Who I Am

About

Background

I'm a Software Engineer based in the Philippines with over 9 years building production backend systems — the kind that move money, authenticate users at scale, and keep running when things go wrong.

My work lives at the intersection of distributed systems, cloud infrastructure, and application security. I gravitate toward event-driven architectures, API design, and the unglamorous-but-critical work of making systems observable, testable, and maintainable long after the initial build.

I take security seriously as an engineering discipline, not an afterthought. I'm a Certified Web Penetration Tester (CWPT) and I'm pursuing a Professional Science Master's in Cybersecurity, which feeds directly into how I think about the systems I build.

Outside of client work, I run a Proxmox homelab that doubles as a personal infrastructure playground — CI runners, self-hosted services, and a place to break things safely. It's where a lot of my practical knowledge about networking, containers, and distributed systems has been earned the hard way.

I'm open to backend and platform engineering contracts — greenfield systems, migrations, performance work, or security-focused engagements. If the problem is hard and the stack is modern, I'm interested.

How I Work

Backend-First

I design for the API contract first, then build outward. Clean interfaces, consistent error surfaces, versioning from day one.

Security by Default

Threat modelling, input validation, least-privilege IAM, and dependency auditing are part of my normal build process — not a separate phase.

Ownership Mindset

I write runbooks, own alerts, and think about on-call before code ships. Systems I build are meant to be operated by humans under pressure.

Location

Philippines

Open to remote contracts worldwide

Experience

9+

Years in production

Certifications

CWPTCertified Web Penetration Tester

Appkademiya · Issued Sep 2026 ·Verify →

Appkademiya Certified Web Penetration Tester (CWPT) certificate issued to Ian Gabriel Sanchez on Sep 16, 2026

Education

BS Computer Science

Holy Angel University · Graduated 2018

PSM Cybersecurity

Holy Angel University · Expected 2028

Availability

Open to contracts
Get in Touch →

9+ Years, Several Teams

Experience

Backend & Platform

  • Moved invoicing and billing to Stripe, including migration tooling to transfer customer subscriptions from Maxio (Chargify) and Paywhirl
  • Migrated backend infrastructure to Infrastructure-as-Code (AWS CDK), cutting deployment time by 70% and enabling reproducible environments
  • Built automated data replication and synchronization pipelines across relational and NoSQL stores for reporting and analytics
  • Engineered integration layers and orchestration logic powering AI agent workflows across third-party APIs
  • Integrated an ERP system into subscription and billing flows, and added an invoice payment flow through a third-party payments provider
  • Planned and executed managed Postgres tier upgrades across staging, production, and read replicas
  • Moved CI from CircleCI to GitHub Actions, and isolated end-to-end test data so the suite could run fully in parallel
  • Re-architected a web app and API to be stateless, and replaced deprecated identity-provider API endpoints ahead of their end of life

Leadership & Delivery

  • Led an engineering team of 6 as Head of Engineering, owning delivery from business requirements through to production
  • Turned business requirements into technical designs, choosing the stack and documenting pros, cons, and trade-offs for each major decision
  • Owned the engineering budget and team lifecycle end to end: hiring, mentoring, performance reviews, and offboarding
  • Planned, prioritized, and assigned the team's work, and ran the release path from staging to production, including the infrastructure, databases, and CI/CD behind it
  • Directed triage and resolution for critical production incidents, deploying hotfixes under pressure to minimize customer impact
  • Introduced CI/CD and structured development workflows, reducing release failures and increasing deployment frequency
  • Evaluated technical CVs and project submissions for engineering hires, focusing on real-world project relevance over pedigree
  • Ran technical spikes to size new integrations and payment approaches before committing delivery time, including an auto-rollback mechanism

Security & Compliance

  • Drove SOC 2 compliance efforts, resolving both reported and undetected vulnerabilities
  • Implemented rate limiting and domain banning for commonly abused features
  • Built role-scoped, self-service investigator access so outside users only see their assigned work
  • Overhauled a company's authorization system, restructuring how users, roles, and per-location access are granted and enforced across the platform
  • Resolved findings from an external web application penetration test, and fixed access-control edge cases around guest and role-less accounts
  • Reviewed features before release for data exposure, flagging unauthenticated access paths to sensitive evidence data before they shipped
  • Fixed identity-linking so each user maps to the correct authenticated identity-provider account

Systems & Tooling

  • Designed database schemas and REST/RPC APIs for healthcare, billing, and SaaS platforms from the ground up
  • Built internal tooling to automate recurring operations, reducing manual effort and improving response times
  • Integrated event-driven microservices with Apache Kafka for reliable, ordered data transport
  • Wrote reusable integration components that reduced development effort for future third-party integrations

Tools & Technologies

Stack

Languages

  • TypeScript
  • Java
  • SQL
  • Bash

Frameworks

  • NestJS
  • Spring Boot
  • React
  • Express

Infrastructure

  • AWS CDK
  • Docker
  • Proxmox
  • GitHub Actions
  • Tailscale

Data & Messaging

  • PostgreSQL
  • Kafka
  • Redis
  • MySQL