Go · Swift · Kubernetes · PostgreSQL · System design · Monitoring and observability
Secures with
FAPI 2.0 · mTLS · OAuth 2.0
Build. Secure. Advise.
Three engagements, three different ways of working. I architect and lead the build, implement the security standards, and advise the organisations adopting them.
Client engagements
Architect and lead
Brankas Direct
Bank-integration logic was being re-implemented for every provider. I rewrote the boundary so it could not be.
Account-to-account payments for Southeast Asian merchants. I restructured the Go service layer around SOLID boundaries so bank-integration logic stopped being re-implemented per provider.
The bank's REST surface stops at my boundary. Downstream services never see a provider change.
Banking-as-a-service in the Philippines. I implement the Financial-grade API security profile, mutual TLS in both directions, and the webhook delivery the bank exposes to its clients.
I graded where they stood, mapped it against FAPI and SNAP, and wrote the path between.
Advisory engagement with a state-owned Indonesian financial institution. I graded API and security capability against a maturity model, mapped the gaps against FAPI and SNAP, and wrote the roadmap.
An AI barista trainer built at the Apple Developer Academy. Speech to text and text to speech drive a role-play that runs against a cafe's own standard operating procedure.
A board is the contract. It holds who is working on what, and ticket comments are the only channel agents talk through. Anything a downstream agent needs has to be written onto the ticket, because the ticket is all it can see.
The model that builds is never from the same family as the models that test, verify, and review it. Same-family review repeats the same blind spots, so a gate that shares the builder's training is not really a gate.
Independence goes on the spec, capability goes on the code. Checking code against a written contract is objective, so the strongest model does it. Judging whether the spec matches what the user actually asked for has no gate below it, so a second model reviews it before work starts. A wrong spec passes every later gate green and ships the wrong feature.
When the orchestrator takes over a build, it cannot also be the gate on its own work. An independent reviewer has to pass the change first, on the acceptance criteria alone.
Loops are bounded on the record itself, with attempt counts, leases, and a spend ceiling, rather than by instructions written in prose. Infrastructure failures never consume the retry budget: an empty response from a flaky runner is not a failed attempt.
Experience
Brankas Technology
Jun 2021 to present · Jakarta, remote
Technical Lead
Mar 2023 to present
Promoted
Lead a 5-engineer backend team on Direct, the account-to-account payment product, and on core banking integration for a Philippine digital bank.
Drove a clean-architecture rewrite of the Go service layer with an enforced repository structure, consolidating bank-integration logic that was being re-implemented per provider.
Own reliability and distributed architecture on the payment path: Prometheus, Grafana, and InfluxDB, Kubernetes HPA, graceful shutdown with connection draining.
Set the design-first OpenAPI contract process for partner-facing payment APIs, giving banks a stable specification ahead of implementation.
Software Engineer
Jun 2021 to Mar 2023
Built and maintained Go backend services for Direct payment flows on Kubernetes and Google Cloud Platform.
Introduced unit testing to the Go codebase with table-driven tests and the race detector in CI, establishing a regression safety net the services had been shipping without.
Migrated a legacy Go-template UI to a Vue 2 single-page application, decoupling frontend delivery from backend release cycles.
Bizzy Indonesia
Dec 2019 to Jun 2021 · Tangerang Selatan
Full-Stack Engineer
Dec 2019 to Jun 2021
Shipped customer-facing features on the React Native iOS and Android app: in-app support chat, product search, a full UI revamp, and payment-gateway checkout.
Migrated roughly half the internal API from the monolith to microservices on AWS Lambda, SQS, and SNS, choosing event-driven serverless for spiky, independently scaling workloads.
Introduced Redis caching on hot read paths to cut API latency without provisioning more database capacity.
Automated Android and iOS release builds with Fastlane, replacing a manual release process.
Pijar Camp
Sep 2018 to Dec 2019 · Jakarta
Formerly Arkademy Edu Tech. Part of Amoeba, Telkom Indonesia.
Front-End Engineer
Sep 2018 to Dec 2019
Rewrote the frontend from a server-rendered PHP CodeIgniter app to a Vue 2 single-page application, fixing load speed and navigation responsiveness that page-per-request rendering could not address.
Built the company's UI component library on a modular SCSS architecture, documented in Storybook, and authored the frontend architecture documentation the team built against.
Developed core platform features: the video player, OAuth login, a paginated course catalogue, and in-app chat.
Native iOS and Swift under Challenge-Based Learning: problem framing, research, lo-fi prototype validation, and feasibility scoping to tight deadlines. Frequently led teams and drove delivery.
Universitas Ciputra
2025 to 2028 expected
Bachelor of Computer Science, Surabaya
Returned to complete the degree while working full time as a software engineer.