Portfolio -

Iqbal Dwi Rusmady

Senior Full-Stack Engineer | Banking, Fintech & API Integration

9+ years building production systems and API integrations with React, Next.js, Java, Spring Boot, and PostgreSQL across banking, fintech, and enterprise environments.

Open to Opportunities

Iqbal Dwi Rusmady

Senior Full-Stack Engineer

Hey, I'm Iqbal, a full-stack engineer from Bekasi, Indonesia with 9+ years building production-grade software for banking, fintech, and enterprise environments.

I specialize in dynamic UI systems integrated with complex APIs, from a public-facing SSO portal running on Kubernetes with zero-downtime CI/CD at Bank Saqu, to transaction monitoring at Bank Mandiri, all backed by secure, performant Java Spring Boot services. I care about code quality and the kind of UX that earns user trust.

9+
Years Exp.
9
Companies
15+
Projects

Top Stack

⚛️React / Next.js☕Java Spring Boot🅰️Angular🐘PostgreSQL🔷TypeScript🔐IAM / LDAP
🏦

Banking & Fintech

🔗

API Integration

🛡️

Secure Engineering

01 //

Professional Summary

Senior Full-Stack Engineer with 9+ years building secure, production-grade web applications for banking and fintech, including Bank Mandiri and Bank Saqu. Specializes in Java Spring Boot (Spring MVC, Spring Data JPA, Spring Security), React.js/Next.js, PostgreSQL, and API middleware, with hands-on ownership of payment gateway integrations, SSO systems, RESTful/microservices architecture, and high-volume transaction reporting (3,000-6,000+ records/transactions). Translates business, operations, and compliance requirements into production software that keeps banking channels running, speeds partner onboarding, and supports regulatory reporting.

💡 Key Highlights:

  • Public-facing SSO portal on Kubernetes with zero-downtime CI/CD (GitHub Actions), serving 100+ users
  • Project Lead across four enterprise banking initiatives at Bank Mandiri, leading cross-functional teams through delivery from requirements to production
  • Dynamic API middleware / UI generator eliminating hand-coded integration screens across partner integrations
  • High-volume transaction monitoring & reporting systems (3,000-6,000+ records) at Bank Mandiri
  • LDAP-authenticated, security-hardened reporting tools (XSS / injection-safe design)
  • Full-stack delivery across Java Spring Boot (Spring MVC, Spring Data JPA, Spring Security), Angular, React, and Next.js

🚀 Open to challenging roles where I can contribute both hands-on development and system design expertise, especially in finance, fintech, and API-intensive environments.

02 //

Technical Skills

Core stack first, grouped down to supporting tools and frameworks

■

Core

▸TypeScript▸JavaScript▸React.js▸Next.js▸Java (Spring Boot, Spring MVC, Spring Data JPA, Spring Security)▸PostgreSQL
■

Architecture & Integration

▸RESTful API Design▸Microservices Architecture▸GraphQL (client-side consumption)▸RBAC / Permission-Based Access Control▸OIDC / SSO integration (Keycloak, OAuth 2.0)▸Third-party API integration▸Custom payment gateways▸Dynamic form generator▸Transaction monitoring▸Server-Side Rendering (SSR)▸Component-Based Architecture
■

Security

▸IAM / LDAP authentication▸XSS prevention▸Host injection prevention▸Secure API design▸Authentication hardening (rate-limiting, lockout, device fingerprinting, request-signing)
■

Infrastructure

▸Docker▸Kubernetes▸Redis▸Google Cloud Platform (GCP)▸CI/CD (GitHub Actions, GitLab CI, Bitbucket Pipelines)
■

Engineering Practices

▸Object-Oriented Programming (OOP)▸Design Patterns & SOLID Principles▸Hibernate / JPA (ORM)▸Multithreading & Concurrency▸Data Structures & Algorithms▸Debugging & Troubleshooting▸Code Review & Mentoring▸Maven▸Gradle▸JUnit▸Mockito▸Vitest (unit testing)▸Playwright (E2E testing)▸Agile delivery▸Cross-functional software delivery▸AI-Assisted Development & Testing (Claude, ChatGPT)
■

Additional Stacks & Tools

▸Angular▸Vue.js / Nuxt.js▸Laravel▸CodeIgniter▸AdonisJS▸Node.js▸React Native▸MySQL▸NoSQL▸Git▸NextAuth.js▸Zustand▸HTML5 / CSS3▸Tailwind CSS▸Radix UI▸JBoss▸WebLogic▸Jasper Reports▸Redux▸MobX▸Ant Design▸Highcharts▸Leaflet▸Google Maps API▸Electron (personal/self-study projects)
04 //

Professional Experience

Chronological record of roles in frontend, backend, and enterprise product delivery. Scroll to browse

01 / 09
Scroll↓

August 2024 - Present

Senior Frontend Developer

Bank Saqu

Jakarta Raya, Indonesia

Designed and built the middleware layer behind the bank's digital channels, unifying login across products, powering third-party payment integrations, and managing internal microservices so operations teams could onboard new banking services and partners faster. Partnered with dedicated QA, penetration testing, and visual/UI regression teams, backed by automated Vitest unit tests and Playwright end-to-end tests, to validate release quality before every deployment.

SSO Portal

  • Spearheaded the architecture and development of the SSO portal's Keycloak-based OIDC middleware, consolidating authentication across multiple digital banking channels and enhancing security for 100+ users
  • Hardened authentication endpoints with rate-limiting, configurable account lockout, device fingerprinting, and cryptographic request-signing, resulting in zero security incidents since launch
  • Built a centralized middleware layer spanning 4 core capabilities (route guards, error-code normalization, session-refresh, and logging) as the integration point between front-end channels and backend services
  • Architected the front-end on Next.js with a shared Radix/Tailwind component system and Zustand state management, consuming backend services via REST and GraphQL, covering 3 distinct surfaces: the authenticated portal, an admin dashboard, and public-facing pages
  • Owned CI/CD and Docker-based deployment on Kubernetes, including release versioning, ongoing dependency vulnerability remediation, and a zero-downtime pipeline

Web Manager

  • Sole front-end engineer for an internal operations console, owning architecture, design system, and delivery end-to-end across 7 operational domains: access control, secure credentials, file-transfer monitoring, regulatory reporting, virtual accounts, notifications, and system configuration
  • Designed a dynamically generated, route- and action-level permission system covering 6 custom roles across 15+ menus and 12+ routes, each with granular action-level permissions (view, create, update, delete, export, upload, approve), computed server-side at login, cached in session, and enforced client-side without hardcoded per-page authorization checks
  • Built a defense-in-depth, Redis-backed session layer (Next.js middleware + NextAuth/JWT) for a tightly-scoped internal team (1-5 daily active users) monitoring payment, payroll, and other dynamically configurable processes, using a 30-minute Redis-backed session TTL with a 35-minute front-end buffer to avoid premature client-side expiry. Each session is revalidated against the backend Redis store and terminated the moment its Redis entry disappears, catching revoked sessions a client-side token alone would miss
  • Centralized API communication (REST and GraphQL) for 5+ backend services through a single client layer, normalizing inconsistent response/error contracts (including RFC 7807 problem details) and toast notifications, and reducing per-feature error-handling code

Skills

AxiosPortalsScrumApplication Security ArchitectureUI/UXSingle Sign-On (SSO) / OIDC (Keycloak)Dynamic Form GeneratorCustom Payment GatewaysNext.jsReact 19TypeScriptNextAuth.jsZustandTailwind CSSRadix UIRedisKubernetesDockerGoogle Cloud Platform (GCP)CI/CD (GitHub Actions)GraphQLVitestPlaywright
05 //

Education

🎓

Sekolah Tinggi Ilmu Komputer Yos Sudarso Purwokerto

Bachelor's Degree, Information Technology

Aug 2013 - Dec 2017

Usually responds within a day

Contact

Open to meaningful product work.

Interested in banking, fintech, API-heavy platforms, and modern product teams building secure digital experiences.