I work at the intersection of cybersecurity, security assessment, AI security, and technology transformation — helping organizations understand risk and build more resilient digital systems.
Security is not simply about finding vulnerabilities. It is about understanding how technology, people, processes, and business decisions interact — and turning that understanding into practical risk reduction.
Security problems rarely exist in isolation.
Security should become part of engineering and business processes, not merely a final gate.
AI creates new capabilities, but also introduces new attack surfaces.
My work sits between security strategy and technical implementation. I assess how systems and business processes can fail, translate technical risks into actionable decisions, and explore how automation and AI can strengthen security operations.
Understanding vulnerabilities, threats, and business risks.
Exploring secure design, testing, and governance for AI/LLM systems.
Integrating security into engineering workflows and infrastructure.
Turning security requirements into practical technology solutions.
PT Bank Negara Indonesia (Persero) Tbk.
Focusing on security assessment, business process security, risk assessment, vulnerability identification, and aligning security with business processes.
PT Astra International Tbk.
Security monitoring automation, secure coding, Kubernetes, Docker, and integrating security into engineering workflows.
DIBERI UNTUK MEMBERI / Yourpay
Technology consulting, community/project development, leadership, and gamification strategy.
PT Bank Negara Indonesia (Persero) Tbk.
Penetration testing, server policy testing, LDAP server testing, and secure application development.
Universitas Bina Nusantara (BINUS)
Security research and engineering work translating principles into practical controls.
An AI-assisted threat modeling platform designed to integrate threat modeling with security standards including CWE, OWASP, ASVS, MSVS, and DREAD. The platform utilizes LLM capabilities to assist threat modeling and features risk scoring based on DREAD methodology.
Note: Developed for specialized internal organizational requirements, not a publicly available SaaS.
Practical controls for AI/LLM applications focusing on threat modeling, prompt injection defense, adversarial testing, jailbreak testing, data leakage prevention, tool misuse prevention, RAG security, and continuous TEVV.
Establishing an AI Code Security Gate. As "vibe coding" and AI-assisted development accelerate, this conceptual workflow introduces an additional security layer before traditional testing.
Experience in integrating security seamlessly into engineering workflows using DevSecOps methodologies across Kubernetes, Docker, and secure coding practices.
As AI systems become connected to data, APIs, and business tools, security has to move beyond traditional application boundaries.
Read the Research"Jeremy is a highly skilled professional with a strong understanding of cybersecurity principles."
Have a security problem, technology challenge, or idea worth exploring?