetes, service meshes, and the evolving landscape of cloud-native security
- Programming Languages: Go for its simplicity and performance, with growing interest in Rust for systems programming
- Emerging Tech: Graph databases for security modeling, WebAssembly for sandboxed execution, and eBPF for kernel-level observability
- AI & Security: Exploring how AI can enhance security operations and threat detection
Beyond Work
When I’m not building security infrastructure, you’ll find me:
- Contributing to open source projects, particularly in the security and identity space
- Writing about complex technical topics to make them more accessible
- Exploring the intersection of AI and security
- Learning about the latest developments in distributed systems and security research
Let’s Connect
I love discussing technology, security challenges, and innovative solutions. Whether you’re interested in collaborating on open source projects, discussing security architectures, or just want to chat about the latest developments in distributed systems, I’d love to hear from you!
Find Me Online
- GitHub: hixichen - Check out my open source contributions
- Blog: Right here! I write about security, distributed systems, and lessons learned from production
Always happy to chat about technology, security, or potential collaborations!