EMPANELED · VISASQ · COLEMAN RESEARCH GROUP

LUKMANUL
HAKIM

Principal Solutions Architect & Cloud Modernization Strategist

Legacy Decomposition · DevSecOps · Systems Reliability (FMEA/FTA)

15
Years Evolution
$93M
CAPEX Governed
99.9%
Availability SLA
Executive Summary
Cross-layer Solutions Architect with 15 years of progressive engineering experience specializing in legacy modernization and monolithic system decomposition into resilient, cloud-native microservices architectures. Bridges physical infrastructure failure modes (L1 fiber/FTTH, $93M CAPEX scope) to distributed multi-cloud platforms (L7 K8s/GitOps) and quantitative risk modeling. Empaneled Subject Matter Expert across global expert networks (VisasQ, Coleman Research), delivering retained technical due diligence and modernization assessments for institutional investors. Integrates standardized reliability engineering (IEC 61025 FTA, IEC 60812 FMEA, and ISO 31000 Risk Governance) with capital governance principles to eliminate single points of failure (SPOF), optimize deployment security, and protect enterprise EBITDA integrity.

Assigned under the Directorate of Operation in 2013. Principal Cloud Architect today.
Ground-truth failure mode analysis across every layer of the stack.

Architectural Differentiator

The Cross-Disciplinary Engineering Moat

Most cloud architects treat infrastructure purely as software abstractions. My practice evaluates systems across physical plant constraints, mathematical fault trees, and capital exposure.

Layer 1 Physical Plant

Assigned within the Directorate of Operation for Telkom Indonesia Group's nationwide IDR 1.5T ($93M) copper-to-FTTH program. Governed ODN attenuation compliance, OSP splicing QA, and BSS/OSS ETL data reconciliation (Oracle, PostgreSQL, SOAP).

Telkom Akses · 2013–2014

Formal Risk Engineering

Authored peer-supervised research applying IEC 60812 (FMEA) and IEC 61025 (FTA) on live FTTH fulfillment architectures. Coupled with a Bachelor of Economics (S.E.), translating engineering error budgets into CAPEX protection and EBITDA metrics.

Thesis Verified · 2018–Present

Layer 7 Cloud Modernization

GCP Professional Cloud Architect. Multi-Cloud (AWS, GCP, Azure, Alibaba), Kubernetes (GKE/EKS/AKS), Terraform IaC, GitOps (Flux CD), CI/CD security gating (OWASP ZAP, SonarQube), and zero-downtime monolithic decomposition for FinTech and Logistics.

GCP PCA Certified · 2015–Present
Execution Blueprint

Legacy Decomposition & Zero-Touch Provisioning (ZTP)

Deconstructing legacy monolithic bottlenecks into autonomous DAG orchestration pipelines. Decoupled BSS-OSS architecture eliminates financial revenue leakage and establishes automated compliance verification.

STATUS: PRODUCTION GRADE · 1 MINUTE 54 SECONDS SLA
PARALLEL DAG ORCHESTRATION
ZTP DAG Pipeline execution showing 1m 54s
IMMUTABLE BAST AUDIT ARTIFACT
GitHub Artifacts showing BAST-WorkOrder JSON

Architectural Deep Dive · 17 Min

The Blueprint, Explained: When Perfect Code Collides with the Physics of the Streets

Systems Translation Layer

Physical Logic · Cloud-Native Translation

Every principle applied in modern cloud architecture was first enforced as a physical constraint during national infrastructure rollout.

Pillar Physical Logic (Layer 1 OSP) Cloud-Native Translation (Layer 7)
I. IDENTIFICATION Asset Tagging: Every cable must possess a unique coordinate ID before burial. An untagged cable represents unquantifiable capital loss. Immutable Tagging: Every cloud resource and Kubernetes pod carries mandatory metadata labels (CostCenter, Owner, TTL) or CI/CD pipelines reject deployment.
II. RESILIENCE Preventive Maintenance: Detecting optical signal attenuation before fiber fracture. Legacy MTTR was 15 hours. Self-Healing Systems: Kubernetes Liveness/Readiness probes and Horizontal Pod Autoscalers isolate failure domains. MTTR <300ms.
III. EFFICIENCY Route Optimization: Mapping shortest physical optical routes to conserve materials and protect CAPEX. FinOps & Rightsizing: Automated workload scheduling and vCPU rightsizing that reduce cloud OPEX by up to 40% without compromising SLA throughput.
IV. SECURITY Physical Plant Hardening: Securing access to Optical Distribution Cabinets (ODC) and manholes to eliminate tampering vectors. Zero Trust Architecture: Strict mTLS service mesh, IAM Least Privilege, and automated CI/CD security scanning (OWASP ZAP, SonarQube) mitigating 60% of vulnerabilities.
V. AIOps & AGENTIC AI Predictive Telemetry: OTDR trace analytics and historical outage correlation to predict fiber disruption before customer impact. Autonomous Infrastructure: Dynamic anomaly detection and Agentic AI workflows (Azure AI Studio, Semantic Kernel) for self-healing operational governance and token lifecycle management.
Evolution Roadmap
L1 → L7 ARCHITECTURE
Cloud Modernization Architecture: Monolithic Legacy to GKE-HA with AIOps
Modernization Roadmap: Monolithic Legacy → Multi-Cloud Migration → GKE-HA with AIOps & Agentic AI
Telemetry Center

Operational Telemetry

Consolidated view of 34 provinces · High Availability Active

SYSTEM: ONLINE (100%)
LIVE TOPOLOGY
● BACKBONE ACTIVE
National Backbone Topology

BACKBONE WEST

Gateway: Batam (SG)

OPTIMAL

SEGMENT CENTRAL

Expansion: HA Ready

ACTIVE

LOOP EAST

Route: North & South

STABLE
KUBERNETES: GKE MULTI-CLUSTER HEALTHY GITOPS: FLUX CD SYNCHRONIZED (ZERO-TOUCH) AZURE AI: AGENTIC WORKFLOWS & SEMANTIC KERNEL ACTIVE TERRAFORM: IMMUTABLE INFRASTRUCTURE APPLIED SECURITY: UNAPPROVED IAM ROLE BLOCKED FMEA RISK AUDIT: RPN WITHIN ACCEPTABLE LIMITS IEC 60812 / IEC 61025 / ISO 31000 COMPLIANT
Career Track Record

Professional Evolution

Empaneled Industry Advisory Council Member

Sept 2025 – Present

VisasQ Inc. & Coleman Research Group · Global (Remote)

  • Deliver retained, NDA-governed technical due diligence and modernization architecture assessments for Private Equity (PE) firms and institutional investors evaluating cloud migration feasibility and telecom backbones.
  • Translate distributed architectures, high-concurrency systems, and multi-cloud resilience into formal risk indices evaluated under ISO 31000 Risk Governance and capital exposure frameworks.
  • Model distributed fault isolation, Single Point of Failure (SPOF) mitigation, and operational risk exposure across legacy-to-cloud transitions using IEC 61025 (FTA) and IEC 60812 (FMEA).

Enterprise IT Advisory Consultant

Jan 2023 – Feb 2025

PT Altha Dyanusa Consulting · Jakarta, ID

  • Formulated enterprise multi-cloud blueprints and ISO 31000-aligned IT risk governance frameworks for institutional clients modernizing monolithic infrastructure into cloud-native environments.

Principal Architect & DevSecOps Consultant

Feb 2015 – Dec 2022

Independent Technology & Architecture Mandates · Indonesia

  • PT Meteor Inovasi Digital (Sep–Dec 2022): Directed 4-month multi-cloud legacy migration (AWS/GCP/Alibaba Cloud); decomposed VM-based monolith into containerized Kubernetes microservices using Terraform, achieving 99.9%+ availability and zero-downtime cutover.
  • PT Kredit Pintar Indonesia (Jul–Sep 2022): Architected GitOps delivery workflows (Flux CD) on Alibaba Cloud, decoupling stateful legacy FinTech workflows into stateless, OJK-compliant microservices with automated audit pipelines.
  • PT Tri Adi Bersama / Anteraja (Nov 2021–Jul 2022): Scaled container orchestration (GKE/EKS) for 120+ decoupled logistics microservices; embedded CI/CD security gates (OWASP ZAP/SonarQube), mitigating 60% of critical vulnerabilities during high-concurrency peak operations.
  • PT Hashmicro Solusi Indonesia (May–Oct 2020): Automated monolithic ERP cloud provisioning and migration pipelines using Terraform IaC, reducing client environment provisioning lead time by 70%.
  • PT Dimension Data Indonesia (Feb–Jun 2015): Engineered MPLS backbone optimization for Tier-1 banking clients using SolarWinds network telemetry to resolve latency bottlenecks across critical payment infrastructure.

Principal Operational and Compliance Manager

Apr 2013 – Oct 2014

PT Telkom Akses (Telkom Indonesia Group) · Directorate of Operation · Jakarta, ID

  • Assigned within the Directorate of Operation to execute field quality compliance audits and service fulfillment testing across the nationwide copper-to-FTTH rollout (IDR 1.5T program scope).
  • Applied IEC 61025 (FTA) and IEC 60812 (FMEA) to identify fulfillment failure modes, achieving a 20% defect reduction during testing with zero capital asset discrepancy.
  • Enforced ISO 31000 Risk Governance protocols to secure compliance, audit-readiness, and SLA integrity across regional fulfillment workflows.
  • Built ETL data reconciliation scripts (Oracle, PostgreSQL, SOAP) linking physical field network inventory with BSS/OSS platforms (I-Sisca, TenOSS) to maintain audit-ready asset records.

Customer Care Specialist

Oct 2011 – Oct 2012

Biznet Networks · Jakarta, ID

  • Handled enterprise customer inquiries, logged connectivity issues, and coordinated trouble-ticket tracking via CRM.

// System Initialization (2011) · User: Lukmanul_Hakim

Technical Specifications

System Capabilities

1.0 Multi-Cloud & Migration
Monolith Decomposition · GCP · AWS · Azure · Alibaba Cloud
2.0 IaC & Platform
Terraform (Advanced) · Ansible · Zero-Touch Provisioning
3.0 Containers & GitOps
Kubernetes (GKE/EKS/AKS) · Docker · Flux CD · Helm
4.0 DevSecOps & Security
SonarQube · OWASP ZAP · Vault · IAM Least Privilege · mTLS
5.0 Reliability & Risk
IEC 60812 (FMEA) · IEC 61025 (FTA) · ISO 31000 Governance · RCA
6.0 Data & Integrations
Oracle · PostgreSQL · SOAP APIs · BSS/OSS Reconciliation
7.0 Agentic AI & Enterprise LLMOps
Azure AI Studio · Semantic Kernel · Autonomous Agent Workflows · Document Intelligence · Token Governance & AI Safety
8.0 Compliance & Regulatory
OJK Compliance · Bank Indonesia Mandates · ISO 27001 · FinOps
9.0 Scripting & Automation
Python · Bash · PowerShell · GitHub Actions · GitLab CI
Verified Credentials

Certifications & Licenses

VERIFIED

Microsoft Certified: Azure AI Apps & Agents Developer Associate

Verify on Microsoft Learn (AI-103)

Microsoft Azure · Validated
VERIFIED

Google Professional Cloud Architect

ID: ac6c40d564fc4911b48506b04f269dac

Google Cloud
VERIFIED

Google Associate Cloud Engineer

ID: 55864fb403294d648d9d2130326a0842

Google Cloud
VERIFIED

AWS Cloud Quest: Generative AI Practitioner

ID: 319f538b-8769-4719-b93f-29b81814900c

Amazon Web Services
VERIFIED

AWS Certified Cloud Practitioner

ID: YT3X1MX1VFBE1K5V

Amazon Web Services
VERIFIED

Cisco DevNet Associate

ID: 1987298840-45/PROA/BLSDM/2024

Cisco Systems
VERIFIED

Cisco CyberOps Associate

ID: 0447256131-103/OA.DTS/2020

Cisco Security
Academic Rigor & Professional Development

Academic Degree & Research

Bachelor of Economics (S.E.)

University of Mercu Buana Jakarta · Mar 2016 – Oct 2018 | GPA: 3.17 / 4.00

Undergraduate Thesis:

Hakim, L. (2018). Operational Risk Analysis Using Fault Tree Analysis and Failure Mode and Effect Analysis in the Process Testing of the FTTH Triple Play (IndiHome) Fulfillment System (Undergraduate thesis). University of Mercu Buana Jakarta.

Academic Thesis Repository (ID: 44912)

Enterprise AI & Agentic Engineering

Production AI & Autonomous Workflows

Enterprise Model Orchestration · Microsoft AI-103 Validated

Autonomous Agent Systems: Multi-agent orchestration via Semantic Kernel and Azure OpenAI

Perception & Extraction: Multi-modal Computer Vision and Azure Document Intelligence

Enterprise AI Governance: Token quota engineering, safety guardrails, and Zero Trust API security

Cloud-Native Deployment: Containerized AI workloads deployed on Azure Container Apps with CI/CD

View Verified Microsoft Learn Credential