Darya Koko
Winner, Best Secure Coder — NZ Women in Security Awards 2023
Empowering engineering teams to build faster, safer, and with confidence
Scroll to explore
Darya Koko
Darya
Koko
Senior Staff Software Engineer Technical Leader Auckland, New Zealand
🏆
NZ Women in Security Awards · 2023
Best Female Secure Coder Award Winner

Award-winning Senior Staff Engineer
& Secure Systems Leader

Darya Koko, also known as Darya Kokovikhina, is an award-winning Senior Staff Software Engineer with over 10 years of experience designing and evolving secure, scalable distributed systems across banking, fintech, and healthcare. Recognised with the Best Secure Coder Award at the NZ Women in Security Awards 2023, she brings a rare combination of deep payments domain expertise, platform engineering leadership, and a secure-by-design philosophy to every system she builds.

As a senior technical leader, Darya has driven large-scale modernisation programmes at institutions including Kiwibank, architecting cloud-native payment systems within PCI-regulated environments while enabling engineering teams to deliver faster, safer, and with confidence. Her expertise spans the full stack of secure delivery — from EFTPOS transaction flows, 3D Secure, and HSM-backed cryptography, to zero-trust API design, threat modelling, and secure SDLC practices.

She is a published author, having contributed to the NZ DEFSEC Security Magazine and the Women in Security Magazine, sharing insights on the future of women in cybersecurity and technology. At the frontier of the next engineering era, Darya is actively applying AI and multi-agent orchestration to improve developer workflows — with a governance-first approach to responsible production adoption.

10+
Years Experience
🏆
Award Winner
2
Publications
Awards & Publications
NZ Women in Security Awards · 2023
🏆 Best Female
Secure Coder Award
Winner · New Zealand Women in Security Awards · 2023
Recognised for outstanding contributions to secure-by-design engineering practices across banking and fintech platforms. This award acknowledges engineers who consistently embed security into the full software delivery lifecycle — from architecture through to production.
Best Secure Coder Award trophy — NZ Women in Security Awards 2023
Certificate of Appreciation — NZ Women in Security Awards 2023
Certificate of Appreciation · 2023
Certificate of
Appreciation
New Zealand Women in Security Awards · Presented by Abigail Swabey, CEO, Source2Create
Awarded for dedication to developing secure applications, implementing encryption mechanisms, and conducting rigorous testing — demonstrating commitment to safeguarding sensitive information, patient data security, and promoting diversity in the cybersecurity field through publications and threat modelling hackathons.
Academic Background
🎓
Postgraduate Diploma in Computing — Cybersecurity
Unitec Institute of Technology, Auckland · 2018–2019
Research: Cache-Based Side Channel Attacks in Virtualisation
🎓
BSc (Hons) Computer Science — First Class Honours
Staffordshire University / APU Malaysia · 2011–2015
Project: Online Platform for Beauty Salons
Author & Contributor
✍️
The Future of Women in Security
Women in Security Magazine · Issue 18 · Jan–Feb 2024 · p.114
✍️
History of Women in Tech and Cybersecurity
DEFSEC NZ Security Magazine · Women in Security Edition · Apr–May 2021 · p.30
Core Capabilities
Languages
C#, .NET Core, ASP.NET Web API, SQL, JavaScript, TypeScript
Architecture
Microservices, Event-driven, Clean Architecture, DDD, SOLID, API-first, High-availability design
Cloud & DevOps
Azure (Functions, Service Bus, APIM, App Services), AWS, Kubernetes, Docker, Terraform, CI/CD
Security
OWASP, STRIDE Threat Modelling, PCI-DSS, Secure SDLC, Snyk, Dependabot
Payments & Cards
3D Secure, PCI-DSS, Postilion, HSM Cryptography, EFTPOS, Card Lifecycle, Secure Integrations
AI & LLM
Multi-agent orchestration, RAG patterns, Prompt engineering, LLM governance, GitHub Copilot, Claude API
API & Integration
REST, GraphQL (HotChocolate, Apollo Federation), gRPC, OAuth2, OpenID Connect
Observability
Sumo Logic, Dynatrace, SLO/SLI, Monitoring & Alerting, Incident Response, RCA
Frontend
React, AngularJS, React Native (Expo), TypeScript

Work Experience

07 roles
Nov 2025 — Present
Current
Independent
AI & Agentic Systems
Independent Engineering Project

Designing and prototyping AI-assisted software engineering workflows, exploring multi-agent orchestration to support structured SDLC processes across analysis, design, development, and testing.

Developed role-based agent frameworks simulating engineering functions, improving task decomposition, context management, and workflow automation in complex systems.
Implemented guardrails for LLM-driven workflows — structured prompts, context boundaries, validation layers, and human-in-the-loop controls to reduce hallucination risk.
Applied solutions to a working React Native / Expo application, validating practical AI-assisted development in iterative cycles.
GitHub CopilotClaude APIReact NativeMulti-agentRAGLLM GovernanceExpo
Apr 2025 — Oct 2025
Contract
Senior Software Developer
Kiwibank — Digital Payments Modernisation

Led design and delivery of key components within Kiwibank's digital payments modernisation programme, contributing to secure, scalable payment systems in a highly regulated PCI environment across multiple squads.

Modernised a critical legacy payments service into a cloud-native microservices architecture (.NET Core, GraphQL), improving scalability, maintainability, and regulatory alignment.
Improved system reliability with Dynatrace dashboards, Sumo Logic synthetic monitoring, and structured RCA practices, reducing incident detection time.
Optimised CI/CD pipelines and introduced feature flagging via LaunchDarkly for safer, controlled production rollouts of critical payment features.
.NET CoreGraphQLPCI-DSSAzure DevOpsDynatraceSumo LogicLaunchDarkly
Dec 2020 — Apr 2025
Senior Software Engineer
Best Practice Software — Healthcare

Senior technical leader driving secure distributed architecture and identity solutions across mission-critical, compliance-sensitive healthcare platforms over 4+ years.

Architected secure IAM solutions using OAuth2, OIDC, mTLS, and certificate-based authentication across cloud and on-premises systems.
Led system decomposition from monolith to microservices and BFF/APIs using DDD, SOLID, and Clean Architecture principles.
Delivered complex secure third-party integrations (ACC, Physitrack) ensuring compliant interoperability across critical healthcare systems.
C# / .NETOAuth2 / OIDCmTLSMicroservicesDDDClean ArchitectureAzure
Oct 2019 — Nov 2020
Software Developer
Kiwibank — Payments & Cards

Engineer within a high-volume, PCI-regulated payments environment delivering secure payment flows and architectural improvements across cards and EFTPOS systems.

Delivered the Visa-compliant 3D Secure (3DS) service with a 3-second SLA, improving transaction success rates and fraud protection.
Developed the Payment Integration Gateway with Postilion switch, enabling efficient card and transaction routing.
Delivered secure PIN change functionality using HSM-backed cryptography; led migration from TFS to Azure DevOps.
3D SecureHSM / CryptographyPostilionPCI-DSSEFTPOSAzure DevOps
Nov 2018 — Oct 2019
Full Stack Developer
iTicket Ltd. — Online Ticketing

Full-stack development on high-volume ticketing and payment platforms. Delivered scaling improvements, Azure cloud deployments, and modernised legacy components for major events including Armageddon and Visa Wellington on a Plate.

AngularJSASP.NET MVCTypeScriptAzureSQL Server
Jan 2017 — Jul 2018
Full Stack Developer
Phaeton DC — Automotive & IT

Full-stack development of 24/7 e-commerce platforms, secure online banking payment integrations, and internal HR systems. Contributed to requirement gathering and mentored new team members.

ASP.NET MVCC#SQL ServerJavaScriptPayment Integrations
Nov 2015 — Nov 2016
Full Stack Developer
SEB Bank — Pension & Insurance

Developed a new Pension & Insurance portal in collaboration with teams in Sweden and Malaysia, delivering to European banking standards in a multinational Agile environment.

.NET FrameworkC#AngularJSWeb APISQL ServerAgile