Deskripsi pekerjaan IT Security PT Inovasi Daya Solusi
Job Description
Cloud & Infrastructure Security Engineering
Secure Infrastructure: Design, configure, and maintain secure access controls and network perimeters within Cloud Platform (Google).
Firewall Management: Manage VPC firewall rules and secure remote access gateways (IAP/VPN).
DevSecOps Automation: Integrate and maintain automated security scanning tools (SAST/DAST, secret detection) within GitLab CI/CD pipelines.
Security Architecture: Proactively design and implement new security controls, identity policies (IAM), and encryption standards to mature our defense depth.
Posture Optimization: Evaluate the existing GCP and GitLab environment to identify security gaps and design the long-term security roadmap.
Security Monitoring & Incident Response
Continuous Monitoring: Build, maintain, and optimize security alerting dashboards and log aggregation using Datadog.
Incident Handling: Act as the first and primary responder to all security alerts, triaging threats, containing incidents, and performing root-cause analysis.
Vulnerability Remediation: Conduct regular vulnerability scans, prioritize risks, and collaborate with developers to patch infrastructure and code flaws.
Hands-on Penetration Testing
- Internal Pentesting: Conduct regular, scoped penetration testing against our web applications and cloud infrastructure.
- Exploit Verification: Manually verify automated scan results to eliminate false positives and demonstrate real-world risk impact to the business.
Compliance & Risk Governance (ISO 27001)
Audit Readiness: Own the maintenance of our ISO 27001 Information Security Management System (ISMS) to ensure we remain audit-ready.
Evidence Collection: Gather and document continuous compliance evidence across all technical and administrative controls.
Policy & Risk Management: Perform regular internal risk assessments, update security policies, and manage the company asset register.
Requirements
- Experience: At least 3+ years of dedicated cybersecurity experience.
- Cloud Infrastructure: Proven expertise securing Google Cloud Platform (GCP).
- Network Security: Hands-on experience configuring GCP VPC firewalls and Cloud Armor.
- Penetration Testing: Practical experience conducting web application and infrastructure pentests.
- DevSecOps Automation: Experience integrating SAST/DAST scanning into GitLab CI/CD pipelines.
- Security Monitoring: Competency routing logs and building alerting dashboards in Datadog.
- ISO 27001: Direct experience preparing evidence and maintaining controls for ISO 27001 audits.
- Risk Management: Ability to perform internal risk assessments and draft security policies.
Core behaviour attributes:
- Autonomy: have proven ability to work effectively independently within a department
- Pragmatism: able to balance tight security controls with the speed of business operations
- Communication: have communication skills to translate technical risks to non-technical stakeholders
- Preferred Certifications (At least one is a major plus)
- Cloud: Google Cloud Professional Cloud Security Engineer
- Offensive: OSCP, CompTIA PenTest+, or Certified Ethical Hacker (CEH)
- Compliance/Management: ISO 27001 Lead Implementer, CISSP, or CompTIA CASP+

