Privacy Analyst · Cyber Threat Intelligence · PCVE

Hanif K

~/$ cat identity.log

Privacy Analyst and Cyber Threat Intelligence Researcher. I build compliance-grade data portals and conduct OSINT investigations to combat a broad spectrum of cybercrimes and extremism. I leverage "vibe coding" and full-stack development as strategic enablers to rapidly automate threat intelligence pipelines and operationalize digital justice.

OSINT Certified — Red Team Leaders Cybercrime Combat & Investigation Google Cybersecurity YSEALI Cybersafe ASEAN CTI · PCVE Research
hanif@privacy-sec: ~
01 / about_me

Who Am I

I'm a Privacy Analyst and Cyber Threat Intelligence (CTI) Researcher focused on combating cybercrime, ensuring data protection, and advancing digital civic safety.

While I am highly proficient in full-stack engineering, I approach coding strictly as a strategic enabler ("vibe coding"). Instead of pursuing traditional software engineering roles, I utilize development skills to rapidly prototype OSINT tools, automate threat intelligence pipelines, and architect systems that comply with rigid privacy laws (GDPR, BSI IT-Grundschutz).

My core mission is digital justice. I actively research and build solutions at the intersection of security and civic duty — ranging from an anti-scam resilience platform and cybercrime investigation workflows, to a RAG-based counter-extremism (PCVE) assistant.

current_focus.json
Privacy & Compliance → GDPR · DSGVO · Data Minimisation
Cybercrime & CTI → Threat Intelligence · Cybercrime Investigations · OSINT Workflows
Applied Security AI → RAG-based PCVE & counter-extremism
Technical Enablers → Full-stack prototyping to support security operations

// privacy note
Contact details omitted from this public page.
Reach out via LinkedIn or professional channels to connect.

Privacy & GRC
GDPR · DSGVO · BSI IT-Grundschutz · Data Audits
Cybercrime & CTI
OSINT · Cybercrime Investigations · PCVE Research
Security AI / RAG
LLM · Vector DB · Disinformation Analysis
Security Engineering
Anti-Scam Platforms · Threat Modeling
Cloud SecOps
AWS · Docker · Secure CI/CD · Access Control
Full-Stack Enablers
Python · Java · Next.js (Prototyping & Automation)
02 / experience

Work History

Oct 2022 – Jul 2024
IT Administrator & Infrastructure Lead
URSA · Indonesia
  • Hardened web server configurations and enforced database access control policies
  • Architected secure digital infrastructure protecting organizational data assets
  • Led technical roadmap aligning infrastructure with operational security needs
Dec 2021 – Feb 2022
Data Analyst Intern
Heptaco · Indonesia
  • Engineered data pipelines and transformation workflows for secure analytics
  • Built executive dashboards tracking key performance indicators
  • Delivered segmentation models to support strategic decisions
Mar 2021 – Sep 2021
Data Scientist Intern
Solusi247 · Jakarta
  • Built NLP pipelines (LDA, Word2Vec) for text classification and pattern discovery
  • Developed RESTful Flask APIs for secure, real-time inference endpoints
  • Implemented Named Entity Recognition for intelligence gathering on text corpora
03 / expertise

Core Domains

Privacy & Compliance
  • GDPR / DSGVO Implementation
  • BSI IT-Grundschutz Standards
  • Data Minimisation & RBAC
  • Immutable Audit Log Architecture
CTI & Cybercrime
  • Broad Cybercrime Investigations
  • Digital Threat Tracking
  • OSINT & Threat Intelligence
  • Anti-Scam Detection & Scoring
Security AI & PCVE
  • RAG-based research assistants
  • Counter-extremism tooling
  • Disinformation analysis pipelines
  • LLM + Vector DB for Intelligence
Full-Stack Enablers
  • Rapid Tooling (Java, Python, JS)
  • API Development for SecOps
  • Cloud Deployment Automation
  • "Vibe Coding" for OSINT automation
04 / projects

Selected Work

GRC PORTFOLIO
SEC_006
Data Privacy & GRC Legal Analysis

A comprehensive portfolio of Governance, Risk, and Compliance (GRC) projects focusing on global data protection frameworks. Includes deep-dive legal text analyses on GDPR Purpose Limitation, HIPAA vs GDPR ISO comparative mapping, CCPA-compliant privacy engineering for automotive tech, and corporate Terms of Service human rights assessments.

GDPR / CCPA HIPAA / ISO Privacy Engineering Legal Analysis
Privacy · GRC
COMPLIANCE
SEC_002
MediGuard Deutschland — GDPR Healthcare Portal

Enterprise patient management system engineered strictly for German healthcare law (§630f BGB, §33 DSGVO, BSI IT-Grundschutz). Enforces privacy by design with immutable medical records (soft-delete only), strict RBAC across 4 organizational roles, 72h BSI breach notification tracking, and a comprehensive audit log for legal compliance.

DSGVO / GDPR BSI Compliance Data Minimisation RBAC Auditing Java Spring Boot
Privacy · GRC
SEC_001
SafePulse — Anti-Scam OSINT & Resilience Platform

Platform designed to combat financial cybercrime by analyzing messages, URLs, phone numbers, and bank accounts for scam indicators. Utilizes automated OSINT workflows to generate scored risk reports. Features anonymous incident reporting to protect whistleblower identities, serving as a frontline defense against digital fraud.

Anti-Scam / Fraud OSINT Workflow Cybercrime CTI Anonymized Reporting
Threat Intelligence
Research
SEC_004
Digital Resilience Assistant — PCVE RAG System

RAG-based AI platform supporting evidence-based intelligence and prevention in: counter-radicalization, PVE (Prevention of Violent Extremism), and disinformation analysis. Automates knowledge retrieval regarding ideology-based extremism and separatist contexts. Built specifically to assist security practitioners and CTI researchers.

Counter-Extremism PCVE Research Disinformation Security AI / RAG
⚠ Educational & Preventive — This application is strictly for intelligence research and preventative purposes. The repository is encrypted and kept private due to the highly sensitive nature of counter-terrorism materials.
🔒 Private CTI Repo Intelligence · AI
SEC_003
SafeNet — Network Anomaly Platform

Security platform extending the SafePulse ecosystem toward infrastructure-layer defense. Automates network threat monitoring, anomaly detection, and digital safety tooling for endpoint environments. Utilizes engineering as a vehicle to streamline threat intelligence gathering.

Threat Monitoring OSINT Automation Incident Response
Security · Monitoring
SEC_005
Server Security Hardening Toolkit

Comprehensive security audit and hardening framework for production web deployments. Focuses on database encryption, access control enforcement (RBAC), intrusion detection, and automated secure backup workflows. Derived from real production infrastructure securing organizational data.

Server Hardening Data Protection Access Control
Coming Soon SecOps
ENG_001
Engineering Enabler: Complex System Architecture

Legacy engineering project demonstrating the ability to architect complex, secure, multi-tenant database systems (NexStay Hotel Platform). Showcases deep understanding of JWT authentication, role-based access control, and backend logic which now supports my ability to audit and secure similar enterprise systems.

System Architecture RBAC / Auth Auditing Data Flow
GitHub Supporting Skill
05 / contact

Let's Combat Cybercrime
& Secure Digital Rights

Open to roles in Privacy (GRC), Cyber Threat Intelligence, OSINT Investigations, and broader Cybercrime compliance. Also available for research collaborations in PCVE and digital safety.

Available for Privacy & CTI opportunities
© 2026 Hanif K — All rights reserved HK://PRIVACY · CTI · PCVE · GRC Secured by design.