The University of Queensland

Enterprise Production Application Engineering

Owning the modernisation of legacy enterprise applications for the university, including Blackboard integrations, full-stack services, event-driven flows, and the AWS infrastructure behind them, while bringing systems in line with current security, accessibility, and engineering standards.

Highlights

  • Owns modernisation of legacy enterprise applications, replacing outdated tech with React, TypeScript, Node.js, and AWS serverless services.
  • Brought applications in line with cyber security controls through SSO, OIDC, and SAML upgrades.
  • Introduced structured audit logging in CloudWatch so P0 incidents can be isolated within minutes.
  • Migrated four legacy applications off self-hosted Jenkins onto AWS CodeBuild, CodePipeline, and CDK-based deployment.

Context

UQ runs a lot of enterprise-scale production software behind the scenes of everyday teaching and learning. Those services have to stay reliable and clear enough that support teams can work out what happened when something changes, and several of them were carrying real technical debt.

Role and scope

Vincent owns the modernisation of legacy enterprise applications, replacing outdated technology with React, TypeScript, Node.js, and AWS serverless services, and designs end-to-end application architecture, including technology selection, authentication, APIs, AWS infrastructure, and CI/CD.

The stack includes React and TypeScript frontends, Node.js services, PHP/Symfony and C# / ASP.NET Core applications, containerised microservices, and AWS infrastructure, working across both modern and legacy codebases that support large-scale university digital platforms.

Technical decisions

Vincent brings internally developed applications in line with cyber security controls through SSO upgrades, OIDC, SAML, security patching, and major framework upgrades, replacing older authentication approaches and unsupported components.

Services run on AWS ECS Fargate, with Route 53 and ALB handling routing, ACM managing certificates, and S3 covering storage and deployment assets. Four legacy applications moved from self-hosted Jenkins pipelines onto AWS CodeBuild, CodePipeline, Docker, and CDK-based deployment patterns.

Engineering impact

Structured application and audit logging in CloudWatch makes privileged-user activity traceable and helps production issues, including P0 incidents, get isolated within minutes. Unit and end-to-end tests are built into CI/CD pipelines so changes are validated automatically before deployment.

Internal platform details stay private, but the work covers integration ownership, production support and on-call rotations, and day-to-day reliability across university systems.