# Riad Eita (رياض عيطة)

> Riad Eita is a Software & AI Engineer in Berlin who designs and builds systems where software, AI and enterprise infrastructure meet: AI assistants with MCP and retrieval, enterprise integration, platforms and system architecture.

Source: https://riad-eita.de/read · Contact: riad.eita@icloud.com

## At a glance

- **Role:** Software & AI Engineer
- **Works at:** Siemens (via Eviden), 2022 to present
- **Based in:** Berlin, Germany
- **Focus:** AI Engineering, Enterprise Integration, System Architecture
- **Core technologies:** React, TypeScript, Java, Python, REST APIs, Agentic AI, MCP, OpenShift, Kubernetes
- **Languages:** German, Arabic, English
- **Contact:** riad.eita@icloud.com

## About

I design and build systems where software, AI and enterprise infrastructure meet. Currently at Siemens (via Eviden): AI integration, enterprise platforms, and the pipelines that keep them running.

A language model becomes useful once it can reach the right data, with the right permissions, inside the tools people already use. A deployment is finished when it behaves the same way on every server. A sign-in works when nobody notices it crossing from one system to the next.

That in-between space – interfaces, contracts, pipelines, identity – is where I spend most of my time: in Java and TypeScript, in Python services, on container platforms, and in the architecture decisions that tie them together.

## Experience

**Software & DevOps Engineer, Siemens (via Eviden)** (2022 – present)

Building agentic AI solutions for an enterprise engineering platform, integrating Model Context Protocol (MCP) servers, LLM tooling and AI-driven automation to extend platform capabilities. Designing and building automated deployment pipelines that manage enterprise software extensions across large server landscapes. Developing REST APIs and microservices on container platforms with dependency resolution and metadata aggregation. Building React-based frontends integrated into enterprise tools. Implementing secure token exchange services for seamless SSO across internal systems. Working across the full stack: infrastructure automation, backend services, frontend interfaces and AI integration.

## Flagship: Embedded AI Assistant

An AI assistant inside an enterprise engineering platform.

**The problem.** Engineering knowledge is spread across specifications, tickets, documents and the tools around them. Finding the right context – and then acting on it – means switching views, writing queries and leaving the tool.

**The system.** Bring the assistant to the data instead of the data to another application: an assistant that lives inside the engineering platform, understands where it is opened, and works through approved tools rather than open-ended access.

### Engineering

- **Streaming through an enterprise stack.** Token-by-token answers from the model, through a Java backend, into a React interface running inside a server-side platform.
- **Permissions stay with the user.** Tools act through the platform's APIs and identity – no super-user in between.
- **Deciding what the model sees.** Retrieval results, project context and skill instructions have to fit a context budget – and only what is needed goes in.
- **Running it.** Containerized services on OpenShift, per-environment configuration with Kustomize, pipelines with tests and quality gates, enterprise authentication in front.

### Architecture

- **Engineering platform** (Where engineers work): Engineering data lives here. The assistant opens in context – the project or item the engineer is looking at.
- **AI Assistant** (React · TypeScript): A chat interface embedded through the platform's extension mechanism: streamed answers, Markdown, conversation history, model selection, settings, import and export.
- **Agent** (Java · LangChain4j): Coordinates reasoning and tool use. Decides what a request needs – knowledge, a skill, an operation – and assembles the answer.
- **LLM** (Enterprise model): The language model, hosted for enterprise use. It only sees what the agent decides to give it.
- **Skills** (Domain instructions): Packaged capabilities: domain knowledge and instructions for a kind of task, loaded when the task needs them.
- **Retrieval** (Python · FastAPI · RAG): Ingests documentation and engineering content and returns the passages relevant to a question.
- **MCP** (Model Context Protocol): Connects the assistant to approved tools. The agent discovers what is available instead of having every operation hard-coded.
- **Vector DB** (ChromaDB): Stores embeddings of enterprise knowledge, so retrieval searches by meaning rather than by keyword.
- **Tools** (Approved operations): Well-defined operations the agent may call – reading, searching, acting – each with a clear contract.
- **Platform APIs** (Within user permissions): Tools act through the platform's own interfaces and identity, never around them.

### Scenario: Ask a question

1. An engineer asks a question inside the platform, in the context of the item they have open.
2. The embedded assistant sends it, with that context, to the backend and waits for a stream.
3. The agent decides the question needs project knowledge.
4. The retrieval service searches indexed documentation and engineering content …
5. … by meaning, through embeddings in the vector database.
6. The model receives the question and the relevant passages – nothing more.
7. The answer streams back into the platform, next to the work it is about.

### Scenario: Run an approved operation

1. An engineer asks the assistant to carry out an operation in the platform.
2. The request goes to the backend with the engineer's identity.
3. The agent plans the task …
4. … and loads the skill that knows how this kind of work is done.
5. Through MCP it finds the tool approved for exactly this operation.
6. The tool runs with a defined contract …
7. … through the platform's own API, within the engineer's permissions.
8. What was done is reported back in the conversation.

### Result

An assistant that answers with the project's own context and carries out approved operations in the platform – without asking engineers to leave the tool they already work in.

### Contributions

- **Agentic AI & MCP:** MCP-based tool integrations, Skills architecture, Tool discovery, Approved operations, Contextual execution
- **Retrieval & knowledge:** RAG architecture, Vector retrieval, Ingestion pipelines, FastAPI services, ChromaDB
- **Enterprise integration:** Platform APIs, Server extensions, Identity integration, Authentication, Networking, Deployment environments
- **Frontend:** Streaming responses, Conversation management, Markdown rendering, Configuration, Model selection, Import / export
- **Platform engineering:** OpenShift, Kubernetes, Kustomize, CI/CD, Configuration management, Troubleshooting

Stack: Java, LangChain4j, React, TypeScript, Python, FastAPI, ChromaDB, PostgreSQL, MCP, OpenShift, Kubernetes, Kustomize

## Selected work

### Extension delivery across a server landscape

*Platform Engineering · Siemens (via Eviden) · platform extensions*

- **Problem:** Enterprise extensions have to reach a large landscape of servers in compatible versions – without manual steps that drift apart over time.
- **Approach:** Automated pipelines that resolve dependencies and versions, fetch artifacts, and roll out through matrix deployments – written to be idempotent, so a repeated run leaves correct servers untouched.
- **Role:** Designed and built the deployment pipelines.
- **Outcome:** Rollouts that are repeatable and traceable instead of hand-made.
- **Technologies:** Jenkins, GitHub Actions, Ansible, Matrix deployment, Artifactory, SVN, Semantic Versioning

### Dependency & metadata services

*Enterprise Systems · Siemens (via Eviden) · container platform*

- **Problem:** Which extension depends on what – and which version runs where – is scattered across repositories and servers.
- **Approach:** REST APIs and microservices on a container platform that resolve dependencies and aggregate metadata into one place pipelines and people can query.
- **Role:** Developed the APIs and services.
- **Outcome:** One place to ask instead of many places to look.
- **Technologies:** REST API design, Microservices, OpenShift, Docker

### Token exchange for single sign-on

*Identity · Siemens (via Eviden) · internal tooling*

- **Problem:** Internal tools each authenticate on their own; people should not have to sign in to every one of them.
- **Approach:** A secure token exchange that federates identity between systems – JWT, OAuth2 / SSO and GitHub App authentication – with secrets managed outside the code.
- **Role:** Implemented the token exchange service.
- **Outcome:** Moving between integrated tools without signing in again.
- **Technologies:** JWT, Token federation, SSO / OAuth2, GitHub Apps, Secrets management

### Project Hub

*Personal Project · Personal project · iOS and web*

- **Problem:** Project work – time, trips, expenses, appointments – ends up in five apps, and none of them produces the document needed at the end.
- **Approach:** A local-first app: a Next.js interface in a native iOS shell with SwiftUI screens, widgets and Siri shortcuts. Data is encrypted on the device and stored in a folder the user chooses, such as iCloud Drive; project dossiers and travel expense reports are generated as PDFs on the device.
- **Role:** Designed and built it.
- **Outcome:** In TestFlight testing on iOS; the web version runs at projecthub.fs223.de.
- **Technologies:** TypeScript, Next.js, Swift, SwiftUI, Capacitor, WidgetKit, App Intents, Web Crypto
- **Link:** https://projecthub.fs223.de

## Expertise

- **Experience** (Interfaces): React, TypeScript, Next.js, Angular, Vite
- **Application** (Software engineering): Java, Python, REST APIs, C#, Microservices, Servlet development, Velocity templates
- **AI** (AI & intelligent systems): Agentic AI, MCP, LLM integration, RAG, Vector databases, AI tooling & automation
- **Identity** (Identity & security): JWT, Token federation, SSO / OAuth2, GitHub Apps authentication, Secrets management
- **Platform** (Platform & DevOps): OpenShift, Kubernetes, Docker, Kustomize, GitHub Actions, Jenkins, Ansible, Matrix deployment, GitHub Enterprise Server
- **Data** (Data & infrastructure): PostgreSQL, SVN, Artifactory, Dependency resolution, Semantic versioning, Idempotent deployments
- **Quality** (Quality & testing): SonarQube, Unit testing, CI/CD quality gates, PDF generation
- **System architecture:** Across every layer: how the parts meet, who owns which contract, and what happens when one of them fails.

## Journey

- **Software** – One application: Java, TypeScript, Python and C# – the craft of building a program that works, learned at DHBW and ATIW.
- **Enterprise systems** – A platform many teams depend on: Extending a large enterprise platform from the inside: server extensions, servlets, Velocity templates, REST APIs.
- **AI integration** – Models inside existing tools: LLMs, retrieval and MCP brought into the tools engineers already use – with their permissions, not around them.
- **Platform engineering** – Everything that has to run: Pipelines, container platforms and deployments: Jenkins, GitHub Actions, Ansible, OpenShift, Kubernetes.
- **System architecture** – How the parts connect: Identity, integration, deployment and data – designing the seams between systems, not only the systems.
- **Solution architecture** – Technology, organisation, people (direction): Where this is heading: shaping end-to-end solutions with the people who will use and own them.

## Education

- **B.A. Political Science, Public Administration & Sociology**, FernUniversität in Hagen (April 2026 – present)
- **Bachelor of Science (B.Sc.) – Applied Computer Science**, DHBW Mannheim
- **Software Consultant**, ATIW – Siemens Professional Education
- **Allgemeine Hochschulreife**, OSZ IMT

## Beyond the code

Every architecture encodes decisions: who can see what, who decides, who is left out. Institutions, laws and habits shape technology as much as technology reshapes them.

Studying political science and sociology next to engineering is my way of looking at the same systems from the other side – from the institutions and the people inside them.

- **Technology:** Philosophy of technology, AI ethics & society
- **Institutions:** Democracy & governance, Social structures & institutions
- **Society:** Sociology, Migration & identity
- **Politics:** Political theory, International relations, Middle Eastern studies
- **Ethics:** Philosophy, Ethics & critical theory

## Questions, answered

### Who is Riad Eita?

Riad Eita (رياض عيطة) is a Software & AI Engineer based in Berlin, Germany, working at Siemens (via Eviden) since 2022. Riad designs and builds systems where software, AI and enterprise infrastructure meet: AI assistants with the Model Context Protocol (MCP) and retrieval, enterprise integration, deployment pipelines and system architecture.

### What does Riad Eita work on?

Riad Eita's flagship project is an Embedded AI Assistant: an AI assistant inside an enterprise engineering platform, built with Java, LangChain4j, React, TypeScript, Python, FastAPI and more. Around it: extension delivery across a server landscape; dependency & metadata services; token exchange for single sign-on.

### Which technologies does Riad Eita use?

Riad Eita works mainly with React, TypeScript, Java, Python, REST APIs, Agentic AI, MCP, OpenShift, Kubernetes. Supporting: Next.js, Angular, Vite, C#, Microservices, Servlet development, Velocity templates, LLM integration, RAG, Vector databases, AI tooling & automation, JWT, Token federation, SSO / OAuth2.

### What is Project Hub?

Project Hub is a personal project by Riad Eita: a local-first app that keeps project work – time, trips, expenses, appointments – in one place and generates the documents needed at the end. Under the hood: a Next.js interface in a native iOS shell with SwiftUI screens, widgets and Siri shortcuts. Data is encrypted on the device and stored in a folder the user chooses, such as iCloud Drive; project dossiers and travel expense reports are generated as PDFs on the device. In TestFlight testing on iOS; the web version runs at projecthub.fs223.de.

### Where did Riad Eita study?

Riad Eita's education: B.A. Political Science, Public Administration & Sociology – FernUniversität in Hagen (April 2026 – present); Bachelor of Science (B.Sc.) – Applied Computer Science – DHBW Mannheim; Software Consultant – ATIW – Siemens Professional Education; Allgemeine Hochschulreife – OSZ IMT.

### How can I contact Riad Eita?

By email: riad.eita@icloud.com. Riad is based in Berlin and speaks German, Arabic, English.

## Contact

If you are working on something where AI, enterprise platforms and people have to fit together, I would like to hear about it. Email: riad.eita@icloud.com. Based in Berlin, Germany.
