Daud Hidayat Ramadhan

Hi, I'm Daud Hidayat Ramadhan

DevSecOps & Backend Engineer

🇮🇩 Indonesia

DevSecOps & Backend Engineer focused on Secure SDLC, CI/CD security, backend services, Kubernetes, and practical automation. I build secure backend systems and security-aware delivery workflows.

About Me

About

About Me

I am a DevSecOps & Backend Engineer focused on building secure backend systems and security-aware delivery workflows. My work connects backend engineering, Secure SDLC practices, and CI/CD security so applications can move faster without ignoring risk.

At BSI UII, I started by building and maintaining backend services for student scholarship systems, then moved into SOC/CISRT work focused on vulnerability management, Secure SDLC research, and DevSecOps pipeline proof-of-concepts. That progression shapes how I think: backend reliability and security controls should be designed together, not treated as separate concerns.

My core stack includes Go, PHP, Laravel, REST APIs, Docker, Kubernetes, OpenBao, and CI/CD security tooling such as SAST, dependency scanning, container scanning, and secret scanning. Cloud and infrastructure tools such as Linux, Nginx, GCP, and Cloudflare support the work, but the primary focus of this site is DevSecOps and Backend engineering.

I use this website as an owned technical portfolio: a place to document projects, security labs, backend patterns, and practical lessons from building safer delivery workflows.

Featured DevSecOps & Backend Work

Selected projects that document how I build secure delivery workflows, backend services, Kubernetes labs, and automation for practical Secure SDLC learning.

DevSecOps CI/CD security scanning pipeline architecture using GitHub, Trivy, Semgrep, GitLeaks, Syft SBOM, Kyverno, Conftest, Cosign, Sigstore, SLSA provenance, DAST, and Kubernetes staging deployment.

DevSecOps Security Scanning Pipeline

A public Secure SDLC and DevSecOps boilerplate for running repeatable security checks with SAST, secret scanning, dependency scanning, container scanning, SBOM generation, and IaC policy validation.

CI/CD SecuritySecure SDLCSASTSecret ScanningSBOMTrivySemgrepShell
Linux security audit automation dashboard for virtual machine hardening, Lynis checks, Fail2ban status, auditd review, package integrity, account hygiene, and automated host security reporting.

Linux Security Audit Automation

A Linux security reporting project that turns periodic host checks into repeatable text and HTML reports with optional email delivery.

LinuxShellLynisFail2banAuditdSecurity ReportingAutomation
Self-hosted DevSecOps homelab architecture with rootless kind Kubernetes, GitHub CI/CD, Flux GitOps, secret management, sandbox testing, vulnerability management, and integrated security scanning.

Self-Hosted DevSecOps Lab

A rootless Kubernetes DevSecOps lab that combines GitOps, service mesh, secrets management, network policy, and the DevSecOps Security Scanning Pipeline as part of a controlled Secure SDLC practice environment.

KuberneteskindIstioOpenBaoFlux CDTailscaleDevSecOpsSecurity Scanning

Work Experience

  • Badan Sistem Informasi UII

    Badan Sistem Informasi UII

    Security Engineer — SOC/CISRT Team

    🇮🇩 Yogyakarta, Indonesia

  • Badan Sistem Informasi UII

    Badan Sistem Informasi UII

    Software Developer (Full-Stack) — SOC/CISRT Team

    🇮🇩 Yogyakarta, Indonesia

  • Badan Sistem Informasi UII

    Badan Sistem Informasi UII

    Software Developer (Back-End) — Finance/Akurasi Team

    🇮🇩 Yogyakarta, Indonesia

Education

  • Universitas Islam Indonesia

    Universitas Islam Indonesia

    Bachelor of Informatics

    Aug 2021 - Jan 2026 (4 yrs 6 mos)
    • Focused on informatics fundamentals, backend application development, databases, and software engineering practice.
    • Graduated with a 3.70/4.00 GPA according to the current CV source.
    • Completed multiple course projects and teaching-assistant activities that supported the transition into backend and DevSecOps work.