Hi, I'm Marcelius — I secure and automate enterprise IT.
I work in the Data Center division at Indomobil Group, where I focus on network security monitoring, penetration testing, and building PowerShell/Python automation for enterprise IT operations. I graduated from Bina Nusantara University with a major in Computer Science, specializing in Cyber Security.
Experience
Enterprise cyber security and IT infrastructure work.

- Implemented network security controls and monitored logs from CheckPoint and Sentinel to detect and prevent internal and external threats.
- Designed and executed proof-of-concept penetration tests for web applications and in-house Android apps, covering phishing, brute-force attacks, SQL injection, XSS, and DDoS.
- Conducted static/dynamic analysis, app reverse engineering, network interception, and secure authentication/storage testing using MobSF, Burp Suite, Frida, JADX, and APKTool.
- Identified and documented vulnerabilities against the OWASP / OWASP Mobile Top 10 and collaborated with developers to remediate and verify fixes.
- Planned and designed network infrastructure, including topology optimization, device configuration, and integration between hardware and software.
- Maintained network and server performance through monitoring, routine maintenance, and data analysis to ensure stability and efficiency.
- Assisted with email and IP address data collection for operational and security purposes.
Projects
Enterprise tools I designed and built to automate and secure IT operations at Indomobil Group.
Enterprise PC Provisioning System
An automated PC/laptop provisioning system that turns a multi-hour manual IT setup into a guided, one-USB workflow — pairing a PowerShell/WinForms deployment tool with a Python (Flask) + MySQL backend.
- Automates disk partitioning, software installation, Active Directory domain join, and EDR enrollment for every new company device
- Syncs asset and deployment data into the corporate inventory system via a secured REST API
- Zero-trust by design: no credentials are ever stored in the distributed tool — secrets are released only after an HMAC-SHA256 authentication gate verifies live Active Directory credentials
- All directory communication runs over Kerberos-sealed and signed LDAP
User Account Management System
A PowerShell (WinForms) automation tool that streamlines the entire Active Directory user lifecycle for the IT team, replacing a series of manual, error-prone admin tasks with a guided point-and-click workflow.
- Creates accounts individually or in bulk from pasted new-hire templates, with duplicate-account checking
- Bulk-disables and relocates resigned employees' accounts, auto-detecting records from pasted HR data
- Edits user domains/logons with a live email-alias (proxyAddress) preview before applying changes
- Pulls pending new-hire requests directly from an internal HR ticketing API into the account-creation form
- Remotely triggers AD Connect Delta Sync over WinRM so changes propagate to AD instantly
Password Policy Security Hardening
Identified and remediated critical authentication vulnerabilities in an enterprise .NET application, replacing unsecured password change functionality with a robust password policy enforcement system.
- Discovered and documented authentication gaps in the password change process that posed significant security risks
- Designed and implemented a comprehensive password policy feature with strength requirements, expiration, history tracking, and complexity rules
- Integrated HMAC-based validation to prevent password manipulation and brute-force attacks
- Conducted security testing to verify the implementation against OWASP authentication standards
- Provided documentation and recommendations for future authentication hardening efforts
Mobile App Security Assessment
Conducted comprehensive penetration testing on enterprise mobile applications, discovering critical API security vulnerabilities that allowed unauthorized access and data manipulation as an administrative user.
- Identified unprotected and inadequately secured API endpoints exposed to unauthorized access
- Exploited privilege escalation vulnerabilities to gain administrative-level access to sensitive data
- Demonstrated capability to modify real production data, exposing critical business and user data integrity risks
- Conducted static and dynamic analysis using MobSF, Burp Suite, and Frida for comprehensive coverage
- Provided detailed security recommendations including API authentication hardening, role-based access control (RBAC), and data validation strategies
- Documented findings against OWASP Mobile Top 10 standards for remediation guidance
Skills & Technologies
The tools and disciplines I use across security testing, infrastructure, and automation.
Organizations
Campus organizations where I built leadership and collaboration skills.

Keluarga Mahasiswa Katolik BINUS
> Coordinator of Public Relations (2023)
> Coordinator of Equipment (2022)
> Vice President, New Student Admission (2022)

Himpunan Teknik Informatika BINUS
> Activist of Relations Division — Marketing
> Staff of Concept and Design, HINGAR (2022)
> Staff of Equipment, TECHNO (2022)
> Assistant Lecturer, HIMTI Responsi (2022 — 2023)
Volunteering
Event and community contributions during my time at BINUS.
BINUS — Co-Host, Webinar PIT AIA — 2022
- Opening the Zoom room for hosting the webinar
- Contacting participants
- Assisting with technical issues and documenting the proceedings
BINUS — Freshmen Leader & Partner — 2022 — 2023
- Assisted new students in adapting to university life by providing academic information and introducing campus organizations
- Helped students navigate academic challenges
- Monitored students' academic and non-academic progress, fostering two-way communication for a supportive university experience
Let's work together
I'm always open to discussions and collaborations. If you have ideas to share or are interested in working together, let's connect.
Message me on LinkedIn