Background.

Experience

Founder & Chief Executive Officer

2026now

Stealth Company (Cybersecurity Startup)

Building a cybersecurity startup focused on delivering practical security, governance, and enterprise protection solutions. Leading company strategy, product direction, client engagement, and service delivery while developing scalable cybersecurity offerings for modern organizations.

  • Founded and lead the company's vision, business strategy, and go-to-market initiatives for cybersecurity consulting and enterprise security solutions
  • Designed and structured service offerings spanning Governance, Risk & Compliance (GRC), Vulnerability Assessment & Penetration Testing (VAPT), and Security Solutions & Engineering
  • Driving the development of a SaaS platform focused on cybersecurity governance, risk management, asset management, vendor security, and organizational security operations
  • Leading solution architecture, client discovery sessions, proposal development, project delivery, and strategic partnership initiatives
  • Establishing operational processes, consulting methodologies, technical standards, and quality assurance practices to support scalable business growth
  • Building relationships with enterprise clients and technology partners while identifying new market opportunities and expanding the company's cybersecurity capabilities
Cybersecurity StrategyProduct StrategyBusiness DevelopmentGRCSecurity ConsultingSolution ArchitectureLeadershipStartup Operations

IT GRC Consultant & Penetration Tester

2024now

Whitesec ID (PT Topi Putih Siberindo)

Helping organizations strengthen cybersecurity posture through governance, risk management, compliance initiatives, and technical security assessments. Building audit-ready security programs while validating controls through practical testing.

  • Delivered 24+ security engagements across GRC and VAPT disciplines spanning technology, fintech, healthcare, and critical infrastructure sectors
  • Lead Auditor certified in ISO/IEC 27001:2022, ISO/IEC 27701, and ISO/IEC 42001 — leading gap analysis, risk assessment, annex A control mapping, SoA development, and evidence preparation through initial certification and surveillance audit cycles
  • Conducted web application, mobile, and API penetration testing following OWASP Testing Guide and PTES methodology — delivering CVSS-rated technical reports with reproduction steps and remediation guidance
  • Developed ISMS documentation suite — risk registers, risk treatment plans, SoA, security policies, procedures, and DPIAs — aligned to ISO/IEC 27001:2022 annex A controls and UU PDP compliance requirements
  • Built GRC One Dashboard, an internal compliance management application consolidating control tracking across ISO/IEC 27001, ISO/IEC 27701, SOC Type 2, Essential Eight, and UU PDP frameworks into a single unified view
  • Supported clients through full ISO 27001 lifecycle — from initial scoping and gap analysis, through risk treatment and control implementation, to certification audit readiness and post-certification surveillance
ISO/IEC 27001:2022ISO/IEC 27701GRCVAPTRisk AssessmentInternal AuditOWASPUU PDP

Security Engineer

20232024

Defenxor (PT Defender Nusa Semesta)

Delivered security operations support across enterprise client environments — deploying and tuning SIEM infrastructure, developing detection capabilities, and monitoring for threats across highly regulated industries including banking, healthcare, government, and critical infrastructure.

  • Deployed and configured Wazuh SIEM integrated with Elastic Stack (ELK) for multiple enterprise client environments, establishing centralized log ingestion pipelines, index management, and real-time event correlation workflows
  • Developed custom threat detection rules and correlation alerts covering Linux and Windows endpoint telemetry — tuned to client-specific environments to reduce false positive rates and improve actionable signal quality
  • Operated SOC monitoring functions for 7+ organizations across banking, healthcare, government, and critical infrastructure sectors — including PT Bank Hibank Indonesia, PT Bank Saqu Indonesia, PT Kalbe Farma, PT Prodia Widyahusada, PT Jakarta International Container Terminal, KPK, and PT Asuransi Jiwa Sequis Life
  • Performed continuous log analysis and security alert triage, classifying events by severity, correlating indicators across data sources, and escalating confirmed threats with documented findings and containment recommendations
  • Coordinated incident management and response activities for PT Bank Resona Perdania — conducting root cause analysis, reconstructing attack timelines, and producing post-incident reports aligned to client SLA requirements
  • Contributed to internal tooling development for incident tracking and event correlation workflows, improving SOC team operational efficiency and response consistency across concurrent client engagements
WazuhELK StackSIEMSOCThreat DetectionIncident ResponseLog AnalysisLinux

IT Support Intern

20222022

Faculty of Mathematics and Natural Sciences, University of Indonesia

Provided IT operations support for the computer laboratory facilities at FMIPA Universitas Indonesia — managing endpoint infrastructure, network deployment, and asset administration in a high-usage academic environment.

  • Administered Windows endpoint lifecycle and Microsoft 365 user accounts across laboratory workstations, handling provisioning, configuration, software deployment, and decommissioning
  • Assisted in structured cabling installation and network infrastructure deployment, including switch configuration, port assignment, and connectivity verification across laboratory segments
  • Maintained IT asset inventory and technical documentation — tracking hardware status, software licensing, and operational procedures to support laboratory continuity and audit readiness
WindowsMicrosoft 365Network InfrastructureIT SupportAsset Management

Education

Telkom University Bandung

2025now

Bachelor's Degree

Teknik Informatika (Informatics Engineering)

Focused on offensive security, governance, and emerging technology — covering penetration testing methodology, GRC frameworks, DevSecOps practices, and AI security.

SMK Harapan Bangsa

20202023

High School Diploma

Teknik Komputer & Jaringan (Computer & Networking)

Grounded in computer networking fundamentals — routing, switching, network infrastructure, and hands-on lab work with Cisco and Mikrotik equipment.

1st Place — Mikrotik Network Competition (50+ participants)