Skip to content
View achmad-firdaus's full-sized avatar
🌴
On vacation
🌴
On vacation

Block or report achmad-firdaus

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
achmad-firdaus/README.md

πŸ‘‹ Hi, I'm Achmad Firdaus

πŸš€ Senior Application Security Engineer | Backend Architect | AI-Assisted Builder

I build secure, scalable, production-grade systems and leverage AI to accelerate both backend and frontend development. Experienced in leading engineering teams, architecting security platforms, and delivering enterprise solutions.


🧠 About Me

  • πŸ” 6+ years in Application Security & Penetration Testing
  • πŸ— Architect & Lead Developer of Security Assessment Platform (SIERA)
  • πŸ‘¨β€πŸ’» Backend Engineer (Golang, Node.js, PHP)
  • πŸ€– Using AI to accelerate development lifecycle (backend & frontend)
  • 🧩 Strong in multi-tenant SaaS architecture & system design
  • πŸ‘₯ Led cross-functional engineering team (8 members)
  • 🎯 Focused on secure, scalable, and production-ready systems

πŸ† Certifications


πŸš€ Flagship Project

πŸ”Ή HRIS SaaS Platform (Production-Grade System)

A multi-tenant HR platform designed with security-first architecture and built using AI-assisted development.

βš™οΈ Tech Stack

Backend

  • Node.js + Express
  • JWT Authentication (Access + Refresh Token via httpOnly Cookie)

Frontend

  • Next.js 16 (App Router)
  • React 18 + TypeScript
  • Tailwind CSS
  • Recharts (data visualization)
  • Framer Motion (UI animation)

Database

  • PostgreSQL

πŸ” Security & Architecture

  • RBAC (database-driven roles & permissions + dynamic menu mapping)
  • Hardened HTTP headers using Helmet
  • API Rate Limiting
  • Secure token handling (httpOnly cookies)

πŸ“Š Observability & Logging

  • Structured logging using Pino
  • Request logging middleware
  • Audit logs with tamper-evident hash-chain design

🧠 Key Highlights

  • 🧩 Multi-tenant SaaS architecture
  • πŸ” Security-first design (aligned with real pentesting experience)
  • πŸ€– Built using AI-assisted development (backend & frontend acceleration)
  • βš™οΈ Production-ready with Docker-based deployment

πŸ”Ή Security Assessment Platform (SIERA)

  • Container-based internal security testing platform
  • Built with Golang, Node.js, PostgreSQL, Redis
  • Designed for scalable vulnerability assessment workflows
  • Used in enterprise security operations

πŸ”Ή Other Engineering Work

  • Vulnerability Assessment Automation Tools
  • Backend Systems for Enterprise Applications
  • Security Testing Workflows & Reporting Automation

βš™οΈ Tech Stack

πŸ‘¨β€πŸ’» Backend & Systems

  • Golang, Node.js (Express), PHP (Laravel, CodeIgniter, CakePHP)

πŸ—„οΈ Infrastructure

  • PostgreSQL, Redis, Docker, Linux, CI/CD

πŸ” Security

  • Web Security (OWASP Top 10)
  • API Security Testing
  • Manual Exploitation (Burp Suite)
  • CVSS Risk Analysis

πŸ€– AI-Assisted Engineering

  • Accelerating development lifecycle using AI
  • Rapid prototyping & scalable system scaffolding

πŸ’‘ Engineering Philosophy

  • πŸ” Security is not an afterthought β€” it is built-in by design
  • βš™οΈ Systems must be scalable, observable, and production-ready
  • πŸ€– AI is a force multiplier, not a shortcut
  • πŸ“Š Focus on real-world impact & maintainability

πŸ“Š GitHub Stats

stats


🀝 Let's Connect


⭐ Building secure systems, scaling engineering teams, and leveraging AI to move faster.

Pinned Loading

  1. Cyber-Security Cyber-Security Public

    Cyber Security

  2. hris-platform hris-platform Public

    Enterprise-grade HRIS platform with RBAC, dynamic approval workflow, audit logging, and security monitoring. Built with Node.js, Next.js, PostgreSQL, and Docker.

    JavaScript