~$ whoami

Rifqi Rofian Tanamas

L2 Security Analyst Tangerang, Indonesia

Three years of SOC work for government, banking and financial clients — threat hunting in QRadar and Splunk, Python automation that takes error out of analyst decisions, and detection tuning that cut false positives by 90%.

Open to international relocation Visa sponsorship required
scroll for the full profile

~$ cat about.md

I am a cybersecurity professional with 3+ years of progressive experience in SOC operations, incident response and security automation. Today I work as an L2 Security Analyst at ITSEC Asia, taking escalations from L1 through deeper investigation and hunting QRadar for activity that never raised an alert.

Before that I led a seven-person L1 SOC team, which is where most of my engineering work happened: Splunk dashboards and use cases that cut false positives by 90%, and Python tooling with layered filtering that raised blocking accuracy by 70% while removing a class of analyst error.

I have delivered IT security projects across government, financial and banking sectors — AV deployment at scale, SIEM integration, threat hunting, and AI-assisted security automation — which means I am used to writing for two audiences at once: the engineer who has to fix it and the auditor who has to sign off on it.

I am now looking for an international SOC or detection engineering role. I am open to relocation and I will need visa sponsorship — stating that up front saves everyone a round of email.

based in
Tangerang, ID
timezone
GMT+7 (WIB)
relocation
open
sponsorship
required
experience
3+ years
languages
ID native · EN intermediate

~$ tail -f experience.log

Five positions, newest first. Impact first, tooling second.

  1. L2 Security Analyst

    ITSEC Asia active

    Feb 2026 — PresentJakarta, IndonesiaFull-time

    • Receive and handle escalations from L1 analysts, performing deeper investigation and triage of security incidents.
    • Conduct threat hunting using QRadar to proactively identify suspicious activity within client environments.
    • Support a banking sector client, ensuring timely detection, investigation and response in a high-compliance environment.
    • Developed and use an AI agent to assist security analysis and threat hunting, improving investigation speed and consistency.
    • QRadar
    • Trend Micro
    • CyberInt
    • AI-assisted analysis
  2. Lead Technical (Cybersecurity)

    Focus Solusi Infotama

    Jul 2024 — Jan 2026Jakarta, IndonesiaFull-time

    • Led a 7-person L1 SOC team, providing operational direction, mentoring and conflict resolution for high-quality incident response.
    • Developed Python-based automation tools with layered filtering, reducing analyst error and increasing blocking accuracy by 70%.
    • Created and fine-tuned Splunk dashboards and use cases, reducing false positives by 90% and improving response efficiency.
    • Acted as an L2 Analyst, handling complex security incidents and providing escalation support.
    • Led the Bitdefender AV deployment project across 2,850 endpoints, managing a 4-person implementation team.
    • Served as a translator between client expectations and vendor deliverables, resolving technical miscommunications.
    • Splunk
    • CrowdStrike
    • ExtraHop
    • Ixia ThreatArmor
    • Bitdefender
    • Python
    • Jira
  3. IT Security Engineer

    CIMB Niaga Finance

    Apr 2024 — Jun 2024Tangerang Selatan, IndonesiaFull-time

    • Operated antivirus platforms (PandaSecurity, SentinelOne, Kaspersky), ensuring timely updates and threat troubleshooting.
    • Provided VPN support and password resets, assisting users in maintaining secure remote access.
    • Conducted anomaly reviews within CyberArk, ensuring secure and compliant privileged access usage.
    • Supported daily Active Directory operations, including account setup and GPO checks.
    • SentinelOne
    • Kaspersky
    • PandaSecurity
    • CyberArk
    • Active Directory
    • VPN
  4. Cybersecurity Engineer

    Alpha Citra Siber Indonesia

    Jun 2023 — Apr 2024Jakarta, IndonesiaFull-time

    • Operated SIEM systems (Splunk, QRadar, Wazuh) to monitor and triage ~20 security incidents weekly across three client environments.
    • Enhanced detection logic and SIEM configurations, improving alert accuracy and reducing unnecessary escalations.
    • Authored technical documentation and contributed to the knowledge base for Splunk implementation.
    • Delivered 24/7 SOC support in a rotational shift environment.
    • Splunk
    • QRadar
    • Wazuh
  5. IT Support Technician

    Universitas Multimedia Nusantara

    Jul 2019 — Jun 2023Tangerang, IndonesiaFull-time

    • Delivered desktop support and system maintenance, improving IT service reliability for faculty and staff.
    • Installed computer peripherals and implemented updated virus protection based on latest threat intelligence.
    • Managed user accounts and credentials in alignment with university security policies.
    • Desktop support
    • Antivirus
    • Account management

~$ ls -la projects/

Selected engagements. Banking clients stay anonymous by agreement.

Antivirus Deployment — BPS

Badan Pusat Statistik (Statistics Indonesia)

2024 · Project Leader

Led the Bitdefender rollout across 2,850 endpoints at the national statistics agency. Managed a 4-person implementation team, held the deployment to its SLA, and delivered hands-on training so the client could run the platform after handover.

  • Bitdefender
  • 2,850 endpoints
  • Team of 4
  • SLA delivery

SOC Implementation — DJBC

Direktorat Jenderal Bea dan Cukai (Customs & Excise)

2025 — 2026 · Technical Advisor

Technical advisor for Python automation scripts and Splunk dashboards at the customs authority. The detection work cut false positives by 90% and left the SOC in a state the agency could take through an audit.

  • Splunk
  • Python
  • −90% false positives
  • Audit readiness

Multi-Client SIEM Operations

Alpha Citra Siber Indonesia · 3 managed clients

2023 — 2024 · SOC L1 Analyst

Triaged 20+ incidents weekly across three managed-service tenants and documented the alert classification standards the team worked from — the groundwork that lets CSIRT operations stay consistent between analysts and shifts.

  • Multi-tenant SIEM
  • 20+ incidents / week
  • Alert classification
  • CSIRT

~$ printenv SKILLS

Grouped by domain. No percentages — a self-scored bar proves nothing.

SIEM

  • Splunk
  • QRadar
  • Wazuh

Endpoint Security

  • SentinelOne
  • CrowdStrike
  • Bitdefender
  • Trend Micro
  • Kaspersky
  • PandaSecurity

Threat Intel

  • CyberInt

Automation

  • Python
  • Bash
  • AI-assisted security agents

Identity & Access

  • Active Directory
  • CyberArk
  • BeyondTrust

Other

  • VPN
  • IDS / IPS
  • Jira
  • Git
  • Excel
  • Team leadership
  • Incident response coordination

~$ gpg --verify certs/

Credly-verified badges open the issuer’s public record in one click.

Certified Defensive Security Analyst

Hack The Box · Aug 2026
Verify credential

Cybersecurity Analyst (CySA+)

CompTIA · May 2025
Verify credential

Certified AppSec Practitioner

The SecOps Group · Feb 2024
Issued Feb 2024

Linux System Administration

ADINUSA
Certificate of completion

~$ cat education.txt

Nusa Mandiri University

Bachelor’s — Information Systems

2021 — 2023GPA 3.67 / 4.00

Bina Sarana Informatika University

Associate — Information Systems

2018 — 2021GPA 3.72 / 4.00

~$ ./contact.sh

Hiring for a SOC, detection engineering or incident response team and able to sponsor a visa? Email is the fastest route — I reply to every message that names the role and the location.

Prefer to write it yourself? rifqirofian@gmail.com · Tangerang, Indonesia (GMT+7) · Open to relocation, visa sponsorship required.