Skip to content
Proudly on .id — Indonesia's national domain

Kiell Tampubolon

I review and harden MCP servers and AI agents, build security automation that holds up against real CVEs, and write the research to back it up. I also train Indonesia's next generation on DNS security as a PANDI .id Academy trainer.

  • AI Security
  • MCP Security
  • Security Automation
  • Technical Writing

Cybersecurity Engineer · .id Academy Trainer (PANDI) · Internet Governance Advocate · Batam, Indonesia (working across Indonesia & Singapore)

01 / About

About

Cybersecurity engineer with cross-border experience in Indonesia and Singapore, and an active trainer for PANDI's .id Academy since 2024.

My work sits at the intersection of internet governance and DNS ecosystem security: phishing and DNS abuse mitigation on the operational side, digital literacy and safe .id adoption on the community side.

Founder of Cyber Nova, a Batam-based security startup.

Completed PANDI's Training of Trainer on DNS and DNSSEC and took part in DNS APAC 2024.

02 / Experience

Experience

  1. Jul 2025 – Present

    Founder & CEO

    Cyber Nova · Batam

    • Security startup: vulnerability assessment, threat intelligence, digital defense architecture.
    • Leads cross-functional technical teams and promotes local cyber talent.
  2. Jul 2024 – Present

    Security Engineer

    Constellar · Singapore (hybrid)

    • Security assessments and vulnerability scans.
    • Alert and incident monitoring and response.
    • Phishing simulation campaigns.
    • Security reporting for stakeholders across a multicultural organization.
  3. Jul 2023 – Jul 2024

    Kampus Merdeka Mentor, Red Hat & AI

    PT Kinema Systrans Multimedia (Infinite Learning) · Batam

    • Mentored students nationwide to RHCSA (EX200) and AI & Cybersecurity Practitioner certification.
  4. Oct – Dec 2022

    Junior Cyber Security / IT Support

    PT Schneider Electric · Batam

    • Production endpoint security (SCCM, Cylance, SentinelOne).
    • Network monitoring and incident documentation.

03 / Selected Work

Selected Work

Security Engineering Automation & Integration

Automated Phishing Triage & Email Forensics Engine

Enterprise email security operations & incident response

  • Reported emails used to mean an analyst opening the raw source and manually reading SPF/DKIM/DMARC verdicts for every ticket in the queue, a repetitive first pass that ate analyst time without making triage any more consistent.
  • Automated extraction and parsing of raw .eml/.msg artifacts for phishing investigations.
  • Header validation checks for SPF, DKIM, and DMARC alignment to surface spoofing vectors, flagging on alignment rather than raw pass/fail so convincing spoofs do not slip through.
  • Webhook integration with KnowBe4 Phish Alarm Button (PAB) and PhishER for automated triage routing, so an analyst opens a ticket with header verdicts and indicators already attached instead of a blank email.
  • AI-assisted triage workflow built with Microsoft Copilot Studio, Power Automate, and custom Python microservices; the model surfaces a recommendation and reasoning for ambiguous cases, a human still signs off on the close/escalate call.

Outcome — Published outcome: triage time for a reported email dropped from minutes to under thirty seconds per ticket, with a consistent verdict format across analysts.

  • Python
  • Power Automate
  • Microsoft Copilot Studio
  • KnowBe4 PAB/PhishER
Security Engineering Automation & Integration Software Engineering

Entra ID (Azure AD) Identity & Access Audit Engine

Enterprise identity security & AI administration

  • Built to catch identity drift, not one bad config: an offboarded account that stays enabled for weeks because reconciling three separate systems is nobody’s single job.
  • Automated cross-referencing of active vs. inactive Entra ID accounts against onboarding and offboarding tickets.
  • Some of the usual PowerShell cmdlets for role auditing were unavailable in the environment (licensing tier and admin-restricted execution policy), which ruled out the standard scripted approach.
  • Verified privilege boundaries for AI Administrator and Security Administrator roles directly through Microsoft Graph API calls and the Entra admin center’s role assignment views, cross-checked manually where API access was itself scoped down.
  • Automated drift detection for stale accounts and policy violations, with standing (not one-time) compliance reporting.

Outcome — Working around restricted cmdlets forced a more API-first design, one that does not depend on a specific module version or an admin-granted cmdlet that could be revoked later.

  • Microsoft Graph API
  • Entra ID
  • Entra admin center
Software Engineering Security Engineering

Tier-1 OSS Agentic Auditing & Responsible Offboarding

Open-source systems engineering & AI-SDLC research

  • Static and dynamic analysis across 25+ Tier-1 infrastructure repos, including vLLM, Qdrant, Ray, Temporal, OpenTelemetry, Dify, Meilisearch, DataFusion, and LiteLLM.
  • Surfaced issues including atomic memory-budget overflows in Rust vector databases, circuit-breaker race conditions in Ray Serve, and missing OTLP HTTP retry handling.
  • Chose to close 25 automated PRs rather than ship them: a patch that resolves a symptom in a local repro can still violate invariants only visible to someone who has lived in that codebase’s history.
  • Held to explicit DCO (Developer Certificate of Origin) and CLA compliance on anything that reached a sign-off decision, to protect maintainer bandwidth over raw PR volume.

Outcome — The standard applied throughout: if I would not want to review a PR as the maintainer, I should not be opening it as the contributor.

  • Static analysis
  • Dynamic analysis
  • Rust
  • OTLP
Teaching Security Engineering

Blue Team SOC Lab & Mentoring Framework

Training design · security mentoring

  • Hands-on mentoring modules built around open-source Blue Team stacks (CyberBlueSOC).
  • Interactive 60-90 minute detection and incident-response labs for SOC analysts.
  • CyberBlueSOC
Security Engineering Teaching

Enterprise Wi-Fi Security & Threat Awareness Campaign

Awareness communications · corporate InfoSec

  • Company-wide advisories on evil twin access points, captive portal risks, and public Wi-Fi hygiene.
  • Standardized helpdesk knowledge-base documentation for user-facing security reporting.
  • Helpdesk knowledge base
Security Engineering Automation & Integration

Payment Webhook Repair Lab

Integration reliability engineering - payment event handling

  • Built to answer one narrow question: when a payment provider sends the same event twice, sends events out of order, or fails halfway through, what does the system actually do.
  • Reproduces the common failure modes on a local harness: duplicate events, invalid signatures, malformed payloads, timeouts, upstream failures, partial writes, and out-of-order updates.
  • Boundary checks use HMAC signature verification against the raw request body, with a strict payload schema on top so a malformed field is rejected before it reaches state.
  • Event idempotency is handled by event ID and payload hash, so a duplicate carrying different data fails closed instead of silently overwriting state.
  • Order state transitions are explicit and reject stale events, so a late notification cannot move a fulfilled order back to pending.
  • A bounded retry worker tries a failed event three times, then moves it to a review queue. Manual replay is authorized and audited end to end.
  • Local HTTP API and an audit timeline over the request lifecycle, plus reset, emit, and replay scripts.
  • 18 deterministic tests cover the failure matrix end to end. No live payment provider is contacted.

Outcome — A reviewer can reproduce, watch, and reason about each failure mode without a payment account, and every recovery path is visible in the audit timeline.

Security Engineering Software Engineering Automation & Integration

MCP Local-to-Hosted Deployment Fix

AI infrastructure engineering - MCP gateway controls

  • Built for the specific gap between a local MCP server that works on a laptop and one that runs behind a gateway other people can reach.
  • A streamable HTTP gateway sits in front of a small MCP tool registry, with a target smoke client that talks to it the same way a real client would.
  • Bearer-token authentication is validated per request. The wrong token returns 401, the wrong path returns 404, a slow tool returns 408, and an unavailable tool returns 503. The client sees the same failure classes it will see in production.
  • Tenant isolation is enforced at the gateway, not inside tools, so a tool cannot accidentally return another tenant fixture.
  • Write tools require a request-bound approval that expires. Read tools do not. The distinction is enforced by the same policy layer that decides everything else.
  • Structured JSON logs carry a request ID per call, and secrets are redacted before the log line is written.
  • Deterministic failure injection lets a reviewer trigger each failure class on demand, no production traffic needed.
  • 13 runtime tests cover authentication, tenant boundary, approval binding, and each failure status.

Outcome — A team can see the checks and controls a real hosted MCP gateway needs before they move their own integration, with a runbook for each failure class instead of an optimistic demo.

Security Engineering Automation & Integration

MCP Security Preflight

Pre-release security review - MCP tool metadata and policy

  • Built for teams about to expose MCP tools to users or internal agents, where a happy-path demo is not enough evidence that the tools are safe to hand out.
  • Static rules scan tool metadata for unsafe command declarations, excessive filesystem and network scope, secret-like values, and untrusted input flowing into sensitive operations.
  • Secret-like values are redacted before they reach the report, so the finding can be shared without leaking the value it is about.
  • Behavioral checks hit a local fixture server to test tenant boundaries, write approval, and quota enforcement under controlled inputs.
  • Writes require an approval bound to a specific request and tool, and approvals expire. Cross-tenant reads are denied at the fixture boundary before any data is returned.
  • Every decision is recorded as an audit event with a reason code and a sanitized input hash.
  • One run produces both a Markdown report and a JSON report with rule ID, severity, affected tool, evidence, and remediation.
  • 10 deterministic tests cover the rule engine, tenant boundary, approval, quota, and report generation. The output states plainly that the preflight is not a penetration test.

Outcome — Each finding becomes an engineering task with a rule ID and a remediation, and the report is honest about what a bounded preflight can and cannot prove.

Security Engineering Automation & Integration

mcpscan: MCP Supply-Chain Security Scanner

MCP supply-chain & CI/CD security scanning

  • Built because a tool description is just text to a language model, and text is instructions: a prompt-injection payload hidden in a tool description, including invisible Unicode, executes with no visible diff for a human reviewer to catch.
  • 22 static rules across command injection, tool poisoning, dangerous .claude/ hooks, over-broad permissions, leaked secrets, vulnerable SDK versions, path traversal, SSRF, insecure deserialization, disabled TLS verification, and GitHub Actions workflow risks such as pwn requests and workflow_run token reuse, mapped to the OWASP MCP Top 10:2025.
  • Zero runtime dependencies, no network calls, no telemetry. It only reads files, so it is safe to point at a repository you do not trust yet.
  • Benchmarked the path traversal rule against four real 2026 MCP CVEs, including a CVSS 9.1 unauthenticated RCE chain, and found it only covered read sinks. Every real exploit used a write sink. Shipped the fix and escalated write-sink hits to high severity by default.
  • The --fix flag only patches findings with one unambiguous correct answer, such as yaml.load to yaml.safe_load, so it never generates a wrong patch that quietly compiles.
  • Built a small harness that writes one adversarial fixture per detection rule and checks results against the rule registry, not memory. Six of seven fixtures fired on the first pass. The miss was a secrets regex that could not match JSON-quoted keys, now fixed. Two obfuscation techniques still slip past detection and are documented as open, not claimed as solved.
  • Ships as a CLI on PyPI, a GitHub Action, a pre-commit hook, and SARIF 2.1.0 output that drops straight into GitHub code scanning.

Outcome — A self-built adversarial harness catches six of seven attack fixtures on the first pass, and the two open gaps are documented rather than hidden, the same standard the tool applies to the MCP servers it scans.

  • Python
  • Static analysis
  • SARIF 2.1.0
  • GitHub Actions

04 / Training & Speaking

Training & Speaking

2,000+

learners reached

6+

institutions & programs

2

countries (ID & SG)

  • 2024 – Present

    .id Academy (PANDI)

    Active Trainer

    Digital literacy and internet governance bootcamps: UNIMA (Manado, eastern Indonesia) and ITEBA (Batam).

  • Nusa Dua, Bali · Jul 2024

    PANDI Training of Trainer

    DNS Fundamentals to DNSSEC

    Instructors including Champika Wijayatunga (ICANN). Participant, DNS APAC 2024.

  • Jul – Oct 2025

    Google Cloud Arcade (via Dicoding)

    Hundreds of learners

    Facilitator

    Hundreds of learners across cloud and cloud security pathways.

  • Nov 2024

    DTS × Google Career Certificates (Kominfo)

    Cybersecurity PROA Facilitator

    National digital talent scholarship program facilitation.

  • Jun 2025

    Hacktiv8

    100+ attendees

    Speaker — "Phishing 101: Don't Be a Victim!"

    Practical anti-phishing session for a developer audience.

  • 2025

    Schoters by Ruangguru, Work Abroad Festival 2025

    400+ attendees

    Panelist — "Hack the Future: Building a Cybersecurity Career in Singapore"

    Career panel on building a cybersecurity career across borders.

05 / What I Do

What I Do

Offensive & Defensive Security

Penetration testing, threat intelligence, vulnerability management.

DNS & Internet Governance

DNS abuse mitigation, DNSSEC, safe .id adoption, multistakeholder engagement.

Training & Community

Curriculum design, workshops and bootcamps from campus to industry.

Security Automation & Tooling

Python microservices, Power Automate, and Copilot Studio workflows that turn manual security triage into a repeatable pipeline.

06 / Certifications

Certifications

07 / Writing

Writing

View all writing →

08 / Contact

Contact

Available for short, scoped AI/MCP security and automation engagements, and open to security engineering roles. Training collaborations and speaking invitations are always welcome.

Looking to hire for an MCP/AI security review or a security automation sprint? View services .

Looking to book a talk or training session? View the speaker kit .

LinkedIn GitHub Medium