1/44
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Can you walk me through your professional background and experience?
My name is Yudhistira Heriansyah, you can call me Yudhis. Iāam a cybersecurity professional based in Jakarta, Indonesia. Holding a bachelor degree in computer science from Binus University. Professionaly, i work as a cybersecurity consultant at Nusantara Compnet Integrator, bringing over 9 years of IT experience, spanning multicloud environment including Microsoft Azure, AWS, GCP, and alibaba cloud. Iām also hold a comprehensive portofolio of industry certification, including the Google Cloud Professional Cloud Security Engineer, multiple Microsoft Expert certification, AWS Security, and advanced offensive security accreditation like eWPTX from INE Security.
I uniquely bride defensive cloud engineering, arhcitecture review, devsecops pipeline, and threat modeling with red teaming engagement and an active bug bounty activities to align attackers techniques with enterprise guardrails.
Why are you interested in this position?
I am interested in this positions because it allows me to apply my core expertise as a Cloud Security Engineer with large-scale architecture and enterprise security implementation. The technical scope, spanning native GCP Stacks, devsecops automation, and Cloud native aplication protection directly match with my professional stack and career trajectory. Itās an exciting opportunity to tackle high-impact security challenges at an enterprise scale.
What do you know about Iberdrola Innovation? and why you want to work with us?
I know that East-West Digital was launched by Iberdrola to commercialize and scale advanced digital solutions globally, building directly upon nearly a decade of cutting-edge R&D pioneered by Iberdrola Innovation Middle East at the Qatar Science & Technology Park (QSTP) since 2016.
Why are you considering leaving your current company?
Iāve had a rewarding and growth tenure at Nusantara Compnet Integrator, where Iāve successfully led end-to-end cybersecurity solutions, consulting design, and architecture reviews. However, I am looking for my next major challenge, specifically an international opportunity that allows me to apply my multi-cloud expertise and offensive-to-defensive skill set on a global scale, particularly within dynamic markets like the Middle East.
What kind of cloud security project are you currently working on?
I am currently involved in end-to-end cloud security consulting and architecture design projects, focusing heavily on securing multi-cloud environments across AWS, Azure, and GCP. This includes implementing DevSecOps security gates, such as integrating OpenText Fortify for SAST and Prisma Cloud/Aqua Security for CNAPP within CI/CD pipeplines as well as building automated security guardrails using Terraform and designing secure API and microservices architectures.
What is your biggest cybersecurity achievement?
One of my proudest achievements is successfully bridging the gap between offensive security research and defensive cloud engineering. Beyond earning top-tier industry certifications, I have actively identified and responsibly reported critical vulnberabilities such as IDOR and API Flaws across prominent enterprise platforms through bug bounty programs.
Applying these real-world attacker insights to design secure-by-default coud architectures and custom security tools like AliPath for Alibaba Cloud RAM has allowed me to systematically prevent enterprise-level breaches.
What type of working environment do you prefer?
I thrive in collaborative, high-performance environments that balance autonomy with cross-functional teamwork. Whether working remotely, hybrid, or embedded within international engineering teams, I value cultures that emphasize clear communication, technical excellence, and proactive problem-solving. I enjoy environments where security is treated as an enabler of business velocity rather than a bottleneck.
Have you worked with international teams?
Yes. Throughout my career, I have collaborated extensively with diverse, cross-functional stakeholders. This includes coordinating technical reviews, aligning security requirements with global engineering standards, and driving complex implementations across multi-region environments.
Why should we hire you instead of another cloud security engineer?
You should hire me because I bring a rare dual perspective: deep technical mastery of the cloud security stack combined with an active offensive mindset. Beyond configuring GCP, Terraform, and DevSecOps toolchains like Prisma Cloud, Aqua Security, and OpenText Fortify, my background as a bug bounty researcher and security consultant means I don't just follow compliance checklistsāI anticipate how real-world attackers think. I can walk into your environment, threat-model your architecture, secure your pipelines, and bridge the gap between engineering speed and robust enterprise defense from day one.
How do you approach securing Google Cloud (GCP) environments, and what native security tools do you rely on?
I have deep hands-on expertise with the core GCP security stack, backed by my Google Cloud Professional Cloud Security Engineer certification. For identity and access management, I implement fine-grained IAM conditions and Workload Identity Federation to eliminate long-lived service account keys. For network perimeter defense and data exfiltration prevention, I utilize VPC Service Controls and configure Cloud Armor for Web Application Firewall (WAF) protection, rate-limiting, and DDoS mitigation. Additionally, I leverage Secret Manager for dynamic secret management and Security Command Center for continuous posture monitoring.
Explain Google's Shared Responsibility Model.
Googleās Shared Responsibility Model clearly divides security duties between Google and the customer. Google is responsible for āSecurity of the Cloudā which includes the underlying physical data centers, hardware, global network infrastructure, and virtualization layers. The customer is responsible for āsecurity in the cloudā which encompasses customer data configuration, IAM policies, network firewall rules, operating system patches on VMs, container security, and application-level code hardening. In short, Google ensures the platform is secure, but we responsible for configuring and securing everything we build and run on top of it.
How do you approach DevSecOps integration and Infrastructure as Code (IaC) security?
I embed security directly into the software development lifecycle by integrating SASTāusing OpenText Fortifyāalongside DAST, container artifact scanning, and CNAPP tools like Prisma Cloud and Aqua Security into modern CI/CD pipelines such as GitHub Actions and GitLab CI. For Infrastructure as Code, I utilize Terraform to provision environments while baking in automated security guardrails and compliance baselines to ensure compliance before deployment.
How does your offensive security and bug bounty background influence your day-to-day security engineering?
I uniquely bridge defensive cloud engineering with an offensive attacker mindset. As an active bug bounty researcher who has responsibly identified vulnerabilities like IDOR and API flaws across various enterprise platforms, combined with my experience in consulting architecture reviews and threat modeling (using frameworks like STRIDE), I anticipate how bad actors might exploit multi-tenant cloud environments. This allows me to build robust engineering guardrails and fix application logic flaws before code hits production.
Describe the most complex cloud migration you've been involved in.
The most complex migration I handled involved moving legacy monolithic applications and hybrid databases into a asecure, multi-tenant cloud architecture while maintaining strict regulatroy compliance. The prmiary challenge was mapping granular IAM roles, securing cross-perimeter data flows, and ensuring zero downtime. I resolved this by designing a phased migration deployments, setting up strict network perimeters with VPC Service Controls, and implementing continuous posture monitoring to catch configuration drift mid-migration.
Have you ever introduced DevSecOps into an existing CI/CD pipeline?
Yes, introducing DevSecOps into legacy pipelines is a common challenge Iāve tackled. I integrated security tooling, such as OpenText Fortify for SAST, container image vulnerability scanning, and CNAPP solutions like prisma Cloud and Aqua Security directly into existing GitHub Actions and GitLab CI workflows. I structured these integrations to run asynchronously during early build stages and enforced strict quality gates only for high-risk vulnerabilities, allowing teams to shift security left smoothly without distrupting their release velocity.
Describe a time when developers disagreed with your security recommendations.
During a pipeline integration project, developers pushed back against adding strict SAST security gates and compliance checks because they were worried it would slow down their rapid deployment sprint cycles. Instead of forcing a rigid block, I collaborated with the team to tune the security rules, prioritizing critical and high-severity vulnerabilities while autoamting the cecks directly into their existing GitHub actions workflow. By showing them how the automated checks caught logic flaws early without blocking low-risk deployments, they saw security as an enabler of clean code rather than a bottleneck.
How do you prioritize security risks?
I prioritize security risks using a risk-based approach that evaluates exploitability, business impact, and asset criticality. I assess whether a vulnerability is actually reachable in the current archutecture, what business data or systems it exposes, and whether compensating controls like WAF or VPC-SC mitigate the exposure. This ensures remediation efforts focus on high-impact risks first.
How do you balance security with business needs?
I believe security should act as an enabler for business velocity rather than a roadblock. I balance security with business needs by embedding security early into the design phase, shifting left through architecture reviews, threat modeling, and automated infrastructure as Code guardrails.
How would you secure a GCP project from scratch?
Securing a GCP project from scratch requires a multi-layered, āsecure-by-designā approach. First we establish a clean resource hierarchy using Organization, Folder and Project to isolate environments. and then we implement granular IAM roles and avoid using primitive roles. After that for network perimeters we can set up custom VPCs with private subnets, configure VPC service controls to prevent data exfiltration and implement Cloud Armor for WAF and DDoS protection. And then for data protection we should enable encryption using CMEK via Cloud KMS and store sensitive credentials in Secret Manager. last we can enable SCC for continuous posture monitoring, vulnerability scanning, and threat detection.
How does IAM work in GCP?
GCP IAM operates across a strict hierarchical structure: Organization ā Folders ā Projects ā Resources.
What are predefined roles vs custom roles?
Predefined Roles: Managed and regularly updated by Google. They are granular functional roles curated for specific job functions like Storage Viewer.
Custom Roles is a user-defined collection of specific permissions tailored precisely to an organizationsās least privilege requirements. I use custom roles when predefined role grants too many unnecessary permissions, ensuring identities can only perform the exact actions required for their function.
How would you implement least privilege in GCP?
Avoid primitive roles, utilize predefined roles, bind roles to groups or service accounts, use IAM conditions for attribute-based access control, and regularly audit access logs and IAM policies using Policy Intelligence and Security Command Center to detect and revoke over-permissioned accounts.
What is VPC Service Controls?
VPC Service Controls is a security feature taht allows organizations to create a secure, software-defined perimeters around Google-managed service APIs (like Cloud Storage, BigQuery, and Cloud SQL). Even if an attacker compromises a virtual machine or steals a valid IAM token, VPC Service Controls blocks data exfiltration by dropping any API calls or data transfers originating from outside the designated corporate network perimeter.
When would you use Cloud Armor?
I use cloud armor when deploying public-facing web applications, APIs, or load balancers that require edge-level defense. We can use cloud armor as Layer 7 DDoS mitigation & WAF, we can also set rate limiting, and geo-based access control.
How do you protect an API running on GCP
Deploy Cloud Armor behind an HTTP(S) Load Balancer to handle rate-limiting, geo-blocking, and WAF rules., route traffic through API Gateways, enforcing authentication via OAuth 2.0 and JWT.
How would you securely store application secrets?
To securely store and manage application secrets, I use Secret Manager combined with strong supporting controls, first Enforce strict least-privilege IAM so only the specific service account running the application can access the secret. and then Protect data at rest using Customer-Managed Encryption Keys (CMEK) via Cloud KMS. Last, Leverage Secret Manager's versioning and automatic rotation features. So the applications can dynamically query the latest version via API at startup, eliminating hardcoded passwords and enabling zero-downtime credential rotations.
What security checks belong inside a CI/CD pipeline?
Secret Scanning, SAST, IaC Scanning, SCA, Container Image Scanning
Have you integrated security into GitHub Actions?
Yes, I frequently use GitHub Actions to automate DevSecOps pipelines. I integrate security checks into workflow YAML files so that every pull request or commit triggers automated scanning such as SAST, secret detection, Terraform linting, and container image analysis.
How do you scan Docker images?
Docker images are scanned by inspecting both the base OS packages and the application dependencies bundled inside the container layers. This is typically done during the build phase of a CI/CD pipeline using container vulnerability scanners.
What tools have you used?
Throughout my professional experience, I have worked extensively with a wide range of security and DevSecOps tooling:
SAST & Code Analysis: OpenText Fortify and SonarQube.
CNAPP, Container & SCA Scanning: Prisma Cloud, Aqua Security, Trivy, and Snyk.
IaC Security: Checkov and Terraform native security linters.
CI/CD Platforms: GitHub Actions and GitLab CI
How do you secure Terraform?
Securing terraform involves safeguarding both the code and the deployment state. first we can set state file protection by storing terraform.tfstate remotely in encrypted backend buckets (GCS) with strict IAM controls, object versioning, and customer-managed encryption keys (CMEK). Running automated static analysis tools like checkov in the CI/CD pipeline to catch misconfigurations such as public GCS buckets or overly open security groups before apply.
How do you prevent secrets from entering Git?
Installing local pre-commit hooks (like Trufflehog or GitGuardian gitleaks) on developer workstations to scan code before a commit is even allowed.
Integrating automated secret detection tools directly into GitHub Actions or GitLab CI pull request checks.
Enabling native platform features like GitHub Advanced Security secret scanning to automatically block pushes containing known patterns (like AWS/GCP keys or private certificates) and alerting teams if a credential leaks."
OWASP Top 10 for Web Apps
Broken Access Control - The application fails to properly enforce what an authenticated user is allowed to access or perform. - IDOR
Security Misconfiguration - Insecure configuration of applications, servers, cloud services, databases, frameworks, or security controls. - Directory Listing, Default admin still enabled
Software Supply Chain Failures - Failures in securing the software supply chain, including dependencies, libraries, CI/CD pipelines, repositories, build systems, and third-party components. - Malicious package deployed
Cryptographic Failures - Sensitive information is inadequately protected because of weak cryptography, improper key management, or failure to encrypt data. - Password stored with MD5 without Slat
Injection - Untrusted input is interpreted as commands or queries by an interpreter. - SQL Injection, XSS
Insecure Design - Security weaknesses are introduced during the design or architecture phase rather than through a simple coding mistake.
Authentication Failures - The application incorrectly verifies user or service identity or improperly manages authentication/session mechanisms. - Credential Stuffing
Software or Data Integrity Failures - The application trusts software, code, updates, serialized objects, or data without adequately verifying their integrity or source.
Security Logging & Alerting Failures - Security events are not properly logged, monitored, correlated, or alerted, preventing timely detection and response.
Mishandling of Exceptional Conditions - The application handles unexpected errors, failures, race conditions, resource exhaustion, or abnormal states insecurely.
How do you perform threat modeling?
I follow a structured methodology to identify, quantify, and mitigate security risks during the design phase of software and infrastructure architecture. The process typically including map out the system architecture and create the data flow diagrams. Next, I identify sensitive data like PII, financial records, credentials and map out where data crosses trust boundaries.
after that, i analyze components against the STRIDE framework (spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege), last is designing and documenting architectural controls or security countermeasures such as enforcing TLS, adding WAF rules, implementing least-privilege IAM, etc.