Hafzan Ishigaki Bin Abd Karim
Ishigaki
Shah Alam, Selangor +601******** **************@*****.*** Summary
Experienced DevSecOps and Cloud Security professional adept at architecting automated, zero-downtime deployment workflows and securing multi-cloud ecosystems. Proficient in integrating strict quality gates and GitOps principles within CI/CD pipelines to guarantee the seamless and secure delivery of complex software portfolios. Highly motivated and aspiring professional eager to deepen practical expertise in cybersecurity and cloud architecture. Driven by a continuous learning mindset to absorb new industry knowledge, gain advanced hands-on experience, and contribute impactful, secure solutions to complex enterprise technology challenges.
Experience
Manager Digital Innovation and Design, Aliiance Bank Malaysia Berhad July 2025 - Present
● Engineered a highly resilient, fully automated continuous delivery pipeline for mission-critical banking products. Synergized GitLab, Jenkins, ArgoCD, and Red Hat OpenShift (OCP4) to create a seamless, zero-downtime deployment flow across DEV, SIT, UAT, and PROD environments, accelerating release velocity while strictly enforcing deployment governance.
● Designed and implemented a sophisticated, automated circuit-breaker architecture within Google Cloud Platform (GCP). This dynamic mechanism autonomously governs enterprise AI operations by monitoring real-time consumption and instantaneously severing API traffic to prevent runaway resource utilization and safeguard cloud budget from billing anomalies.
● Spearheaded the end-to-end automated CI/CD deployment and patch management architecture for an internal enterprise desktop application. Built robust, automated release mechanisms via Jenkins that align perfectly with complex developer requirements, eliminating manual update bottlenecks and ensuring continuous, secure software delivery.
● Orchestrated an automated, fail-safe security matrix within Jenkins to govern the software delivery lifecycle. Deployed highly sensitive, automated quality gates that instantly sever the deployment chain upon detecting critical or high-risk vulnerabilities, eliminating the possibility of introducing architectural flaws into the DEV environment.
● Architected a universally standardized, declarative GitOps deployment model across the entire application portfolio. Engineered a zero-deviation delivery ecosystem that guarantees absolute operational consistency and generates an immutable, forensic-level audit trail for every release event across all cross-functional engineering teams, ensuring airtight regulatory compliance. Analyst, Deloitte Business Advisory Sdn Bhd June 2022 – June 2025
● Architected a secure Data Lake design leveraging AWS Security Services, including Security Hub, AWS Config, and GuardDuty, to implement cutting-edge security measures adhering to industry standards.
● Developed RBAC IAM Policies and resource-based policies for S3 buckets based on least privilege principle for AWS Data Lake Architecture to restrict access to necessary resources.
● Create incident response plan, data backup strategy and encryption strategy for Data Lake.
● Led Cloud Readiness/Risk Assessments for multiple Malaysian banks, ensuring compliance with BNM RMiT Appendix 10.
● Conducted comprehensive security assessments across Azure and AWS environments, identifying and mitigating high-severity vulnerabilities in legacy systems, microservices architectures, and cloud configurations, resulting in significantly enhanced overall system security.
● Implemented DevSecOps using Checkmarx in CICD pipeline for a major Indonesian client, enhancing application security with SAST, SCA, image scanning, and DAST in a unified solution.
● Supporting Zero Trust implementation for a local bank, assessing current IT infrastructure and security posture, then recommending advanced tools to enhance overall cybersecurity resilience. IT Intern, Razer Merchant Services Jan 2022 - May 2022
● Provided comprehensive explanation on initiating vulnerability assessments using Nessus.
● Examined AWS services like GuardDuty and Security Hub for effective security vulnerability monitoring.
Education
Degree in Information Technology Hons. Cyber Security On-going (Part Time) UNITAR International University
Diploma in Network Security July 2019- May2022
German-Malaysian Institute
CGPA: 3.62
Skills
● Cloud Computing: AWS, Azure
● Security: Cloud Security, Vulnerability Assessment
● DevOps/DevSecOps
● Compliance: BNM RMIT
● Tools: Kali Linux, AWS Console, Azure Portal, Burp Suite, Snyk, Metasploit, Nessus, Zap Proxy, Docker, Sonar Cloud, Kubernetes, GitHub, Jenkins, GitLab, Checkmarx, OpenShift Container Platform, GCP
Professional Certificates
● OWASP Top 10 API - ApiSec University
● Microsoft Azure - AZ900
● Microsoft Azure - AZ104
● API Penetration Testing - ApiSec University
● Certified DevOps Foundation - CCSD
● Certified Kubernetes Administrator (CKA)
Languages
● English: Fluent
● Malay: Native speaker
Soft Skills
● Time management
● Independent
● Adaptive person
● Critical thinking
● Teamwork
● Problem solving