Deskripsi pekerjaan Senior IT GRC Consultant (VAPT) Robere & Associates (indonesia)
Key Responsibilities :
- Deliver consulting services related to Vulnerability Assessment & Penetration Testing (VAPT), Information Security, and Cybersecurity Governance.
- Perform or support vulnerability assessments and penetration testing activities for web applications, mobile applications, APIs, networks, and IT infrastructure.
- Analyse security vulnerabilities, assess risks, and provide practical remediation recommendations based on industry best practices.
- Prepare clear and comprehensive technical reports and executive summaries of assessment findings.
- Collaborate with clients to explain security findings, mitigation strategies, and remediation plans.
- Assist clients in strengthening their security posture through security assessments, gap analyses, and compliance reviews.
- Support security awareness sessions, technical workshops, or client consultations related to cybersecurity and information security.
- Work closely with Project Managers and clients to ensure project deliverables are completed on time and meet quality standards.
- Stay up to date with emerging cybersecurity threats, attack techniques, vulnerabilities, and security technologies.
- Contribute to the continuous improvement of VAPT methodologies, templates, and internal knowledge sharing.
Requirements :
- Bachelor's degree from a reputable university with a minimum GPA of 3.00, preferably in Information Technology, Computer Science, Cyber Security, or other related disciplines.
- Minimum 3–5 years of experience in Information Security, Vulnerability Assessment & Penetration Testing (VAPT), IT Security, or IT GRC.
- Good understanding of Information Security principles, IT Governance, Risk Management, and Cybersecurity best practices.
- Familiarity with security frameworks and standards such as ISO/IEC 27001, NIST Cybersecurity Framework, OWASP Top 10, COBIT, and MITRE ATT&CK is preferred.
- Hands-on experience in conducting or supporting VAPT activities for web applications, mobile applications, APIs, networks, or infrastructure.
- Familiarity with security assessment tools such as Nessus, Burp Suite, Nmap, Metasploit, Acunetix, OWASP ZAP, or similar tools is an advantage.
- Understanding of secure coding concepts, common security vulnerabilities, and remediation recommendations is preferred.
- Strong analytical, troubleshooting, and problem-solving skills.
- Excellent communication and presentation skills with the ability to explain technical findings to both technical and non-technical stakeholders.
- Detail-oriented, eager to learn, and able to work independently as well as collaboratively in a fast-paced consulting environment.




