Security Manager responsible for overseeing risk-based security program and compliance. Leading team and collaborating with stakeholders for cybersecurity in Indonesia.
Responsibilities
Develop and manage risk-based security program and strategy, drive its successful implementation through security, policies, procedures and standards.
Work closely with technical, non-technical stakeholders and cross-functional teams to ensure compliance with security standards and policies and integration of security requirements into business processes and projects.
Define risk appetite, develop risk acceptance, management and reporting protocols to make sure company leadership is aware of the risk profile and can make informed decisions. Conduct regular security assessments, audits and inspections to identify gaps and areas for improvement, and report the results.
Support the CTO in security budgeting, vendor selection, and control assurance activities.
Lead and manage a team of security professionals, including hiring, training and performance management.
Oversee the implementation and maintenance of security technologies such as SIEM, intrusion detection and prevention systems, WAF, vulnerability management, etc.
Implement security incident response protocols and plans, lead incident response and security breaches investigations. Conduct root cause analysis, develop and implement mitigation and corrective actions.
Act as a subject matter expert in cloud security, directly supporting DevOps and Software Engineering teams in secure infrastructure architecture, deployment, configuration and operations. Participate hands-on in security reviews of infrastructure changes.
Design and implement secure software development lifecycle (S-SDLC) and engage with Software Engineering and DevOps teams to implement secure development practices, including code reviews, static and dynamic security scanning, dependency checks, etc. Ensure software vulnerabilities are fixed in time and work closely with relevant teams to develop, manage and track SLOs on security fixes.
Stay current with emerging security threats and technologies, and implement appropriate measures to mitigate risks.
Provide training and awareness programs to technical and non-technical employees on information security best practices and procedures.
Requirements
7+ years of professional experience in cybersecurity with at least 3 years in a leadership or team-lead role.
In-depth understanding of cybersecurity principles and best practices.
Excellent understanding of risk-management principles and demonstrated experience implementing them in the real-life security program.
Hands-on experience implementing and reviewing cloud infrastructure configurations and assessing its security. Experience implementing secure infrastructure management pipelines.
Experience building and running security incident response programs and being hands-on coordinating and participating in security incident response.
Availability to respond to security alerts and respond to security incidents outside of business hours.
Certification in information security is preferable
Strong knowledge of SIEM tools, intrusion detection systems (IDS/IPS), and security monitoring tools
Benefits
Join us as we make magic happen to increase Indonesia’s financial inclusion!
Field Supervisor ensuring efficient security operations for United Security at client locations. Conducting inspections, providing leadership and maintaining compliance with protocols.
Managing Consultant driving cyber resilience improvements for critical national infrastructure, with a focus on regulatory frameworks. Leading client engagements and enhancing operational safety and uptime.
Security Engineer Intern at Snap Inc. Developing security projects and enhancing security posture with meaningful contributions during a 13 - week internship.
OT Cybersecurity Consulting Director at Marsh leading cyber risk assessments and consulting projects across Canada and other regions. Requires strong technical knowledge and client relationship building.
Senior Cyber Security Consultant delivering high - impact cybersecurity solutions to clients in various industries in Montreal. Collaborating closely with project managers and guiding junior consultants.
Consultant technique pour Microsoft 365 Security à Ingram Micro, impliqué dans le support avant - vente et le déploiement des solutions cloud Microsoft.
Specialist in Information Security at IESO ensuring security for Ontario's electricity system. Responsibilities include monitoring access logs, delivering security programs, and investigating breaches.
Partner Sales Specialist focusing on enabling partners to sell Microsoft Security solutions. Collaborating with teams to activate partners for effective sales across their customer base.