✦ SOFTWARE ENGINEER • TECHNICAL WRITER • SECURITY RESEARCHER ✦

Engineering, Security, and Technical Content — Built on Real-World Experience

Software engineer since 2008. Technical writer since 2011. Lead engineer from 2015–2025. Security researcher since 2024.

I write about software engineering, cloud infrastructure, application security, and real-world development practices.

About

Hi, I'm Hangga Aji Sayekti.

Software engineer since 2008, lead engineer from 2015 to 2025. I've helped teams build production systems, mentor developers, and drive engineering initiatives.

Since 2011, I've been writing practical programming tutorials. In 2023, my work appeared on Baeldung, CircleCI, Vultr, and DigitalOcean. Since 2024, I've also been active in penetration testing and secure coding training.

Today, I help developer-focused companies create technically accurate content that actually resonates with engineers.

2008Started professional career
2011First programming tutorials
2015–2025Lead Engineer roles
2023Published on Baeldung, CircleCI, Vultr, DigitalOcean
2024–presentPenetration testing & secure coding trainer
Learn More About Me →
Coding illustration
Selected work

Published technical content

Tutorials, security research, and engineering guides from 2023–2025

Kotlin Tutorial

Configure Kotlin's Bytecode Version with Gradle

Step-by-step guide to controlling JVM bytecode versions in Kotlin projects, ensuring compatibility and leveraging newer runtime features.

Read article →
Penetration Testing

Automating XSS Hunting with Dalfox

Hands-on tutorial for XSS detection using Dalfox on Kali Linux — installation, core commands, and automated scanning techniques.

Read article →
API Security · CI/CD

Automating API Security Tests in CI/CD for Java

Integrating OWASP ZAP, REST-Assured, and other tools into CircleCI pipelines to catch vulnerabilities early without slowing development.

Read article →
Supply Chain Security

Vulnerability Scanning for Gradle Dependencies

Automating detection of vulnerable dependencies (Log4Shell, CVE-2017-5638) in CI/CD pipelines to prevent supply chain attacks.

Read article →
Serverless · Kotlin

Build Serverless APIs with Kotlin Ktor & Coroutines

Complete guide to building efficient, coroutine-driven serverless APIs — from project setup to CRUD implementation and cloud deployment.

Read article →
Bug Bounty · IDOR

From a Simple Profile Endpoint to a 100k+ User IDOR

How a casual recon session uncovered an IDOR vulnerability affecting 100k+ users on HackerRank — methodology, impact, and fixes.

Read article →
Gradle Tutorial

Excluding Transitive Dependencies in Gradle

In this tutorial, we’ll specifically discuss several ways to exclude transitive dependencies in Gradle.

Read article →
Ripple Writers Program

Reducing Cold Starts for a Kotlin API

Optimizing startup latency for Kotlin Ktor APIs on DigitalOcean App Platform — dependency trimming, engine switching, and runtime config.

Read article →

Areas of Focus

I help developer-focused companies communicate complex technical topics with clarity, accuracy, and real-world engineering context.

📘

Technical Content

Tutorials, engineering deep-dives, cloud infrastructure guides, DevOps content, architecture articles, and developer education resources.

🛡️

Security Content

Secure coding guides, vulnerability analysis, bug bounty write-ups, application security content, and security-focused technical education.

🔍

Technical Review

Technical editing, code validation, fact-checking, and content reviews to improve accuracy and developer trust.

Why Developer-Focused Companies Hire Me

⚙️

Engineering Depth

17+ years of hands-on software engineering experience, from application development to system architecture and technical leadership.

✍️

Real-World Content

Articles and tutorials built from practical experience, not rewritten documentation or generic AI-generated content.

📰

Published Technical Writer

Published on platforms including Baeldung, CircleCI, Vultr, and DigitalOcean, reaching developer audiences worldwide.

🛡️

Security Perspective

Active in penetration testing, bug hunting, and secure coding, bringing a security-first mindset to technical content.