Contact

Follow Us On:

case study
ABOUT ME

OKTRIOKA GISBU

IT Security & Compliance Professional with an academic background in Information Systems from Sriwijaya University and more than 2 years of experience in information security management. Experienced in designing and implementing security controls, developing incident response playbooks, handling sensitive data, and promoting cybersecurity awareness across the organization.

In addition to focusing on Operational Security, also experienced in supporting information security compliance with OJK and Bank Indonesia regulations and participating in information security audits. Experienced in managing Active Directory (AD), firewall administration, system hardening, implementing security solutions such as Kaspersky, EDR, NAC, PAM, WAF, and FIM, as well as serving as an SOC Coordinator to support security monitoring and incident response activities.

Education

EDUCATION LEVEL

SMA Negeri 2 Lubuklinggau, Lubuklinggau

  • Vice Chairperson of the Journalism Extracurricular
  • Secretary of the Student Leadership Training Extracurricular (LKS)
  • Member of the City-level Student Leadership Training in Lubuklinggau City

Sriwijaya University, Palembang

ORGANIZATIONAL EXPERIENCE

DEPUTY OF MEDIA AND INFORMATION DEPARTMENT

The Media and Information Agency is responsible as an institution that manages and provides public information and communication. The main tasks as a Deputy in this agency include managing public information, coordinating between divisions within the organization, being responsible for information design, and other related responsibilities.


  • Monitoring the activities of 10+ active members consisting of two divisions.
  • Managing the tasks of each internal member.
  • Planning monthly social media schedules and strategies.
  • Determining the core design for social media in accordance with events and Standard Operating Procedures.
  • Analyzing and evaluating social media.
  • Creating social media content for Instagram and YouTube.
case study
case study
EXPERIENCE

IT SECURITY PLANNING

KB BANK, SOUTH JAKARTA (2024-2026)
  • Developed a security plan that includes the protection of sensitive data, access control, and cyber risk mitigation to safeguard the company's digital assets.
  • Completed information security audits in compliance with OJK and Bank Indonesia regulations, ensuring adherence to data and operational security policies.
  • Conducted testing and evaluation of the latest information security solutions, including relevant new technologies to improve the company's system protection, such as PAM, WAF, and FIM.
  • Designed incident response playbooks for phishing and other threats, and trained teams to implement quick and effective responses.
  • Organized cybersecurity training and campaigns to raise employee awareness of digital threats and best security practices.
  • Implemented role-based access control and supervised privilege management to minimize the risk of data breaches.
  • Performed installation and configuration of system hardening on PCs at the head office and branches, including the implementation of Kaspersky antivirus, EDR (Endpoint Detection and Response), and NAC (Network Access Control).
  • Prepared documentation, presentations, and posters related to cybersecurity, including studies on Privilege Access Management and case studies of security incidents.
  • Completed Ethical Hacking training to support the development of technical skills and proactive threat identification capabilities.
  • Successfully completed the audit for ISO 27001:2013 certification and transitioned to the 2022 version, ensuring that all information security policies and procedures align with the latest standards in Information Security Management System (ISMS) management.
WORK EXPERIENCE

IT SECURITY OFFICER

BANK SAHABAT SAMPOERNA, SOUTH JAKARTA (2026 - Present)
  • Conducted cybersecurity audits in accordance with banking regulations and security standards, ensuring 100% resolution of audit findings.
  • Designed and implemented cybersecurity strategies to support enterprise asset protection and organizational risk mitigation.
  • Acted as Security Operations Center (SOC) Coordinator, ensuring security monitoring, escalation, and incident response operated effectively in compliance with SLA.
  • Managed core security controls, including Privileged Access Management (PAM) and Endpoint Detection & Response (EDR), across enterprise users, servers, databases, and applications.
  • Managed and coordinated Vulnerability Assessment & Penetration Testing (VAPT) activities across multiple banking systems, ensuring 100% remediation follow-up aligned with regulatory requirements.
  • Developed and maintained incident response playbooks, improving incident response time by 10–20% in line with SLA.
  • Performed Threat Intelligence and Threat Hunting, including monitoring of Dark Web and breach forums to identify potential data exposure and emerging cyber threats.
  • Conducted Security Assessments on enterprise systems and applications to identify and mitigate security risks.
  • Delivered security awareness programs and phishing simulation campaigns to more than 1,200 employees nationwide, increasing awareness of social engineering threats.
case study
ADDITIONAL EXPERIENCE

CERTIFICATIONS & TRAINING

Completed various certification and training programs in Cybersecurity, Compliance, and Security Operations to strengthen expertise in implementing security controls, identifying threats, mitigating risks, and applying security practices aligned with industry standards and regulatory requirements.


  • Certification (2025): Certified Ethical Hacker (CEH) v13 - EC-Council
  • Certification (2026): Certified Governance Risk and Compliance Analyst (CGRCA) - Hack & Fix
  • Certification (2025): Certified Phishing Prevention Specialist (CPPS) - Hack & Fix
  • Certification (2025): ISO/IEC 27001:2022 Lead Auditor - Mastermind
  • Certification (2024): Foundations of Cybersecurity - Google (Coursera)
  • Certification (2024): ISO/IEC 27001:2022 Information Security Associate - SkillFront
  • Training (2025): Kaspersky Endpoint Security - Kaspersky
  • Training (2024): CyberOps Associate Training - CISCO
  • Training (2024): SOPHOS Training - SOPHOS
  • Training (2025): Ethical Hacking Essentials (EHE) - EC-Council
case study
MY SKILLS

HARD SKILLS & SOFT SKILLS

HARD SKILLS

  • Cybersecurity Planning
  • Information Security Risk Management
  • Information Security Audits
  • Penetration Testing Coordination
  • Sensitive Data Management
  • Implementation of Security Technologies (e.g., PAM, WAF, FIM)
  • Cybersecurity Incident Response
  • Implementation of System and Device Hardening (e.g., Kaspersky Antivirus, EDR, NAC)
  • Policy and Procedure Security Management
  • Development and Maintenance of Incident Response Playbooks
  • Threat Monitoring and Detection
  • Cybersecurity Training and Awareness Development
  • Security Control and Privilege Access Management
  • Compliance and Regulatory Frameworks (OJK, BI, & ISO 27001)

SOFT SKILLS

  • Team Work
  • Analyze Skills
  • Problem Solver
  • Leadership
  • Time Management
  • Interpersonal Skill
  • Creative Thinking
  • Adaptability
  • Communication
  • Attention to Detail