CYBERSECURITY • AI SECURITY • SECURITY ASSESSMENT

Securing Technology.
Engineering Trust.
Exploring What’s Next.

Jeremy Alfananda — Cybersecurity & AI Security Professional

I work at the intersection of cybersecurity, security assessment, AI security, and technology transformation — helping organizations understand risk and build more resilient digital systems.

"Security is not a checkbox."

Security is not simply about finding vulnerabilities. It is about understanding how technology, people, processes, and business decisions interact — and turning that understanding into practical risk reduction.
01

Think in Systems

Security problems rarely exist in isolation.

02

Build Security In

Security should become part of engineering and business processes, not merely a final gate.

03

Use AI Carefully

AI creates new capabilities, but also introduces new attack surfaces.

More Than Security

My work sits between security strategy and technical implementation. I assess how systems and business processes can fail, translate technical risks into actionable decisions, and explore how automation and AI can strengthen security operations.

Security Assessment

Understanding vulnerabilities, threats, and business risks.

AI Security

Exploring secure design, testing, and governance for AI/LLM systems.

DevSecOps

Integrating security into engineering workflows and infrastructure.

Technology Transformation

Turning security requirements into practical technology solutions.

Career Timeline

2023–Present

Assistant Manager, CISO / Security Assessment

PT Bank Negara Indonesia (Persero) Tbk.

Focusing on security assessment, business process security, risk assessment, vulnerability identification, and aligning security with business processes.

2022

DevSecOps

PT Astra International Tbk.

Security monitoring automation, secure coding, Kubernetes, Docker, and integrating security into engineering workflows.

2021

Technology & Security Consulting

DIBERI UNTUK MEMBERI / Yourpay

Technology consulting, community/project development, leadership, and gamification strategy.

2020

Cyber Security Intelligent Officer

PT Bank Negara Indonesia (Persero) Tbk.

Penetration testing, server policy testing, LDAP server testing, and secure application development.

2017–2021

Bachelor's Degree in Cyber Security

Universitas Bina Nusantara (BINUS)

Technical Expertise

Security

  • Security Assessment
  • Threat Modeling
  • Vulnerability Assessment
  • Risk Assessment
  • Application Security
  • Penetration Testing
  • Security Strategy

AI Security

  • LLM Security
  • Prompt Injection
  • AI Threat Modeling
  • AI Application Security
  • Adversarial Testing
  • AI Governance

Engineering

  • DevSecOps
  • Kubernetes
  • Docker
  • Secure Coding
  • Automation
  • PHP / Java / LDAP

Frameworks & Standards

  • OWASP
  • CWE
  • ASVS
  • MSVS
  • STRIDE
  • DREAD

Certification Highlights

CompTIA Security+ Google Cybersecurity Assets, Threats, and Vulnerabilities Connect and Protect Foundations of Cybersecurity Play It Safe Tools of the Trade: Linux and SQL

Selected Work

Security research and engineering work translating principles into practical controls.

Flagship

Project 01 — Alfa Threat Model

An AI-assisted threat modeling platform designed to integrate threat modeling with security standards including CWE, OWASP, ASVS, MSVS, and DREAD. The platform utilizes LLM capabilities to assist threat modeling and features risk scoring based on DREAD methodology.

Note: Developed for specialized internal organizational requirements, not a publicly available SaaS.

Application → Threats → Vulnerabilities → Risk Score → Security Controls
Research

Project 02 — Securing AI & LLM Applications

Practical controls for AI/LLM applications focusing on threat modeling, prompt injection defense, adversarial testing, jailbreak testing, data leakage prevention, tool misuse prevention, RAG security, and continuous TEVV.

User Input

LLM Application

Security Controls
├── Prompt Security
├── Data Security
├── Tool Security
├── Model Security
└── Monitoring

Secure AI System
Engineering

Project 03 — AI-Assisted Secure Coding

Establishing an AI Code Security Gate. As "vibe coding" and AI-assisted development accelerate, this conceptual workflow introduces an additional security layer before traditional testing.

AI Generated Code

AI Behavior Analysis

Code Security Scan

Security Gate

DAST / SAST / Pentest

Production
Automation

Project 04 — Security Automation

Experience in integrating security seamlessly into engineering workflows using DevSecOps methodologies across Kubernetes, Docker, and secure coding practices.

Code → Build → Security Scan → Container → Runtime Monitoring → Alert

Thinking in Public

What People Say

"Jeremy is a highly skilled professional with a strong understanding of cybersecurity principles."

Alfred Radja Jaya

Let's Build Something Secure.

Have a security problem, technology challenge, or idea worth exploring?