Aldi Ramdhani Herawan

CTO

Jakarta, Jakarta, Indonesia24 yrs 6 mos experience
Highly Stable

Key Highlights

  • Proven leader in information security strategy and governance.
  • Expertise in regulatory compliance and risk management.
  • Strong technical background in cybersecurity and infrastructure.
Stackforce AI infers this person is a cybersecurity leader in the Fintech industry with extensive experience in risk management and compliance.

Contact

Skills

Core Skills

Cyber Risk ManagementLeadershipCyber Security RiskCybersecurityIt Management

Other Skills

Analytical SkillsApplication SecurityAttention to DetailBudgeting & ForecastingCISACertified Information Security Manager (CISM)Certified in Risk and Information Systems Control (CRISC)Cisco Firewall SecurityCisco IPSCisco VPNCommunicationComputer ForensicsConversion OptimizationCryptographyCyber Policy

About

Experienced Professional with a demonstrated history of working in the Financial and Technology Industry. Broad and strong technical and business knowledge on various Information Security domains. Eagerly passionate in a Strategic Managerial position the Information Security area that offers Professional growth while being resourceful, innovative and flexible.

Experience

Amartha

Head of Information Security

Jan 2024Present · 2 yrs 2 mos · South Jakarta, Jakarta, Indonesia · On-site

  • Strategic Leadership
  • Create and execute cybersecurity strategy aligned with business goals
  • Build security policies and governance frameworks
  • Communicate security needs to executives and board members
  • Compliance & Risk Management
  • Ensure compliance with regulations (POJK, PBI, UU PDP, ISO27001)
  • Conduct regular risk assessments and security audits
  • Work with legal teams to meet regulatory requirements
  • Security Architecture
  • Design security for all systems, apps, and networks
  • Secure payment systems, lending platforms, and customer databases
  • Review security of new technologies and integrations
  • Incident Response
  • Create incident response plans and lead investigations
  • Handle breach notifications and customer communications
  • Minimize business disruption during security events
  • Team Management
  • Lead security team (analysts, engineers, GRC, data privacy specialists)
  • Develop training programs and security awareness campaigns
  • Create career paths and manage team performance
  • Vendor Risk Management
  • Assess security risks from partners and vendors
  • Set security requirements for third parties
  • Monitor ongoing vendor security and manage data sharing agreements
  • Security Technology
  • Select and implement security tools (SIEM, endpoint protection, encryption, etc)
  • Monitor security operations and establish performance metrics
  • Maintain and configure security systems
  • Business Continuity & Fraud Prevention
  • Work with fraud teams to prevent financial crimes
  • Develop business continuity and disaster recovery plans
  • Protect against external and internal threats
Cyber Risk ManagementLeadershipInterpersonal SkillsISO 27001Resource AllocationCyber Policy+8

Career Break

Jun 2023Dec 2023 · 6 mos · Jakarta Metropolitan Area

Goto financial

3 roles

Head of Information Security - Commerce Enablement

Promoted

Sep 2021Jun 2023 · 1 yr 9 mos

  • GoTo Financial is the Fintech pillar of GoTo Group companies. Commerce Enablement is a business unit at GoTo Financial that focuses on the offline merchants segment.
  • The Products under Commerce Enablement are :
  • Moka POS - https://www.mokapos.com/
  • GoStore - https://www.mygostore.com/
  • GoKasir - https://gobiz.co.id/gokasir
  • Selly - https://www.selly.id/
  • As the Head of Information Security in Commerce Enablement, my responsibilities includes :
  • Strategic Security Leadership: Head of Information Security, I provide visionary leadership in developing and executing the organization's information security strategy. I align security initiatives with business objectives, ensuring that security is an enabler, not an obstacle, to growth.
  • Comprehensive Risk Management: I oversee the identification, assessment, and management of cyber security risks. My role involves conducting thorough risk analyses to prioritize and implement security measures that protect the organization's critical assets and data.
  • Incident Response and Recovery: Spearhead incident response and forensic investigations, delivering actionable insights for continuous improvement. In the event of a security breach, I orchestrate swift and efficient responses, minimizing damage and ensuring a rapid return to normal operations.
  • Security Governance: I establish and maintain a robust security governance framework, including security policies, standards, and procedures. I work closely with internal and external stakeholders to promote a culture of security awareness and compliance.
  • Regulatory Compliance: I ensure that the organization complies with relevant industry regulations and standards such as ISO 27001, PDPA, PSE Kominfo. This includes establishing and maintaining policies and procedures to meet compliance requirements.
CommunicationLeadershipIT Security AssessmentsInterpersonal SkillsResource AllocationAttention to Detail+13

Information Security Manager (DevSecOps Leads) - Merchant Platform (GoBiz)

Jan 2020Jan 2022 · 2 yrs

  • Information Security Manager (DevSecOps Leads) manages a team of Security Engineers, with the main goal is to Build an effective and efficient information security measures for all GoBiz's Cloud-based Infrastructure
  • Responsibilities includes :
  • Develop and oversee the organization's infrastructure security architecture
  • Assess and oversee the design and implementation of new infrastructure tools technologies
  • Implement effective and efficient risk-bases security measures through automation and orchestration
  • Observe and monitor the evolving threats and vulnerability that might impact GoBiz's Infrastructures
  • Conduct Incident Responses and Forensic investigations
  • Produce various relevant security metrics
  • Simplify security-related processes with automation and orchestration
  • Work with different stakeholders to reduce cybersecurity risks
CybersecurityCommunicationLeadershipIT Security AssessmentsInterpersonal SkillsISO 27001+18

Information Security Manager - GoMerchants

Jan 2019Dec 2019 · 11 mos

  • GoMerchants is a group withing the Gojek organization which focus in handling merchants-related business processes. Midtrans and SPOTS are two of the companies within the Scope of GoMerchants.
  • As an Information Security Manager at Gojek (GoMerchants) my goals are to identifies, develops, implements and maintains security-related processes that reduce the organization's operational risks.
  • Responsibilities includes :
  • Establish and implement security-related policies
  • Ensure regulatory compliance (PCI DSS, ISO 27001, BI Licenses) for both Midtrans and SPOTS
  • Oversee data security and privacy
  • Manage the company's Computer Security Incident Response Team
  • Supervise identity and access management
  • Establish and oversee the organization's security architecture
  • Conduct electronic discovery and digital forensic investigations
  • Work with different department to establish disaster recovery (DR) and business continuity plans
CybersecurityCommunicationLeadershipIT Security AssessmentsInterpersonal SkillsISO 27001+17

Midtrans

3 roles

AVP Information Security & Compliance

Sep 2014Dec 2018 · 4 yrs 3 mos

  • AVP Information Security & Compliance identifies, develops, implements and maintains security-related processes that reduce the organization's operational risks.
  • Responsibilities includes :
  • Establish and implement security-related policies
  • Ensure regulatory compliance (PCI DSS, ISO 27001, BI License)
  • Oversee data privacy
  • Manage the company's Computer Security Incident Response Team
  • Supervise identity and access management
  • Establish and oversee the organization's security architecture
  • Conduct electronic discovery and digital forensic investigations
  • Work with other high-level executives to establish disaster recovery (DR) and business continuity plans
CybersecurityCommunicationLeadershipIT Security AssessmentsInterpersonal SkillsISO 27001+16

Head of IT Infrastructure, Security & Operations

Promoted

Sep 2013Sep 2014 · 1 yr

  • Responsible of Corporate Information Technology (IT) Infrastructures Operation and Management
  • Maintained a high level of service delivery in Corporate Network
  • Designed and Implemented Corporate IT Infrastructure Development
  • Design, implement, support, and evaluate security- focused tools and services
  • Develop and interpret security policies and procedures
  • Conduct risk assessments, penetration tests and vulnerability assessments
  • Implement technical solutions and Participate in security compliance efforts (PCI-DSS)
CybersecurityCommunicationLeadershipIT Security AssessmentsInterpersonal SkillsISO 27001+16

Infrastructure Security Engineer

Oct 2012Aug 2013 · 10 mos

  • Deploy and maintain Infrastructures to comply with PCI-DSS compliance.
  • Deploy and maintain Infrastructures redundancy and DR system for 99.5% availability.
  • Manage CentOS servers running Java and Ruby for Online Payment Gateway system.
  • Design, build and manage Automatic Deployment System for Agile Software Development
  • Manage MySQL Cluster database.
  • Manage Cisco devices (ASA Firewall, IPS, Router and Switches), Mikrotik Router and Safenet HSM.
  • Manage data logging, analysis and backup.
CybersecurityCommunicationLeadershipIT Security AssessmentsInterpersonal SkillsISO 27001+15

Politeknik telkom

Lecturer

Feb 2010Feb 2012 · 2 yrs · Bandung Area, West Java, Indonesia

  • Teaching in subject courses :
  • Computer Networks
  • System Administration
CybersecurityCommunicationAttention to DetailFirewallsIT ManagementAnalytical Skills+2

Universitas pendidikan indonesia

2 roles

Network & System Administrator

Promoted

Jul 2003Oct 2012 · 9 yrs 3 mos · Bandung, West Java, Indonesia

  • Responsible of Campus’ Information and Communication Technology (ICT) Infrastructures Operation and Management • Assisted The IS Manager to service students and staff
  • Maintained a high level of service delivery in Campus Network
  • Designed and Implemented Campus’ ICT Infrastructure Development
CybersecurityCommunicationLeadershipIT Security AssessmentsInterpersonal SkillsISO 27001+15

IT Technical Support

Jun 2001Jul 2003 · 2 yrs 1 mo · Bandung, West Java, Indonesia

  • Support Network & System Operation
CybersecurityCommunicationIT Security AssessmentsAttention to DetailVulnerability AssessmentFirewalls+7

Education

Institut Teknologi Telkom

Master — Informatics Engineering - Data Mining

Jan 2010Jan 2012

UNIVERSITAS PENDIDIKAN INDONESIA

Bachelor's degree — Pendidikan Teknik Elektro

Jan 1999Jan 2007

Stackforce found 100+ more professionals with Cyber Risk Management & Leadership

Explore similar profiles based on matching skills and experience