Achmad Firdaus

Senior Lead Application Security Engineer

West Bekasi, Indonesia

Summary

Application Security Engineer with 6+ years of experience in penetration testing, secure system design, and backend engineering. Experienced in leading engineering teams and building internal security platforms that improve vulnerability assessment workflows and operational efficiency. Holds eWPTX and Burp Suite Certified Practitioner (BSCP) certifications with strong expertise in web application security, API security, and vulnerability research.

Experience

Senior Lead Application Security Engineer

Present

SecLab Indonesia

Architect and lead developer of SIERA, a container-based security assessment platform built using Golang, Node.js, PostgreSQL, and Redis. Proven ability to collaborate with enterprise clients, conduct security consulting engagements, and translate complex vulnerabilities into practical remediation strategies.

  • Architected and led development of SIERA, a container-based internal security assessment platform built using Golang, Node.js, PostgreSQL, and Redis.
  • Managed a cross-functional team of 8 engineers including backend, frontend, UI/UX, and security specialists.
  • Designed scalable security testing workflows to improve internal vulnerability assessment operations.
  • Led technical discussions with enterprise clients to define security testing strategies and remediation plans.
  • Conducted technical presentations explaining vulnerability impact and mitigation approaches to stakeholders.
  • Led development of internal tools used to support vulnerability assessment and penetration testing operations.
  • Conducted penetration testing engagements for web applications, APIs, and mobile platforms.
  • Identified critical vulnerabilities including authentication flaws, access control weaknesses, and injection attacks.
  • Presented vulnerability findings and remediation strategies directly to client engineering teams.

Lead Application Security Engineer & Pentester

SecLab Indonesia

  • Performed security assessments for enterprise web applications and APIs.
  • Conducted manual exploitation using Burp Suite and custom testing methodologies.
  • Delivered vulnerability reports including exploitation proof-of-concept and remediation recommendations.

Penetration Tester

SecLab Indonesia

  • Developed backend systems and REST APIs supporting web and mobile applications.
  • Built Android and web-based data warehousing applications.
  • Implemented PostgreSQL replication architecture for high availability.
  • Managed Linux server infrastructure and deployment processes.

Web & Mobile Application Developer

Mimotek Indonesia

  • Developed enterprise backend systems using PHP frameworks including Laravel, CodeIgniter, and CakePHP.
  • Designed and optimized stored procedures for SQL Server and MySQL databases.
  • Implemented automation scripts and integrated systems with SAP, AS400, and enterprise platforms.

PHP Developer

PT. Astra Graphia Information Technology (AGIT)

  • Developed enterprise backend systems using PHP frameworks including Laravel, CodeIgniter, and CakePHP.
  • Designed and optimized stored procedures for SQL Server and MySQL databases.
  • Implemented automation scripts and integrated systems with SAP, AS400, and enterprise platforms.

IT Instructor & Network Administrator

Educational institution

  • Managed the school’s network infrastructure including firewall, hotspot, and printer sharing systems using MikroTik.
  • Served as a technical proctor for national computer-based examinations (UNBK).
  • Taught computer networking fundamentals and information system applications to students.
broMadX

broMadX: notes on app security, engineering, and what I’m learning. Written by achmad (formal résumé: Achmad Firdaus on About).