15 days ago
Jakarta, IndonesiaSenior
Responsibilities
- Build, tune, and improve security detection and monitoring capabilities across the technology ecosystem.
- Develop security automation and internal tooling for investigation, containment, evidence collection, and incident response.
- Investigate security incidents, determine root causes, and convert findings into prevention and detection improvements.
- Conduct security assessments across cloud, infrastructure, applications, and perimeter environments.
- Analyze emerging threats and abuse patterns including account takeover, credential stuffing, payment abuse, bots, scraping, and API attacks.
- Partner with Engineering and SRE teams to improve logging, security controls, system hardening, and remediation.
- Support threat emulation, attack simulation, incident response, and continuous security improvement initiatives.
- Participate in an on-call rotation as an escalation tier.
Requirements
- 2–3+ years of hands-on cybersecurity experience in Blue Team, Detection Engineering, Security Operations, Security Automation, or related areas.
- Strong experience with SIEM platforms such as Splunk, Elastic, Wazuh, or Sentinel, including building and tuning detection content.
- Proficiency in Python or Go for maintainable security automation and internal tooling.
- Strong fundamentals in Linux, networking, cloud security, APIs, and security monitoring.
- Familiarity with MITRE ATT&CK, Sigma, SOAR, incident response, threat intelligence, and attack simulation methodologies.
- Hands-on experience with enterprise perimeter security technologies, including Cloudflare and firewall management.
- Strong problem-solving and communication skills, including the ability to explain technical findings as risks and remediation recommendations.
