Satiya

Satiya WaraPutra

Senior Backend Engineer

Systems that scale. Pipelines that ship. Security built in.

Years Building
10+
Records / Day
1M+
Faster Releases
30%
Industries Served
2

Depok, Indonesia · GitHub

About

The short version — who I am and what I care about.

I've spent 10+ years building systems where downtime isn't an option — banking pipelines moving millions of records a day, telco middleware adopted company-wide, and CI/CD that gets faster over time. I work in Java, Python, Node.js, and Go, and I care as much about what happens after deploy as the code itself.

What I Solve

High-throughput backends, API platforms, and the automation that keeps them running in production.

Where I Deliver

Banking payment rails, telco middleware, and enterprise data pipelines across Indonesia.

How I Work

Own problems end-to-end — architecture, code review, CI/CD, observability, and team growth.

Skills

Depth over breadth — tools I use in production, not a keyword dump.

Primary Stack

JavaPythonNode.jsGoTypeScriptSQL

Frameworks

Spring BootNestJSFastAPIExpressApache NiFiOdooHyperledger Fabric

Infrastructure & Security

DockerGitLab CI/CDKong GatewayGrafanaSonarQubeOpenShiftDependency-Track

Experience

Where I've worked — scannable highlights. The full story is in Case Studies.

Senior Software Engineer

PT Firstwap International

Own telco product modernization while pushing engineering-wide gains in delivery speed and security.

  • Cut release cycles by 30% by overhauling GitLab CI/CD across multiple product lines.
  • Led the company-wide SBOM program in Dependency-Track — component analysis and supply-chain visibility from build to audit.
  • Host monthly tech sharing sessions; code reviews backed by SonarQube static analysis.

Selected Work

  • On-Premise AI Platform — Local LLMs on NVIDIA DGX for policy-compliant code review — no data leaves the building.
  • SCTP Library (Go) — Protocol library built from scratch; now the telco department standard.
Read the full case study →

Back-End Engineer / R&D

Telkomsigma

Shipped banking and BI infrastructure for Indonesian financial institutions at production scale.

  • Launched Open API portals on Kong Gateway for Bank Kaltim & Kalbar with automated publishing.
  • Supported BI-Fast go-live at Bank Maspion with Grafana/Prometheus observability.
  • Owned high-volume core banking data pipelines — 1M+ records daily (see case study).
Read the full case study →

Earlier Career

Back-End Engineer 2019 – 2020

Indocyber Global Teknologi

Built IFRS 9 / PSAK 71 compliance tooling and core datalake worker services for banking deployments.

Odoo Developer 2017 – 2019

PT. EnergyX 369 Indonesia

Customized Odoo ERP for enterprise clients — RMA workflows, financial reports, and client training.

Odoo Developer 2015 – 2017

Freelance

Shipped Odoo ERP solutions for small businesses while completing a Computer Science degree.

Case Studies

Deeper dives into two projects where architecture decisions made a measurable difference.

Company-Wide SBOM Initiative

PT Firstwap International · 2023 – Present

SecurityCI/CDCycloneDXDependency-TrackSCA
Architecture overview — sanitized, high-level only
SBOM CI/CD pipeline with Dependency-Track component analysisEvery release · CI/CD integratedProductReposGitLab CI/CDBuild · TestSonarQubeCycloneDXSBOMAPI uploadDependency-TrackSBOM ingest · PortfolioComponent analysis (SCA)Policy · Risk scoringVuln matchingAudit &ComplianceVulnerability intelligence (configured in Dependency-Track)OSVNVDOSS IndexGitHub Adv.

Context

As product portfolios grew across telco services, teams lacked a unified view of third-party dependencies — making vulnerability response slow and compliance audits painful.

Challenge

Introduce SBOM-driven component analysis across multiple product lines — without disrupting release workflows or treating vulnerability scanning as a bolt-on step outside the pipeline.

Approach

  • Standardized on CycloneDX SBOM format and Dependency-Track as the central component analysis platform.
  • Integrated SBOM generation and upload into GitLab CI/CD so every release is analyzed automatically via Dependency-Track's API.
  • Configured vulnerability intelligence sources (OSV, NVD, OSS Index) inside Dependency-Track for automated component risk matching — not as a separate scanner.
  • Established review practices alongside SonarQube static analysis and ran knowledge-sharing sessions on supply-chain risk.

Outcome

  • Company-wide visibility into third-party components across all product versions in one portfolio view.
  • Known vulnerabilities surfaced automatically through Dependency-Track's SCA engine — faster triage, less manual lookup.
  • Stronger compliance posture with auditable SBOMs and policy-based risk tracking.
  • SBOM upload became a standard CI/CD gate — component analysis runs on every release.

Side Projects

Personal experiments outside of work. Most of my professional output is closed-source — see Case Studies for that.

These are things I build on my own time to explore new stacks and ideas. They complement — not replace — the enterprise work described above.

02

Blockchain Digital Certification

A permissioned blockchain app for issuing tamper-proof digital certificates — built on Hyperledger Fabric for enterprise private-chain requirements, with chaincode in Go (the language of the Fabric ecosystem on GitHub).

Hyperledger FabricGoPrivate Blockchain
03

Telegram Community Bot

Automates group moderation and recurring admin tasks so community managers can focus on engagement, not busywork.

PythonAutomation
04

Odoo Migration (v8 → v10)

Led a full-version ERP migration with zero data loss and minimal downtime — an early deep-dive into production system upgrades.

OdooERP

Education & Training

Foundation and continuous learning — kept brief; experience speaks louder at this stage.

Degree

Bachelor of Computer Science

University of Gunadarma

Sep 2013 – Sep 2017

Certifications

  • Software Architecture & Design of Modern Large Scale Systems (Udemy)
  • Go: The Complete Developer's Guide (Udemy)
  • Apache NiFi Complete Master Course (Udemy)
  • Google Cloud Arcade Facilitator 2025

Contact

Interested in backend engineering, consulting, or building something together? I'd like to hear from you.

© 2026 Satiya WaraPutra