IT Application Security
Must-have:SecurityLead
SALARY IS NEGOTIABLE AND WILL BE DISCUSSED DURING THE INTERVIEW, BASED ON CANDIDATE'S QUALIFICATIONS AND EXPERIENCE.
Requirements:
- Minimum 4–5 years in IT, with at least 3 years in an IT security or cybersecurity-focused role
- Hands-on experience in vulnerability assessment and penetration testing of web applications, APIs and infrastructure (e.g., Burp Suite, Nessus/OpenVAS, Nmap, Metasploit), including writing reports and following findings through to remediation
- Experience in security monitoring and incident handling using a SIEM/SOAR platform; experience with Wazuh and TheHive is a plus.
- Solid knowledge of network, endpoint and application security, including firewalls, IDS/IPS, access management, OWASP Top 10 and secure SDLC
- Experience supporting security audits and familiarity with ISO 27001
- Proven project management and communication skills: able to coordinate vendors and crossdepartment teams, and explain security risks clearly to management in Bahasa Indonesia and English
- Bachelor's degree in Computer Science, Information Technology or a related field; CompTIA Security+ or CEH certification is a plus.
Responsibilities:
- Maintain a secure IT environment for all company applications, infrastructure and end-user devices by managing security tools (firewall, IDS/IPS, endpoint protection, email security, IAM) and making sure security patches are applied on time
- Run the VAPT program: perform internal vulnerability scans and penetration tests, coordinate external penetration tests with vendors, and drive remediation with application and system owners until fixes are verified
- Monitor security events using SIEM/SOAR and lead incident response, from alert triage and investigation to recovery and post-incident review
- Work with developers to build security into applications, including secure coding guidance, OWASP Top 10 controls and security review before go-live
- Support internal, customer and third-party security audits, close audit findings, and work with the IT Security Governance team to maintain security policies and SOPs aligned with ISO 27001
- Manage security projects end to end and report security status, risks and metrics to management regularly