
Awan Ikhwan
Cloud Policy Governance Lead
Skills

See my services

Work experience
IT GRC Cloud and Cybersecurity
Telkom Indonesia • Full-time
Sep 2022 - Present • 4 yrs 1 mo
Job Description: 1. Architected and managed IT GRC and cloud security frameworks aligned with ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018 for private and public cloud environments. 2. Governed the Security Shared Responsibility Matrix using the CSA Cloud Control Matrix (CCM) v4.0 to ensure comprehensive cloud compliance. 3. Conducted governance-level reviews of technical security controls, including SIEM, NGFW, WAF, VAPT, and user access reviews (UAR). 4. Coordinated internal and external ISMS audit activities and maintained full certification-readiness documentation. Key Achievements: 1. Authored and maintained 40+ governance documents (policies, standards, procedures), consistently achieving zero audit findings across all ISMS audits. 2. Led the Managed Security Service Provider (MSSP) cybersecurity governance for a national government agency (Badan Gizi Nasional) under Indonesia's SPBE initiative. 3. Successfully delivered 60+ critical governance artifacts within the SIPGN scope, ensuring full alignment with government regulations and industry best practices.