Cyber Security Manager
since 05.2022 - Till the present day |Acclime Group
Kali Linux, Acunetix, Burp Suite, OWASP ZAP, Metasploit, Wireshark, Fortigate Firewall, DLP by GTB Technology, ESET Antivirus/malware, ELK Stack, Splunk, Sophos EndPoint Security, Sonicwall Firewall, Azure AD, ISO27001, PCIDSS
The roles and responsibilities as Information Security are:
● Provided Information security leadership to the Information Technology team, and proactively manage risks and issues of Information security.
● Provided security consultancy, security architecture, technical guidance, security incident investigation, expertise and solution on cyber security.
● Performed development and maintenance of IT Security compliance and policy.
● Coordinating and auditing compliance and certification requirements.
● Lead and manage Business Continuity Plan and Disaster recovery.
● Managed NextGen Firewall (Sonicwall).
● Managed End Point Antivirus and Malware (Sophos).
● Managed Microsoft 365 Online security.
● Performed regular IT security activities such as performed log review, access right (physical and logical) reviewed, patch management, security incident response.
Accomplishment during work are as follow:
● Developed project management timelines and coordinating to all stakeholder due to ISO27001 Certification project.
● Developed and implement IT security policy from the scratch.
● Developed IT Assessment and performing annual IT Risk base on ISO 27005.
● Re-define and automation IT Asset into Asset Management System using ManageEngine.
● Delivered ISO 27001 Accreditation for Indonesia office.
IT Security Lead
09.2020 - 05.2022 |Flow
Kali Linux, Acunetix, Burp Suite, OWASP ZAP, Metasploit, Wireshark, Fortigate Firewall, DLP by GTB Technology, ESET Antivirus/malware, ELK Stack, Splunk, Sophos EndPoint Security, Sonicwall Firewall, Azure AD, ISO27001, PCIDSS
The roles and responsibilities as Information Security are:
● Provided Information security leadership to the project team, and proactively manage risks and issues of Information security.
● Provided security consultancy, technical guidance, expertise and solution on IT security.
● Performed development and maintenance of IT Security compliance and policy.
● Coordinating and auditing compliance and certification requirements.
● Lead and manage Business Continuity Plan and Disaster Recovery.
● Cyber security awareness and training.
● Managed Data Leakage Prevention/DLP (GTB Technology).
● Managed End Point Antivirus and Malware (ESET).
● Performed regular IT security activities such as performed log review, access right (physical and logical reviewed), patch management, monitoring Incident Response.
Accomplishment during worked are as follow:
● Developed and implement IT Security Policy base on ISO 27001 from the scratch.
● Answered and Managed IT security requirements and audit of Client such as DBS Bank (Indonesia and India), HSBC Vietnam, Home Credit.
● Developed IT Risk Dashboard and performed annual IT Risk base on ISO 27005.
● In progress Developing Log Management/SIEM using ELK Stack.
● Managed and prepared documentations regarding to ISO 27001 certification.
● Delivered ISO 27001 Accreditation.
Information Security and Business Continuity
12.2019 - 02.2020 |MNC Bank International
Kali Linux, Acunetix, Burp Suite, OWASP ZAP, Metasploit, Wireshark, Fortigate Firewall, DLP by GTB Technology, ESET Antivirus/malware, ELK Stack, Splunk, Sophos EndPoint Security, Sonicwall Firewall, Azure AD
The roles and responsibilities as Information Security are:
● Provided Information security leadership to the IT team, and proactively manages risks, issues and scope throughout the project life cycle.
● Provided security consultancy, technical guidance, expertise and solutioning on cyber security.
● Performed maintenance of IT Security compliance and policy.
● Managed Network security devices (Fortigate Firewall and IPS/IDS).
● Managed and answer audit finding by OJK and Internal Audit related to IT Security.
Accomplishment during worked are:
● Provided security requirement for new mobile banking development (Android and IOS).
● Performed security testing for new mobile banking (Android).
● Performed review Hardening Standard procedure for OS and Database Server.
● Performed review firewall policy regarding to OJK audit finding.
Information Security Specialist
01.2019 - 11.2019 |Wirecard Digital Technology
Kali Linux, Acunetix, Burp Suite, OWASP ZAP, Metasploit, Wireshark, Fortigate Firewall, DLP by GTB Technology, ESET Antivirus/malware, ELK Stack, Splunk, Sophos EndPoint Security, Sonicwall Firewall, Azure AD, ISO27001, PCIDSS
The roles and responsibilities as Information Security are:
● Provided Information security leadership to the project team, and proactively manages risks, issues and scope throughout the project life cycle
● Performed secure code analysis and Penetration testing due to Application or product Development.
● Performed maintenance of IT Security compliance and policy (PCI-DSS, ISO 27001) regional or local to identify and map control objectives.
● Review Application features and User Story accordance to IT Security Development compliance (PCIDSS, OWASP, ISO 27001).
Accomplishment during worked are:
● Performed secure code analysis and Penetration Testing PrimeCash v6 as Cash Management System in AffinBank, Malaysia.
● Mapping all features Cash Management System with Regulation (BI, OJK) and Framework Compliances (PCIDSS, OWASP, ISO 27001).
IT Senior Consultant / IT Security Consultant
03.2015 - 09.2018 |Sofrecom
Kali Linux, Acunetix, Burp Suite, OWASP ZAP, Metasploit, Wireshark, Fortigate Firewall, DLP by GTB Technology, ESET Antivirus/malware, ELK Stack, Splunk, Sophos EndPoint Security, Sonicwall Firewall, Azure AD, ISO27001, PCIDSS
The roles and responsibilities as IT Senior Consultant/IT Security Consultant are:
● Provided Design Architecture & Concept, Strategic Planning, Project Planning, Project Delivering, Assessment and Audit, Gap Analysis.
● Provided technical leadership to the project team, and proactively manages risk, issues and scope throughout the project life cycle.
● Involved in Penetration testing due to IT security assessment project.
Accomplishment during worked as IT Consultant:
● Ministry of Communication and Information, National Data Center Assessment and Feasibility Study.
● Telkomsel, Telkomsel Telecommunication Center and STO (Sentral Telepon Otomat) Core Network istpOperation Excellent (CNOX) Audit.
● Assesment and review for Confidentiality, Integrity and Availabilty of 16 TTC and 4 STO base on ISO 27001.
Indosat Ooredoo Security Assessment and Penetration Testing:
● Vulnerability assessment including Core Network, DNS, WAP GW, Border GW, firewall, routers, servers, Operating System, Database, Applications.
● IM2, Identification of IM2 Information Technology synergy areas within Qtel Group.
IT Project Manager
03.2013 - 03.2018 |Sofrecom
Analytics, Research
The roles and responsibilities as Project Manager are:
● Provided project plan and time management, monitoring progress, reporting and documentation.
● Provided technical leadership to the project team, and proactively manages risk, issues and scope throughout the project life cycle.
● Improve high level of understanding of the organization's business systems and ensure the quality of software developed.
The Accomplishment during worked as follow:
● Telkomsel Analytics and Research, Insight Business Intelligent Portal Project.
The Portal serves information from Marketing activities such as campaign, analytics, insight, competition, product, survey and other activities from various business units in Marketing Directorate.
● Gaia or I-SISKA Change Request 2014 for Telkom Indonesia.
Senior BSS / OSS Consultant
01.2007 - 08.2017 |Sofrecom
BSS / OSS, CRM
The roles and responsibilities as Senior Functional Expert are as follow:
● Managed and provide detail requirement and testing plan Customer Care, Network Management and billing system functionalities.
● Managed and provide analysis of anomalies/bugs or change request.
● Managed 1-st and 2-nd level maintenance support of Gaia as BSS.
Accomplishment during Gaia or i-siska Implementation and maintenance:
● Migration for 11 millions subscriber and 7000 users in 7regions all around Indonesia this include for 5 modules which are G.Contact, G.Network, G.Billing, G.Fault, and G.Catalog.
● Defined and implemented Telkom's Indonesia Products, Packages, Service, Tariff Offers and rate plan of POTS, ADSL, Leased Line in Gaia Catalog.
● Standarization of Telkom's Indonesia Network configuration in G.Network.
● Managed 1-st and 2-nd level maintenance support.
● Integration Gaia as BSS with OS3/Tenoss as OSS and TREMS (SAP) as Revenue Management.
Accomplishment during Girafe Maintenance are:
● Girafe Maintenance for 6 regions of Telkom Indonesia Access Code for Indosat SLJJ Multi Service Bundling Discount Tariff promotion night offer.
System Analyst
02.2000 - 04.2007 |Thames Pam Jaya
CRM
The roles and responsibilities as System Analyst are as follow
● Improved of analysis and design of structured adjustment CRM, Billing and Job Management System.
● As a leader of projects due to adjustment of Billing and Job Management System.
● Provided technical leadership to the project team, and proactively manages risk, issues and scope throughout the project life cycle.
● Improved high level of understanding of the organization's business systems and ensure the quality of SEP Software developed.
Accomplishment during Implementation and maintenance:
● Customer Care and Billing System adjustment and Improvement.
● Stamp duty electronic between TPJ and Dirjen Pajak (Tax Directorate).
● Customer Care data message between PAM Jaya and TPJ.
● Payment Banking (BCA, BNI, BUKOPIN and NISP).
● Master Cetak/Bayar as row data reconciliation with PAM Jaya.
● All the corporate KPl's reports.
● Job Management System Implementations.
● Integration of Customer care and billing system, Job management System and GIS.
● Datawarehouse and business Intelligence development Developed Request of Proposal for new Customer care and Billing.
Programmer
01.1999 - 01.2000 |Layar Sentosa Shipping
C/C++, PL/SQL, Java, .NET, Developer/2000, Unix Shell, Python, Jira, Confluence
● Developed Human Resources Information System.
● Developed Logistic Application.
● Developed Account Receivable Application.