Independent engineer · Sri Lanka, working across Europe

Backend systems for products that can't afford to fail.

I design and build the layer your business actually runs on — signature and identity infrastructure held to eIDAS standards, real-time platforms holding thousands of devices across unmanned sites, and the mobile products sitting on top. I also build my own: Signum, an eIDAS-aligned signature platform that runs on the customer’s own PKI.

Nine years, mostly as the senior engineer a founding team brings in when the architecture stops being optional.

Shehan Gamage
Shehan GamageEst. 2017
Available — Q4 2026
EngagementsFractional · project
OverlapCET + 3.5h
ReplyWithin 24 hours
9y
Shipping production backends
5,000+
Devices under management in one platform
4.7×
Revenue lift after digitalising a telco's distribution
eIDAS
Aligned signature infrastructure, built end to end
01 — Services

What I'm hired for

Four things, consistently. Each one starts with a two-week architecture assessment so the scope, risk and cost are on the table before anyone commits to a build.

S/016–16 weeks

Trust & signature infrastructure

PKI design, advanced electronic signatures and the architecture that keeps qualified reachable, HSM and EJBCA integration, audit trails that survive a compliance review. If your product needs to prove who did what, this is the part that has to be right.

EU DSSEJBCACloud HSMKeycloak
S/028–24 weeks

Real-time systems at scale

Alarming, telemetry and device fleets — the systems where latency is the product. I've run this at around five thousand devices across unmanned sites, on links that drop mid-command, and the failure modes are not theoretical to me.

GoONVIF / RTSPMQTTOpenTelemetry
S/03Zero to launch

Product build, backend through mobile

One person owning the API, the data model, the deployment and the iOS/Android client. Founders hire me for this when a hand-off between three contractors would cost more than the feature.

Spring BootFlutterPostgreSQLAWS
S/042 weeks · fixed

Architecture review & technical due diligence

A written assessment of what you have: scaling ceilings, security exposure, the three decisions that will hurt in eighteen months, and what it costs to fix each. Useful before a raise, an audit, or an acquisition.

Written reportThreat modelRoadmap

How an engagement runs

Fixed price where scope allows
Week 0 — free
Call

Forty-five minutes on the system and the constraint. You leave with a direction whether or not we work together.

Weeks 1–2 — fixed
Assessment

A written architecture and risk review with costed options. It stands alone — many engagements stop here, deliberately.

Weeks 3+ — milestones
Build

Shipped increments against agreed milestones, in your repo and your cloud from the first commit. Weekly written status.

Close
Handover

Decision records, runbooks and a walkthrough with whoever inherits it. Retained support monthly if you want it.

02 — Product

The one I own

A document-signing platform that produces PAdES-BASELINE-LT signatures a third party can verify without us — and that points at whichever certificate authority and timestamp authority the customer already trusts. Eight Spring Boot services, a Next.js editor, and the certificate lifecycle underneath. In staging, pre-release.

Pre-release · staging2024 — present

Signum

Document signing that runs on your PKI, not ours

Co-founded with a German partner. I own the architecture, the PKI and the build; the Kubernetes staging deployment is my co-founder’s.

If you are building your own signature stack, I am the supplier here, not the competitor.

Signum document editor — signature and date fields placed on an agreement, with the field palette alongside
Signature level
PAdES-BASELINE-LT
Standard
ETSI EN 319 142 · EU DSS 6.1
Legal class
Advanced (AdES) — not qualified
Trust
Bring your own CA · EJBCA CE by default
Revocation
OCSP + CRL, embedded at signing
Timestamps
RFC 3161, configurable TSA
Backend
8 Spring Boot services · Kafka · PostgreSQL
Status
Staging · pre-release
Java 17Spring BootSpring Cloud GatewayEU DSSEJBCAKeycloakHashiCorp VaultPostgreSQLKafkaMinIONext.jsReactTypeScriptDockerPrometheus · Grafana · Loki
03 — Selected work

Things that shipped

Seven systems delivered across security, telecoms and consumer software. Several are under NDA at the client's name — the engineering is described, the logo isn't.

Flagship2022 — present

Real-time video surveillance platform

Four years on the platform a German security provider runs its control rooms on — around 5,000 devices across unmanned tower sites, with more vendors being onboarded now. I built the Flutter app it ships to customers, the Go tool that brought new towers online, the device-discovery subsystem in the current React console, and the self-hosted map stack underneath all of it.

Device discovery, in production: sweep a tower subnet, fingerprint every camera, NVR, speaker and router read-only, then confirm identity with exactly one scoped credential per device — trying a second would lock the account out
Replaced the commercial basemap and satellite imagery with a self-hosted OSM tile server, geocoder and government orthophoto feeds, live in production
Multi-vendor hardware provisioning in Go, and the Flutter client the customer-facing side runs on
ONVIF PTZ that stays usable over a tower VPN: one move command in flight per camera with the newest velocity superseding the queue, and a cached ONVIF session carrying the camera’s own clock skew
GoTypeScriptNestJSReactFlutterONVIF · RTSP
Alarm handling interface — device telemetry and camera list, a live camera pane with a motion detection box, an event timeline, and an escalation runbook with contact steps
Interface prototype — the client’s production system, sites and data are not shown.
W/01 · InfrastructureNDA

Provi — device provisioning

A Go system that discovered, configured and managed routers, NVRs, cameras and speakers across a fleet of unmanned sites. I wrote the driver abstraction over the multi-vendor hardware, the subnet scanner and the identification passes; a second engineer covered the rest. CLI and GUI modes for field engineers. Its identification layer is what the current platform’s discovery service grew out of.

GoPostgreSQLDocker
W/02 · GeospatialNDA

Self-hosted map and imagery stack

Took a surveillance platform off its commercial map and satellite providers. An OpenMapTiles-generated tile server and a Nominatim geocoder, plus aerial orthophotos stitched from every German state’s WMS and the Dutch national feed — seventeen providers, each with its own bbox, zoom range and attribution obligation. The whole config generates from one source-of-truth JSON, so adding a region is data entry. In production.

DockerMapLibrePythonCaddy
W/03 · TelecomsVisit ↗

SIMS — distribution management

Sri Lanka's state mobile operator ran SIM distribution on paper. My team replaced it with a Java servlet platform; I built the Android side of it end to end — the field rep app, the transaction-management app and the director dashboard — plus the servlet endpoints they talk to and the console for administering app users and settings. Sixty-plus releases across three years, still versioned past 6.x when I handed it over.

JavaServlets · JSPMySQLAndroid
W/04 · SaaSProduct

SAAT — time tracking

Multi-platform time tracking with team management, Keycloak-backed OAuth2/OIDC and real-time sync across desktop and web. Flyway-managed migrations so schema changes ship without a maintenance window.

Spring BootFlutterKeycloak
W/05 · TelecomsClient system

Prepaid reload terminal

A counter terminal for prepaid top-ups, driving an external multi-SIM module over a raw Bluetooth serial socket. A top-up is a conversation with the operator over USSD and SMS, and neither side is reliable: replies arrive split across messages, wording drifts between networks, and the module stops answering. I wrote the byte-stream transport, the per-operator command layer for five mobile networks and three fixed-line brands, multipart SMS reassembly by byte boundary, and fuzzy matching over confirmation text so a reworded operator reply does not read as a failed sale. Operator command codes sit in a JNI library rather than in dex.

Android · JavaNDK · JNIBluetooth SPPUSSD · SMS
W/06 · Field salesClient system

EzDeal — offline-first van sales

A distributor app for reps who spend the day out of coverage and still have to hand each shop a printed invoice. Offline login, offline stock and invoicing over a file-backed local store that expires on a timer so nobody sells against stale stock, client-side invoice numbering that survives the sync, and a rolling two-week local purge with backup upload. Bluetooth thermal printing, QR scanning for customer lookup, GPS route tracking, and a server-driven force-update channel for when a rep is three versions behind. Shipped to v5.3.1 over three years.

Android · JavaOffline syncML KitBluetooth printing

And the work that never gets written up

Seven systems is the part worth showing. Most of nine years is the other kind: the admin console nobody demos, the migration that has to run once and be right, the integration against an API written in 2011. It is unglamorous and it is most of the job.

Domains
Physical securityTelecomsGeospatialField salesWorkforcee-SignatureConsumer apps
Surfaces
Backend servicesiOS · AndroidDesktopCLI toolingWeb consolesDevice firmware integration
Recurring work
Data migrationsThird-party integrationsOffline syncDevice provisioningAuth & SSOObservabilityDeployment pipelines

Different clients, different stacks, same brief — it has to keep working after I leave.

04 — Track record

Where I've been

Two companies founded, one long-running engagement with a German security provider, and a consistent pattern: brought in early, stayed through production.

2022 — Present
Remote · Germany

Senior Engineer · Contract

German security provider — video surveillance

Four years across one platform’s stack, in an internationally distributed team: the Flutter customer app from its first commit, the Go provisioning tool for multi-vendor tower hardware, the device-discovery service in the current React web console, and the self-hosted map infrastructure under all of it. Around 5,000 devices, with new vendor families still being integrated.

GoTypeScriptReactFlutterONVIF
2024 — Present
Sri Lanka · EU clients

Co-Founder & Managing Director

Signum · QuickPath Technologies

Two ventures of my own. Signum is an eIDAS-aligned electronic signature platform for the European market, built to run on the customer’s own PKI and co-founded with a German partner — I own the architecture, the PKI and the build. Every service runs in Docker, with a Prometheus, Grafana and Loki stack in front of it, because a signature platform has to be able to show what happened. QuickPath is the studio behind the delivery work, and the team that scales when a project outgrows one engineer.

Spring BootDockerKafkaKeycloakGrafana · Loki
2018 — 2023
Sri Lanka

Co-Founder & Full-Stack Developer

E Z Soft Technologies

Built enterprise data systems for a national Sri Lankan telecommunications operator — SIM distribution, transaction management, and the mobile apps the distributor network ran on. High-throughput schemas and a Docker deployment pipeline.

JavaMySQLDocker
2023
Remote

Backend Engineer

emvoy

Short engagement on a workforce management platform: REST APIs, PostgreSQL query optimisation, auth flows and AWS deployment.

GoPostgreSQLAWS
05 — Toolkit

What I work in

Daily drivers, not a list of everything I've touched. Go and TypeScript carry most of the backend weight now, Java the older systems; Flutter and native Swift carry the clients.

Backend & web
GoTypeScriptNestJSReactJavaSpring BootPython
Mobile
FlutterAndroid — Java · KotliniOS — Swift
Native desktop
Swift · SwiftUIRust · TaurimacOS
Devices & protocols
ONVIFRTSPMQTTBluetooth SPPNDK · JNI
Data
PostgreSQLMySQL
Trust & identity
EJBCAEU DSSHashiCorp VaultCloud HSMKeycloakOAuth2 / OIDC
Geospatial
MapLibreOpenMapTilesNominatimWMS
Infra & ops
DockerAWSCaddyKafkaPrometheusGrafanaLokiOpenTelemetry
06 — Approach

How I work

Also worth knowing
Based in Sri Lanka, 3.5 hours ahead of CET — my afternoon is your morning.
CCNA in progress; networking is a real part of the surveillance work.
English, working async, written-first.

Most systems don't fail at the feature level. They fail at the decisions nobody wrote down.

01
Constraints before code

Compliance regime, latency budget, data residency, failure tolerance. These decide the architecture; everything after is implementation. Getting them wrong is the expensive mistake.

02
Boring technology, deliberately

Postgres, Kafka, Spring, Go. Proven components leave the novelty budget for the part of your product that’s actually novel — and leave a codebase your next engineer can read.

03
Observable from the first deploy

Metrics, traces and structured logs go in with the first service, not after the first incident. In regulated systems this is a compliance requirement anyway.

04
Written decisions, handed over

Every engagement leaves architecture decision records behind. You should be able to replace me without archaeology — that's the point of hiring someone senior.

07 — Notes

Writing

Case studies and postmortems from systems I have shipped or broken.

All essays →
Fit

Who I'm useful to

Saying this plainly saves us both a call. I'd rather turn down work than take an engagement where I'm the wrong answer.

A good fit
+You have a compliance, security or identity surface and the cost of getting it wrong is real.
+Latency, throughput or device scale is the hard part of your product, not a nice-to-have.
+You're a founder who needs one senior person owning backend through mobile, not three contractors.
+You want the decisions written down, so the work survives my leaving.
Probably not
Marketing sites, CMS builds, or anything where the backend is a form handler.
Staff augmentation by the hour with no say in architecture — you'll get better value elsewhere.
Work that needs to start next week with the scope still undefined.
Projects where "we’ll add security later" is the plan. I’d be the wrong hire.
08 — Contact

Tell me what you're building.

One email is enough to start. Describe the system, the constraint you're worried about, and roughly when it needs to exist — I'll tell you honestly whether I'm the right person.

info@shehan.dev
Good first email
— What the system does
— The constraint that worries you
— Timeline and rough budget band
— Whether you need me, or a team