Engineering · Applied AI · Security · Governance

Expertise

I work at the convergence of software engineering, applied AI, and information security governance — building digital systems that are useful, scalable, secure, traceable, and ready for real operational environments. The four areas below reflect how that convergence shows up in practice.

Convergence diagram: Build · Secure · Govern, reinforced by four connected domains — Software Engineering, Applied AI, Security, and Governance.

Four areas of practice

Each area covers its capabilities, representative experience, the problems it typically addresses, and how it connects to the other three.

01

Software Engineering

Backend and full-stack engineering for systems that need to work reliably in real operational environments — not only during initial development, but across years of change.

Connects to

Software engineering is the foundation the other three areas build on: applied AI features, security controls, and governance requirements are all ultimately implemented in code and system design — part of a wider Build · Secure · Govern approach to a system.

Capabilities

  • Backend engineering
  • API design
  • Database architecture
  • Application architecture
  • System integration
  • Maintainability
  • Testing strategy
  • Observability
  • Performance
  • Software delivery

Representative experience

Backend and full-stack engineering across hospital information systems, fintech, and a cybersecurity compliance platform — including work at Medify.id (hospital information systems, 2019–2022), Bebasinvestasi and TechX (backend engineering, from 2022), and Bitlion (contributing to a cybersecurity compliance self-assessment platform, from 2024).

Problems addressed

  • Systems that need to stay maintainable as they grow across teams and years, not just at launch.
  • APIs and integrations that must remain reliable as usage and complexity increase.
  • Database and application architecture decisions that affect long-term operability.
  • Gaps in testing, observability, and delivery practice that make change risky.
02

Applied AI

Applied, product-oriented AI work: integrating generative AI and LLM-enabled capabilities into features that real users depend on, with attention to reliability and responsible use.

Capabilities

  • AI-enabled product development
  • Generative AI integration
  • Image-generation workflows
  • LLM-enabled applications
  • Prompt and output evaluation
  • AI service integration
  • Operational cost awareness
  • Reliability and monitoring
  • Responsible handling of user inputs
  • Human review and fallback design

Problems addressed

  • Turning a generative AI capability into a dependable, user-facing product feature.
  • Evaluating AI-generated output for quality and appropriateness before it reaches users.
  • Keeping AI-enabled features reliable, monitored, and cost-aware in production.
  • Deciding where human review and fallback are needed around AI-generated results.

Representative experience

Since 2023, applied generative AI product work at Hoomy AI — an AI-assisted home-design product built for the Indonesian market, covering image-generation workflows, prompt and output evaluation, and reliability considerations for AI-enabled features.

Hoomy AI home-design product homepage
Connects to

Applied AI work still has to be built like software, secured like any user-facing feature, and governed where AI-generated output carries risk — connecting back to software engineering, security engineering, and governance.

03

Security Engineering

Security treated as an engineering responsibility — built into architecture, authentication, data handling, and logging, rather than added after a system is complete.

Problems addressed

  • Access control, authentication, and authorization that hold up under real usage.
  • Sensitive data and secrets that need protection across the system, not just at the edges.
  • Audit trails and logging that make security-relevant events traceable after the fact.
  • Vulnerabilities and threats that need to be considered during design, not only after release.

Representative experience

Contributing to a cybersecurity compliance self-assessment platform at Bitlion (from 2024), alongside secure development practice across regulated systems — hospital information systems and a fintech platform — where access control, data protection, and traceability are core requirements.

Connects to

Security engineering sits between software engineering and governance — turning security requirements into code and infrastructure decisions, while feeding evidence and control status back into governance and compliance work.

Authentication
Logging and audit trails
Least privilege
Data protection

Capabilities

  • Secure software development
  • Authentication
  • Authorization
  • Data protection
  • Secure APIs
  • Logging and audit trails
  • Secrets management
  • Threat-aware design
  • Vulnerability handling
  • Security requirements
  • Least privilege
  • Traceability
04

Governance & Compliance

Translating security standards and governance requirements into structured, auditable engineering and organizational practice.

Representative experience. Experience and responsibility spanning ISO/IEC 27001 and ISO/IEC 27002 implementation, security governance, risk and control implementation, and audit readiness — applied through work on a cybersecurity compliance self-assessment platform and across regulated operational environments.

Capabilities

ISO/IEC 27001 & 27002

  • ISO/IEC 27001 implementation
  • ISO/IEC 27002 controls

Risk & Control

  • Risk assessment
  • Control ownership
  • Control-effectiveness thinking

Audit Readiness

  • Evidence management
  • Cybersecurity self-assessment
  • Audit readiness
  • Policy-to-engineering translation
  • Continual improvement

Problems addressed

  • Translating security standards and controls into practices engineering teams can actually execute.
  • Structuring evidence and control ownership so audits and assessments are less disruptive.
  • Assessing risk in a way that connects to concrete engineering and process decisions.
  • Sustaining control effectiveness and improvement over time, not just at a single audit point.

The Govern Link

Governance & compliance gives the other three areas direction and accountability — translating standards into requirements for software engineering, applied AI, and security engineering, and closing the loop with evidence and audit readiness.

Start a discussion

Interconnected expertise

Convergence diagram: Build · Secure · Govern, reinforced by four connected domains — Software Engineering, Applied AI, Security, and Governance.

Open to professional discussions and selected collaborations.