$ echo "hello, world"

Portrait of Mahmut Can Kurt

Mahmut Can Kurt

Backend Developer / Istanbul, Türkiye

I turn tangled business processes into dependable software: workflow engines, multi-tenant PostgreSQL and event-driven Google Cloud pipelines that keep running while everyone else is asleep.

profile.json
// numbers from the Weoll backend
{
  "name": "Mahmut Can Kurt",
  "role": "Backend Developer",
  "yearsInBackend": 5,
  "commits": "2,700+",
  "mergedPullRequests": "450+",
  "serviceModules": "80+",
  "stack": ["Node.js", "TypeScript",
            "PostgreSQL", "Redis", "GCP"],
  "openToCoffee": true
}

about

// README.md

For nearly four years I have helped build and run Weoll, an intelligent business process management (iBPM) SaaS platform that manages the processes of 30,000+ employees. Companies hand it their approvals, tasks and documents, and it has to simply work.

I work across the whole backend: workflow engines, multi-tenant PostgreSQL, event-driven Google Cloud pipelines, security hardening and data protection. I care about code that is easy to read, safe to change and secure by default.

2,700+ commits, 450+ merged pull requests and 80+ service modules in, I still enjoy the hard parts.

experience

// git log --oneline --graph
  1. HEAD -> mainweoll

    Backend Developer @ Global IT (Weoll)

    Dec 2022 - Present

    Weoll combines no-code process design, contextual task management, relational data tables and AI-assisted document management in one platform. Trusted by:

    • Hepsiburada
    • Aras Kargo
    • Toyzz Shop
    • Yemeksepeti
    • Koleksiyon Mobilya
    • ODE Yalıtım
    • Happy Moon's
    • Osmanlı Yatırım
    • Gözalan Holding
    • Built and maintained the engine room of a multi-tenant SaaS: the Weoll backend (Node.js 22, TypeScript, JavaScript, Express.js) on PostgreSQL with an isolated database per customer (Knex.js), Firestore, Redis and Google Cloud, spanning 140K+ lines and 80+ service modules.
    • Made workflows run on schedule and on time: extended the no-code flow engine, where every node is an idempotent Cloud Task, with scheduled triggers, wait and delay steps, end-of-flow rollups, lookup placeholders inside flow actions and automatic alerts to admins when an approval step has no owner.
    • Gave customers a richer data model: built and refined lookup, rollup, formula and currency field types, filter options, bulk Excel import and export, and dependency-safe table deletion that topologically sorts multi-level foreign keys before dropping tables.
    • Opened the platform to outside collaborators: designed external (guest) user management on Firebase Identity Platform, with suspend and activate, instant Pub/Sub sign-out, per-customer external mail limits and guards that keep external users from seeing other externals or gaining admin rights.
    • Protected sensitive data: implemented a client-side encrypted field type, including encrypted phone and email fields, whose ciphertext stays out of search and filters and whose reset is limited to table admins and row owners.
    • Delivered reporting that scales: report filters, search, scheduled email snapshots and timezone-correct dates, plus chunked Cloud Tasks pipelines that turn large tables and reports into Excel files without blocking requests.
    • Built a complete audit trail: structured, paginated logs for table creation, schema and field changes, rollups, row edits, layout updates and flow-version activations, so administrators can always answer who changed what and when.
    • Hardened security: shipped ClamAV antivirus scanning for Cloud Storage uploads as a standalone Cloud Run service with quarantine, owner notification and audit logging; fixed a potential SQL injection path; added HTML sanitization to the page designer; wrote a PostgreSQL error-translation layer that turns SQLSTATE codes into clean client errors; kept dependencies patched.
    • Kept the platform fast and tidy: replaced a blocking Cloud SQL export with a task-driven polling pipeline, added a scheduled orphan-attachment cleaner, prepared the App Engine to Cloud Run move with OIDC-authenticated Cloud Tasks, delivered Android and APNs notification counts and integrated a Jira-backed support desk module.
    • Maintained ready-made Weoll Market apps such as announcements and polls, with Turkish, English and Romanian content and Swagger/OpenAPI documentation for every endpoint.
  2. arma

    Backend Developer @ Arma Group Holding

    Nov 2021 - Dec 2022
    • Automated data collection by building Python web-scraping bots that extracted data from a variety of web sources.
    • Designed a Django REST Framework backend with a MySQL database that powered the company website, from API design to server integration.
    • Served as Database Administrator for the Bul Search Engine and Bul Drive Storage projects, keeping the data layer of two cloud products healthy as part of the Cloud Team.
    • Engineered a Hadoop-based cloud cluster that strengthened the project's data processing and storage capabilities.
  3. intern/kobisi

    Software Engineering Intern @ Kobisi

    Jun 2020 - Aug 2020
    • Built the Node.js backend behind the mobile applications of Kobisi e-commerce projects, integrating robust, scalable e-commerce functionality into mobile platforms.
  4. intern/carpedu

    Software Engineering Intern @ Carpedu

    Sep 2019 - Dec 2019
    • Created a Python and Django web platform for psychology studies, integrating puzzles and visuals to support academic research.
  5. intern/tosia-tech

    Software Engineering Intern @ Tosia Tech

    Jun 2018 - Aug 2019
    • Created a Python and Django travel blog site that strengthened community engagement and content sharing.
    • Developed a secure virtualized payment system using blockchain technology.

skills

// stack.ts
stack.ts
export const stack = {
  languages: ["JavaScript", "TypeScript", "Python", "SQL", "Bash", "HTML", "CSS"],
  backend: ["Node.js", "Express.js", "NestJS", "Django", "Django REST Framework",
    "REST API", "OpenAPI/Swagger", "Microservices", "Event-Driven Architecture",
    "Workflow Automation", "Multi-Tenant SaaS"],
  databases: ["PostgreSQL", "MySQL", "NoSQL", "Firestore", "Redis", "Knex.js",
    "Database Administration", "Query Optimization"],
  cloud: ["Google Cloud Platform", "App Engine", "Cloud Run", "Cloud Tasks", "Pub/Sub",
    "Cloud Storage", "Cloud SQL", "Firebase", "Docker", "Hadoop", "Git",
    "Bitbucket", "Jira"],
  security: ["Authentication and Authorization", "Role-Based Permissions", "Data Encryption",
    "Antivirus Scanning", "SQL Injection Prevention", "Audit Logging"],
} as const;

education

// and the things I keep learning

Duzce University

B.Sc. Computer Science · Sep 2016 - Aug 2021

Languages

Turkish (Native) · English (IELTS Academic 6.0)

Certifications and courses

  • NVIDIA and AWS: deep learning and machine learning fundamentals, computer vision with TensorFlow and PyTorch
  • Udemy: Web Development with Python and Django; React and Context API
  • Carpedu: Python Software Language; Django Web Development; React Native and NodeJS

contact

// let's build something