ISO/IEC 27001 & 27002
- ISO/IEC 27001 implementation
- ISO/IEC 27002 controls
Engineering · Applied AI · Security · Governance
I work at the convergence of software engineering, applied AI, and information security governance — building digital systems that are useful, scalable, secure, traceable, and ready for real operational environments. The four areas below reflect how that convergence shows up in practice.
Each area covers its capabilities, representative experience, the problems it typically addresses, and how it connects to the other three.
Backend and full-stack engineering for systems that need to work reliably in real operational environments — not only during initial development, but across years of change.
Software engineering is the foundation the other three areas build on: applied AI features, security controls, and governance requirements are all ultimately implemented in code and system design — part of a wider Build · Secure · Govern approach to a system.
Backend and full-stack engineering across hospital information systems, fintech, and a cybersecurity compliance platform — including work at Medify.id (hospital information systems, 2019–2022), Bebasinvestasi and TechX (backend engineering, from 2022), and Bitlion (contributing to a cybersecurity compliance self-assessment platform, from 2024).
Applied, product-oriented AI work: integrating generative AI and LLM-enabled capabilities into features that real users depend on, with attention to reliability and responsible use.
Since 2023, applied generative AI product work at Hoomy AI — an AI-assisted home-design product built for the Indonesian market, covering image-generation workflows, prompt and output evaluation, and reliability considerations for AI-enabled features.
Security treated as an engineering responsibility — built into architecture, authentication, data handling, and logging, rather than added after a system is complete.
Contributing to a cybersecurity compliance self-assessment platform at Bitlion (from 2024), alongside secure development practice across regulated systems — hospital information systems and a fintech platform — where access control, data protection, and traceability are core requirements.
Security engineering sits between software engineering and governance — turning security requirements into code and infrastructure decisions, while feeding evidence and control status back into governance and compliance work.
Translating security standards and governance requirements into structured, auditable engineering and organizational practice.
Representative experience. Experience and responsibility spanning ISO/IEC 27001 and ISO/IEC 27002 implementation, security governance, risk and control implementation, and audit readiness — applied through work on a cybersecurity compliance self-assessment platform and across regulated operational environments.
Governance & compliance gives the other three areas direction and accountability — translating standards into requirements for software engineering, applied AI, and security engineering, and closing the loop with evidence and audit readiness.