Yogi Kortisa

CEO

Batam, Riau Islands, Indonesia14 yrs 2 mos experience
Most Likely To SwitchAI Enabled

Key Highlights

  • 17+ years in software and security engineering
  • Trained over 1,000 cybersecurity learners
  • Led 100+ security engagements successfully
Stackforce AI infers this person is a Cybersecurity Consultant with a focus on Offensive Security and Application Security.

Contact

Skills

Core Skills

Application SecurityVulnerability ManagementDevsecopsPenetration TestingInformation Security Consulting

Other Skills

Vulnerability Assessment and Penetration Testing (VAPT)Product SecuritySecurity EngineeringAI-driven securityVulnerability AssessmentRisk ManagementWeb Application SecurityWeb Application Security AssessmentResearch and Development (R&D)Secure Code ReviewIT SecuritySecure SDLCCoaching & MentoringHackingInformation Security Analysis

About

⭐ 17+ years of diverse experience in software & security engineering, hacking education, and community leadership, with a strong focus on web application security and VAPT. Currently exploring offensive AI for hacking. ✅ Security Engineering (3+ years): Led 100+ security engagements, triaged 500+ verified vulnerabilities, and helped organizations avoid financial loss and reputational damage. ✅ Mentoring & Education (2+ years): Trained 1,000+ cybersecurity learners through courses, workshops, and 1-on-1 mentoring. ✅ Software Engineering (5+ years): Maintained and optimized 10+ projects for performance and security. ✅ Community Leadership (7+ years): Delivered 30+ public talks, driving knowledge-sharing and collaboration. As a cybersecurity professional, I bring a wealth of expertise in fortifying digital landscapes against evolving cyber threats. Having played a pivotal role in application/product security engineering, DevSecOps engineering, Vulnerability Assessment & Penetration Testing (VAPT) as well as vulnerability management, I am committed to delivering unparalleled value to organizations seeking robust cybersecurity solutions. During my tenure, I have excelled in: ✅ Building a scalable application security program with a DevSecOps initiative that helps organizations deliver more high-quality secure products/applications. ✅ Integrating agile secure SDLC practices for resilient software development. ✅ Conducting thorough web application security assessments and penetration testing that assist organizations in mitigating risks before they are exploited by attackers. ✅ Leading vulnerability management efforts, including research, identification, triaging, and developing mitigation strategies that help organizations reduce their overall risks. ✅ Providing comprehensive cybersecurity training and mentoring, fostering a culture of awareness. ✅ Driving cybersecurity strategy, policy development, and management. I am now eager to leverage my skills and passion for offensive and application security engineering to contribute to any organizations that need my expertise. My goal is to collaborate on strategic initiatives, develop tailored solutions, and empower your team with the knowledge and tools needed to navigate the ever-changing cybersecurity landscape. ⭐ Let's connect and explore how we can enhance your organization's security posture together! ⭐ Specialties: Web Application Security, Penetration Testing, Cybersecurity Training & Mentoring, Application Security Engineering, Vulnerability Assessment & Management, DevSecOps, and Community Building.

Experience

Batam indonesia free zone authority

5 roles

Senior Offensive & Application Security Engineer

Promoted

Jan 2026Present · 2 mos

  • Lead offensive & application security engineering by combining human expertise with AI-driven agentic security to simulate real-world attacks, uncover systemic weaknesses, and reduce organizational risk at scale.
  • Lead offensive & application security initiatives across apps and API environments using attacker-centric methodologies
  • Design and orchestrate AI-driven agentic security workflows to augment human-led penetration testing and application security assessments
  • Simulate real-world attack scenarios to identify systemic application and architectural weaknesses
  • Partner with engineering and platform teams to translate offensive findings into actionable remediation strategies
  • Scale application security testing and risk reduction through automation, tooling, and continuous security validation.
Application SecurityVulnerability Assessment and Penetration Testing (VAPT)Vulnerability ManagementProduct SecuritySecurity Engineering

Application Security Engineer

Promoted

Aug 2022Dec 2025 · 3 yrs 4 mos

  • Helping teams build secure applications and products including:
  • Develop and execute comprehensive cybersecurity strategies and program plans to enhance overall security posture
  • Lead Application Security (AppSec) / Product Security (ProdSec) engineering efforts, ensuring the robust security of applications and products
  • Drive the implementation of secure SDLC practices within agile environments, promoting security throughout development cycles
  • Spearhead the creation and review of secure architectures and initiated threat modeling exercises
  • Implemented and championed DevSecOps initiatives, fostering a security-first culture and implementing secure CI/CD pipelines utilizing SAST/SCA/DAST/etc
  • Pioneered a security culture initiative, increasing awareness, and expediting the resolution of vulnerabilities
  • Played a vital role in the CSIRT, effectively mitigating incidents, and ensuring a rapid response to security events
  • Effectively manage tasks while providing mentorship to junior security team members
  • Conduct thorough secure code reviews
  • Ensure compliance with government regulations and global standards like OWASP Top 10, ASVS, WSTG, SAMM, NIST, ISO 27001 ISMS, etc
  • Contribute as a Subject Matter Expert (SME) in information security within the Sistem Pemerintahan Berbasis Elektronik (SPBE) task force, ensuring the security of electronic government systems.
Vulnerability AssessmentRisk ManagementPenetration TestingVulnerability ManagementWeb Application SecurityWeb Application Security Assessment+8

Offensive Security Analyst

Promoted

Aug 2022Dec 2025 · 3 yrs 4 mos

  • Helping organizations defend against attackers, including:
  • Implemented a risk-based approach, enhancing overall risk management practices and ensuring compliance with industry standards
  • Developed and implemented security automation to enhance security assessment
  • Execute Vulnerability Assessment & Penetration Testing (VAPT) activities
  • Manage the vulnerability management efforts, from analysis, triaging to remediation of identified vulnerabilities
  • Manage external attack surfaces to minimize vulnerabilities and enhance overall security resilience
  • Lead research and development efforts in security and hacking, staying at the forefront of emerging threats and technologies
Vulnerability AssessmentPenetration TestingVulnerability ManagementHackingInformation Security AnalysisWeb Application Security Assessment+3

Security Champion

Jan 2021Aug 2022 · 1 yr 7 mos

  • Building Security Champions program to solve security gaps between development, operation, and security departments. Currently researching Application Security (AppSec) and Vulnerability Management program with DevSecOps culture and implementation at Batam Indonesia Free Zone Authority (BIFZA) as part of Secure-Software Development Life Cycle (S-SDLC) processes and aiding with penetration testing across our internal & external surfaces, including active monitoring digital assets.
Risk ManagementVulnerability Management

Research Development Software Developer

Jun 2019Aug 2022 · 3 yrs 2 mos

  • Observe, synthesize, theorize, explore, design, develop, test, implement, improve, scale-up application at BIFZA.
Web ProgrammingResearch and Development (R&D)

Dibimbing.id

Cyber Security Mentor

Apr 2025Present · 11 mos

  • Mentor / Advisor — Cyber Security Bootcamp (B2C): Empowering aspiring cybersecurity professionals through an online bootcamp program covering networking fundamentals, cryptography, penetration testing, and defensive security. Focused on practical, hands-on learning to prepare students for real-world cybersecurity challenges.
  • 🔗 dibimbing.id/layanan/bootcamp/cyber-security
  • International Mentor / Trainer — Company Training Program (B2B): Delivering tailored cybersecurity training for organizations worldwide. Mentored teams of developers, system administrators, and technical executives on conducting web and network penetration testing, identifying vulnerabilities, and implementing effective mitigation strategies to strengthen their security posture.
Coaching & MentoringCybersecurity

Hacker otodidak

2 roles

Founder, Cyber Security Consultant

Promoted

May 2024Present · 1 yr 10 mos

  • Offering cybersecurity consulting, education, and advisory services.
  • Specializing in offensive and application security engagements, including:
  • Vulnerability Assessment & Penetration Testing (VAPT)
  • Cybersecurity Education, Corporate Training, and 1-on-1 Private Mentoring
  • Building Application Security (AppSec) Programs
  • Secure SDLC and DevSecOps Implementation/Integration
  • Building Vulnerability Management Programs
  • Managed Vulnerability Assessment & Triage, Continuous Agile Pentesting per Feature, Continuous/Managed Application Security (AppSec) Assessments, and Continuous/Managed External Attack Surface Monitoring (EASM)
  • Cybersecurity Gap Analysis and Maturity Assessments: SMKI, Indeks KAMI, SPBE (Pemdi), ISO 27001-ISMS, NIST CSF, OWASP SAMM, OWASP ASVS, and OWASP DSOVS.
Organizational LeadershipPenetration TestingWeb Application Security AssessmentInformation Security ConsultingResearch and Development (R&D)Vulnerability Assessment and Penetration Testing (VAPT)+3

Security Researcher

May 2021Present · 4 yrs 10 mos

  • Research on Offensive & Application Security (Infrastructure/Network/Web/API/Mobile) and AI for Ethical Hacking.
Penetration TestingWeb Application Security AssessmentInformation Security ConsultingSecure Code ReviewVulnerability Assessment and Penetration Testing (VAPT)DevSecOps+2

Skilvul

Cybersecurity Mentor

Feb 2024Jun 2024 · 4 mos

  • IBM SkillsBuild for AI Cybersecurity Bootcamp Program Kampus Merdeka Batch 6.
Coaching & Mentoring

State polytechnic of batam

2 roles

Cyber Security Instructor

Jan 2023Jan 2023 · 0 mo · Batam, Riau Islands, Indonesia

  • Penetration Testing Internal Boot Camp: Web Pentesting Fundamental. Program Studi Rekayasa Keamanan Siber Politeknik Negeri Batam.
Penetration TestingWeb Application SecurityWeb Application Security AssessmentApplication Security

Advisory Board Member

Nov 2021Present · 4 yrs 4 mos · Batam, Riau Islands, Indonesia

  • Advisory Board Member of Polibatam Cyber Team (PCT) - Polibatam Cyber Labs Center of Excellence (PCLabs)
Information SecurityIT SecurityTeam LeadershipCybersecurityCoaching & MentoringEthical Hacking

Rainusa.co.id

Cyber Security Trainer

Mar 2022Mar 2022 · 0 mo · Indonesia

  • Delivered several days of full Cybersecurity Training with high-quality materials for several corporate IT staff.
Information SecurityCybersecurityCoaching & MentoringNetwork SecurityLinux System Administration

Sekolah hacker

Cyber Security Instructor

Feb 2022Jul 2023 · 1 yr 5 mos

  • Online Bootcamp and Mentoring Program face to face (live) to educate you to become a Cyber Security Engineer (Red Team) in 16 weeks with guaranteed job acceptance. I achieved the distinction of Best Instructor in batches 13 and 17.
Penetration TestingInformation SecurityIT SecurityCybersecurityCoaching & Mentoring

Adinusa (akademi digital nusantara)

Cyber Security Mentor

Feb 2022Jun 2022 · 4 mos

  • Cyber Security Mentor at Cybersecurity Training Sub Batch 1 2022 - Mastercard Academy 2.0
  • Materials:
  • The trifecta CompTIA: Network+, Linux+, and customized Security+
Penetration TestingInformation SecurityIT SecurityCybersecurityCoaching & Mentoring

Pt indonesia villajaya

2 roles

Lead Software Engineer

Apr 2019Jun 2019 · 2 mos

  • Lead and manage a team of programmers
  • Coach and guide the development of the team members
  • Share knowledge, motivate and inspire others to generate new ideas
  • Efficiently communicate and support messages and decisions from management
  • Plan, organize, follow-up and evaluate the work of the team and its impact on the project
  • Actively work with other department leads and facilitate the information flow
  • Identify risks and provide relevant solutions to complex problems
  • Estimate time to accomplish programming tasks and commit to meeting all objectives
  • Perform other IT related duties.
Information Security AwarenessInformation SecurityIT SecurityCybersecurityCoaching & Mentoring

Full Stack Software Engineer

Aug 2017Apr 2019 · 1 yr 8 mos

  • Build customized Enterprise Resource Planning (ERP) system, Point of Sales (POS), recruitment online, and other web-based application systems
  • System integration, various software platforms, and API
  • Monitoring and maintaining existing applications in entire branch offices as well as observing for any potential improvements
  • Sysadmin and DBAs in Head Office
  • Architect, develop and implement software programs to meet business requirements
  • Develop application code and modules for business and technical requirements
  • Tune-up design for maintainability, scalability, and efficiency
  • Develop and implement programs, designs, and codes
  • Design and develop systems, sub-systems, and programs
  • Coordinate and support technical staff, operations, and vendors
  • Interact with clients to determine their requirements and needs
  • Resolve and troubleshoot problems and complex issues
  • Perform unit tests and fix bugs
  • Integrate best qualitative practices in the design and development aspects of programs
  • Research for new technologies to apply to existing systems
  • IT security assessment, pen-testing, server sysadmin, server maintenance, hardening, and database administration.
Organizational LeadershipResearch and Development (R&D)Team LeadershipCoaching & MentoringLeadership

Pt. citra tubindo tbk

Web Programmer

Feb 2017Jun 2017 · 4 mos · Riau Islands Province, Indonesia

  • Develop Travel Authorization Systems.
Web ProgrammingResearch and Development (R&D)PHP

Batam linux user group (blug)

Leader

Jan 2014Jan 2016 · 2 yrs · Riau Islands Province, Indonesia

  • Batam Linux User Group (BLUG) is the largest GNU/Linux and Open Source community located in Batam City, Indonesia and still active until now. https://batamlinux.or.id

Self employed

Cyber Security Educator

Jan 2013Present · 13 yrs 2 mos · Indonesia

  • Offering private online courses on IT security and practical ethical hacking through various platforms such as superprof.co.id. Deliver keynote speeches on IT security at national events, IT community gatherings, local police departments, colleges, high schools, and more.
Information Security AwarenessInformation SecurityCybersecurityCoaching & MentoringEthical Hacking

Self employed web developer and consultant

Freelance Web Developer

May 2012May 2017 · 5 yrs · Riau Islands Province, Indonesia

  • Develop web company profile, e-commerce, information system, and custom web application.

Batam health department

Information Technology Intern

Jul 2011Oct 2011 · 3 mos · Riau Province, Indonesia

  • Operate and maintain SIMPUS software, network maintenance, and IT support/troubleshoot.
Organizational LeadershipCoaching & MentoringLeadership

Education

State Polytechnic of Batam

Bachelor of Applied Science (BASc) — Multimedia Networking

Jan 2013Jan 2017

INTERNET

Computer and Information Systems Security/Information Assurance

Jan 2009Present

Vocational High School 4 Batam

Computer Software Engineering

Jan 2010Jan 2013

Junior High School 3 Batam

Jan 2007Jan 2010

Stackforce found 100+ more professionals with Application Security & Vulnerability Management

Explore similar profiles based on matching skills and experience