Hi, I'm Thomas 👋
Hands-on CTO for regulated fintech in Europe. I take payments, brokerage, and tokenization companies from ambitious roadmaps to platforms that ship and pass the regulator: MiFID II, DORA, KYC/AML, cloud, and the engineering teams that run it.
TW

Based in Vienna. CTO of Assetera, a MiFID II licensed investment firm for tokenized securities, where I rebuilt the complete technology stack in four months. Open to CTO, VP Engineering, and Head of Engineering conversations with payments, brokerage, and investment firms that need to enter or grow in the regulated European market. Remote-Europe and hybrid both work.

At a glance

4 mo
Full stack rebuilt at a MiFID II firm
Assetera: legacy monolith to services, Azure as code, live in production
950+
Pull requests merged
My own, in four months as CTO, across 29 repositories
44
Architecture decisions recorded
ADRs from identity to MiFID record keeping and DORA controls
681k
Trading accounts served
Morpher: 2,000+ markets, sub-500ms market data
0
Audit findings, any severity
Nethermind review of Assetera's primary-market settlement contracts
0
Voluntary attrition
Across 9 senior engineering hires

CTO at Assetera (MiFID II investment firm) · CTO at Morpher Labs 2020-2026 · Co-founder of Permissionless · MSc Telematics, TU Graz

Execution playbook

From good ideas to a regulated platform that ships

The method I used at Assetera, a MiFID II investment firm: audit, delivery cadence, engineering foundations, a written architecture, then the rebuild. Four phases, each one unlocking the next, with the regulator's questions answered in the system.

Read the playbook →

About

I'm a CTO who leads from the codebase. I set technical direction, write the architecture down, build the engineering culture, and still ship code when the hardest production problems show up.

My strongest fit is a fintech that has the licence, or is about to get it, and needs technology that keeps up. At Assetera I rebuilt the complete platform as a MiFID II and DORA ready system on Azure in four months, and put a team and a delivery cadence around it. Before that I spent six years as CTO of Morpher, a trading platform with ~681k accounts and 2,000+ markets. I know what regulators ask for, what auditors look at, and how to build so that both answers are already in the system.

Where I'm strongest

I'm strongest where the licence is real and the technology has to earn the regulator's trust.

Work Experience

A

Assetera
MiFID II
DORA

June 2026 - Present
CTO

CTO of a MiFID II licensed investment firm for tokenized securities. Rebuilt the complete technology stack in four months: services, Azure as code, identity, compliance, on-chain settlement, and the delivery process around it.

CTO of Assetera, a European investment firm licensed under MiFID II that offers tokenized securities to retail and professional clients. DORA applies in full.

  • A new foundation. I inherited a .NET monolith, infrastructure clicked together in the Azure portal, no CI/CD, and few tests. I ran an audit, presented it to the executive team, and ran my execution playbook: delivery cadence first, then engineering foundations, then the rebuild.
  • Rebuilt the stack from scratch in four months. About 15 TypeScript services (marketplace, compliance and EDD, admin API with audit log, attestation signer, EVM and Stellar/Solana indexers, notifications, realtime stream, enrichment) and six frontends, all in production. Case study.
  • Azure estate as code. OpenTofu modules for Container Apps, Front Door with WAF, Key Vault, Service Bus, Postgres, Redis, and observability across four environments. Keyless deploys with GitHub OIDC, image promotion from testnet to production, documented rollback. Case study.
  • Compliance in the system, not next to it. KYC/KYB and EDD with Sumsub and Chainalysis, appropriateness tests, proof of funds, professional opt-up, a fail-closed audit stream, and an activity ledger for MiFID II record keeping, each with its own ADR. Case study.
  • 44 ADRs set the target architecture: Keycloak identity with B2B2C tenancy, event-driven services, multi-chain indexing, per-market fees, primary issuance contracts. The client migration to Keycloak carries passwords and 2FA, so nobody signs up again.
  • A clean external audit. Nethermind Security reviewed the primary-market settlement contracts in September 2026 and found zero issues at any severity, not even informational notes. Documentation and test suite were both rated High. Report.
  • Brokerage on-chain. Primary sales of tokenized stocks (xStocks, Ondo) through RFQ with atomic on-chain settlement on four chains, plus a bank-transfer rail with payer verification.
  • Retired the legacy estate safely: a guided wind-down flow for existing clients, then subscriptions and clusters shut down step by step.
  • AI-native delivery. 950+ of my own PRs merged across 29 repositories in four months, with agents doing the typing and every diff reviewed. Case study.
  • Stack: TypeScript, Node.js, Next.js, PostgreSQL, Drizzle, Keycloak, Azure (Container Apps, Front Door, Key Vault, Service Bus, Entra ID), OpenTofu, GitHub Actions, Grafana, Solidity, Foundry.
P

Permissionless Inc

June 2024 - 2026 (on hold)
Co-Founder (CTO until 2026)

Co-founder of a permissionless stablecoin protocol with a compliance-aware privacy layer. Owned protocol architecture, implementation, audit coordination, and developer docs. The project is on hold; I remain a co-founder.

Co-founder and CTO. Built a permissionless stablecoin protocol that combines on-chain overcollateralization, yield-generating collateral strategies, and privacy-preserving compliance infrastructure. The project is on hold since 2026; I remain a co-founder.

  • Sole developer on the technical side: protocol, pool, compliance layer, and developer docs. Also drove strategy and marketing across upd.io, permissionless-technologies.com, and the preview.upd.io showcase app.
  • Designed the full protocol stack: stablecoin issuance, collateral management, and a compliance-aware dual SNARK-and-STARK privacy layer.
  • Built a production-direction post-quantum STARK verification path for Ethereum L1, with BLS12-381 SNARKs on the hot path for real 128-bit security and STARKs as the post-quantum vault layer. STARK proofs verify through SP1 wrapping today, with a clean upgrade path to native STARK verification when Ethereum supports it.
  • Managed the audit process: auditor procurement, scope review, feedback loops, remediation, and follow-up iterations.
  • Reached pre-launch on Sepolia, pre-audit, before the project went on hold.
  • Stack: Solidity, Foundry, OpenZeppelin, SP1, Circom, TypeScript, Next.js.
M

Morpher Labs GmbH

July 2020 - May 2026
CTO

CTO for a blockchain trading platform with ~681k accounts, 50-100k monthly actives, 2,000+ markets, a custom wallet, L2 infrastructure, and sub-500ms market-data systems. Owned engineering budget, roadmap facilitation, audits, and investor-facing product/tech updates.

Led engineering for a blockchain-based trading platform. ~681k accounts, 50-100k monthly actives, 2,000+ synthetic markets spanning equities, commodities, crypto, forex, indices, and a set of unique custom markets.

  • Scaled engineering from 3 unstructured devs to 7 across 2 product teams (desktop and mobile). Senior ICs were promoted into team-lead roles, not replaced by outside hires.
  • Owned development budget planning for AWS, tooling, audit work, and hiring expansion. Engineering usually ran at or under budget while preserving room for planned infrastructure and headcount growth.
  • Owned technical roadmap facilitation with product, marketing, support, compliance, and engineering. We scored upcoming work by impact, difficulty, urgency, and effort so high-impact quick wins rose to the top and costly low-value items became visible before they consumed months of engineering time.
  • Managed security and product audits: auditor procurement, offer review, scope definition, feedback loops, remediation, and follow-up iterations.
  • Prepared monthly investor-facing product and technology updates covering roadmap progress, feature delivery, bugs, infrastructure, improvements, and engineering risk.
  • Architected the Morpher Wallet. It is an encrypted, double-salted keystore that acts as an RPC-intercepting signer. The wallet itself only signs; the RPC sits outside the wallet, so it is chain-agnostic by design. ~681k wallets created. Works with any EVM chain.
  • Designed and operated a custom Plasma L2 with in-house validators and 1-second block times, well before today's L2 ecosystem (Arbitrum, Optimism, Base) reached production maturity.
  • Built a high-frequency tick-data pipeline that aggregates 8 sources at 1-2k msg/s average and 10k peak. 100% retention via S3 and Athena, with <500ms latency end to end.
  • Migrated production smart contracts to upgradeable proxies. Coordinated multi-chain settlement across the in-house plasma chain, Polygon, and Base, with several hundred thousand on-chain transactions processed.
  • Led incident response twice. An AWS datacenter fire forced a redesign of redundancy and failover automation. A supply-chain attack against a dependency tightened release verification and signature procedures. Both became lasting improvements.
  • Stack: Node.js, AWS, Docker, PostgreSQL, RabbitMQ, Redis, Solidity, Foundry, Truffle, OpenZeppelin, Vue, Jira, Notion.
B

Bitcoders GmbH

August 2018 - September 2020
CTO

CTO for blockchain and fintech client work. Owned architecture, delivery, budget-aware resourcing, roadmap facilitation, and client-facing technical decisions across concurrent engagements.

Led technical strategy and delivery for a portfolio of blockchain and fintech client projects.

  • Built and ran a senior engineering team across multiple concurrent client engagements.
  • Ran the same hiring loop I later refined at Morpher. Zero voluntary attrition on engineering hires.
  • Owned roadmap facilitation, architecture, delivery, budget-aware resourcing, and client-facing technical decisions end to end.
M

Moschitz IT

February 2012 - July 2018
Senior Full-Stack Developer

Built SaaS, warehouse tracking, and bespoke cloud hosting systems from prototype to production.

Built an accounting SaaS and a warehouse tracking solution from prototype to production, plus the bespoke cloud hosting infrastructure that ran them.

  • Stack: PHP, MySQL, Galera Cluster, Linux, Java, Android

Deeper write-ups on the systems above. Problem, constraints, architecture, what I owned, outcome, and tradeoffs.

Leadership operating system

How I run engineering teams. What I have actually built, not what I believe in.

Education

G

Graz University of Technology

2003 - 2012
Master's Degree in Telematics

Telematics is about modeling, planning, implementing, operating and assessing complex hard- and software systems. Similar to Computer Science, but also covers the underlying electrotechnical layer. Specialization in Machine Learning and Signal Processing. Master's Thesis Project completed at the University of Western Australia (UWA) in Perth, focusing on Machine Learning and Natural Language Processing.

Skills

Regulated Fintech & Compliance

MiFID II
DORA
GDPR
MiCA
KYC / KYB
AML & Transaction Monitoring
Enhanced Due Diligence
Appropriateness Testing
Proof of Funds
Record Keeping & Audit Trails
ICT Risk & Incident Response
Third-Party Register & Exit Plans
Sumsub
Chainalysis
Brokerage & RFQ Execution
Payment Rails

Cloud & Platform

Azure
Azure Container Apps
Azure Front Door & WAF
Key Vault
Service Bus
Entra ID
AWS
OpenTofu / Terraform
GitHub Actions (OIDC, keyless)
Keycloak
PostgreSQL
Redis
Grafana
Log Analytics
Microservices
Event-Driven Architecture

Blockchain & Protocols

Solidity
Smart Contracts
Foundry
Hardhat
Truffle
OpenZeppelin
Proxies & Upgradeability
Layer 2
Plasma
Account Abstraction (ERC-4337)
EIP-7702
Bundlers & Paymasters
Stablecoins
Wallets & Keystores
BIP39
Trezor
Ledger
ZK-SNARKs
STARKs
Circom
SP1
Privacy

Backend & Infrastructure

TypeScript
JavaScript
Node.js
Python
PHP
Java
C++
C# / .NET
Swift
Next.js
React
Vue
TailwindCSS
PostgreSQL
MySQL
Redis
RabbitMQ
AWS
RDS
Docker
CI/CD
Browser Automation (Playwright / CDP)
Galera Cluster

AI & Data

Machine Learning
Signal Processing
RAG
LLMs
Claude Agent SDK
Claude Code
MCP Servers
Multi-Agent Orchestration
Ollama / Local Models
Whisper / TTS Pipelines
ETL Pipelines
S3 / Athena
Tick-Data Engineering

Leadership & Delivery

Technical Strategy
Engineering Budgeting
Hiring & Calibration
Roadmap Prioritization
Scrum & Forecasting
Architecture Review
Audit Management
Incident Response
Performance Management
Investor Updates
Compliance & Legal Collaboration
Developer Education
Corporate Training
KYC
Selected work

Tools, courses, and infrastructure I've built

Public projects beyond the company work above. Most of them exist because I needed them while running engineering.

flash-agents

A Claude Code plugin that lets Claude steer while cheap DeepSeek Flash workers do the reading and the typing. Every writing job runs in a disposable copy-on-write clone of the repository and comes back as a git-computed patch, so the evidence is the diff, not the worker's story. Fan-out of up to 16 tasks per call. Built for, and used daily on, the Assetera rebuild.

Claude Code
MCP
TypeScript
DeepSeek
Multi-Agent Orchestration

PrivateGoat

A native macOS menu-bar app that records both sides of a call, transcribes it on the Mac with whisper.cpp, and turns it into summaries, action items, and Jira-ready to-dos with a local model. Meeting audio never leaves the Mac, there is no analytics, and nothing reaches Jira until you send it. Privacy by design for people who sit in regulated meetings all day. Free public beta through Homebrew.

Swift
SwiftUI
whisper.cpp
Ollama
MCP
Atlassian OAuth

Ethereum Blockchain Developer Course

One of the largest Ethereum developer education platforms. Over 140,000 students learned Solidity, smart contract security, Foundry, Hardhat, and production Web3 workflows on the video course since 2016. Beyond the VoD platform, I have lectured in-person at the University of Rome, delivered Fortune 500 corporate training through the Blockchain Training Alliance, and run developer training for public-sector organizations. Public authority, mentorship at scale, and a long-term commitment to the space.

Solidity
Foundry
Hardhat
TypeScript
Next.js
React
OpenZeppelin

Autoreel: Agent-Driven Video Pipeline

A 10-stage Claude Agent SDK pipeline that produces developer-tutorial videos end to end. Word-anchored Whisper timing as the canonical clock, Remotion for compositional rendering, Playwright + CDP for screen capture, an injected EIP-1193 wallet mock with EIP-6963 announce for Web3 demos, and Claude-driven visual gates that catch broken layouts before render. Outputs 1080p long-form and 9:16 shorts from one storyboard. Built to scale Solidity tutorial production to the next cohort of learners.

Claude Agent SDK
Remotion
Playwright
Whisper.cpp
viem
TypeScript
ffmpeg

Soldebug

A Solidity transaction debugger for Foundry. Replay transactions against forked chains to produce detailed stack traces with function calls, arguments, custom errors, and revert reasons.

Rust
Foundry
Solidity
REVM
Alloy

Foundry Dashboard

A desktop application to interact with your Foundry builds. Beautifully decode transactions, manage contracts, and interact with your local node.

Foundry
Rust
TypeScript
Next.js
TailwindCSS
Shadcn UI

MkDocs Shadcn

A theme for MkDocs powered by Shadcn UI. Bring modern aesthetics and components to your static documentation sites.

MkDocs
Python
TypeScript
Shadcn UI
TailwindCSS
Contact

Let's talk

For CTO, VP Engineering, or Head of Engineering conversations, email me at me [at] thomaswiesner.com or reach out on LinkedIn or Farcaster.

I'm especially interested in payments, brokerage, and investment firms that want to enter or grow in the regulated European market, and in teams whose platform has stalled and needs to ship again. I read every thoughtful, relevant inbound.