Skip to main content
Muhammad HafizhuddinMH
Open to opportunities

Muhammad Hafizhuddin

@muhammadhafizhuddin

Information Security Compliance Specialist advising IAM, Secure SDLC, and GCP security architecture for regulated banks.

Indonesia
Message

What I'm looking for

I want to help regulated organizations turn ISO/NIST/OWASP requirements into practical controls for IAM, Secure SDLC, and GCP security posture—owning security governance, VAPT coordination, and evidence-ready reporting with strong cross-team collaboration.

I’m an information security professional with 4+ years of experience across GRC and technical security operations in Indonesian financial services. I currently advise on IAM, Secure SDLC, and cloud security architecture for a digital bank on Google Cloud Platform.

I serve as a security champion and primary cybersecurity liaison across squads, translating group-level information security frameworks into operational controls, exception tracking, and management/regulatory reporting. I’m also a Certified Lead Auditor across ISO/IEC 27001, 27701, and 42001, which guides how I assess governance and evidence quality.

In Secure SDLC and security governance, I review and embed security requirements through Functional & Technical Specification Documents (FSD/TSD), perform threat modeling, and support Secure SDLC gates. I coordinate end-to-end VAPT for GCP and application environments, including scoping DAST testing prerequisites to ensure accurate coverage of the application attack surface.

Across cloud security and operations, I define secure cloud architecture patterns and baseline controls aligned to GCP Well-Architected and the GCP shared-responsibility model, and I validate cloud security posture against ISO 27001, NIST, and OWASP (including OWASP Top 10). Previously, I reviewed privileged access and firewall change controls, supported major migrations and remediation governance, and improved evidence-collection processes for ISO 27001, PCI-DSS, and OWASP alignment—earning a Certificate of Recognition for DBank Pro 2.0.

Experience

Work history, roles, and key accomplishments

PI
Current

Cyber Security Advisory Analyst

PT Bank Saqu Indonesia

Nov 2025 - Present (8 months)

Serves as a primary cybersecurity liaison and security champion, advising on IAM, secure-by-design SDLC governance, and GCP security architecture for a digital bank. Coordinates threat modeling, VAPT/DAST activities, and compliance alignment with ISO 27001, NIST, and OWASP.

PI

IT Security Assurance

PT Bank Danamon Indonesia

Feb 2024 - Oct 2025 (1 year 8 months)

Reviewed privileged access and firewall change control documentation to support least-privilege, segregation of duties, and controlled connectivity changes. Conducted Secure SDLC gate reviews (FSD/TSD) and supported vulnerability assessment and remediation closure across key banking systems.

PI

IT Helpdesk Security

PT Bank Negara Indonesia

Jun 2022 - Feb 2024 (1 year 8 months)

Authored FSD/TSD documentation and user guides for an endpoint-security whitelisting project supporting 1,000+ ATM/CRM devices. Supported DLP and EDR monitoring and configured firewall inbound/outbound rules for ATM/CRM application connectivity.

Education

Degrees, certifications, and relevant coursework

Gadjah Mada University logoGU

Gadjah Mada University

Bachelor's Degree (S1), Archaeology

2016 - 2021

Earned a Bachelor's Degree (S1) from Gadjah Mada University in Yogyakarta, majoring in Archaeology, from 2016 to 2021.

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan