Skill diminta
CI/CD
Deskripsi
- Job Requirements
- Bachelor's Degree (S1)
- in Computer Science, Information Technology, Information Systems, Cybersecurity, or a related field.
- (Mandatory)
- Minimum
- 2–4 years of experience
- in Application Security, Penetration Testing, Vulnerability Assessment, or DevSecOps.
- Strong understanding of
- OWASP Top 10
- OWASP Mobile Top 10
- , and
OWASP MASVS
- Hands-on experience with security testing tools such as
- Burp Suite Professional, OWASP ZAP, SonarQube, Snyk, Checkmarx, Fortify, Nessus, Trivy
- , or equivalent.
- Strong knowledge of modern authentication and authorization technologies, including
- OAuth 2.0, OpenID Connect (OIDC), JWT, RBAC, and ABAC
- Experience performing security assessments for
- Web Applications, Mobile Applications (Android/iOS), APIs, and Microservices
- Familiar with
- CI/CD pipelines
- (GitHub Actions, GitLab CI, Jenkins, or similar) and integrating automated security testing into the software development lifecycle.
- Ability to perform secure code reviews for applications developed in
- JavaScript/TypeScript, Python, Java, Go, Kotlin, Swift
- , or similar programming languages.
- Understanding of application security best practices, secure coding principles, and vulnerability remediation processes.
- Knowledge of cryptography, secure session management, API security, and data protection mechanisms.
- Familiar with
BSSN
- cybersecurity frameworks, including
- Indeks KAMI, IKAS, and Cyber Security Maturity (CSM)
- Understanding of Indonesian cybersecurity and data protection regulations, including
UU PDP
- OJK Cybersecurity Regulations
- , and
- Bank Indonesia (BI) Cybersecurity Requirements
- Strong analytical, problem-solving, reporting, and communication skills.
- Professional certifications such as
- CEH, OSCP, OSWE, CompTIA Security+, GIAC, eJPT, GWAPT, PNPT
- , or equivalent are an advantage.
- Key Responsibilities
- Conduct
- Vulnerability Assessment and Penetration Testing (VAPT)
- for web applications, mobile applications (Android/iOS), APIs, and backend services.
- Perform application security testing based on
- OWASP Top 10, OWASP MASVS, and industry security best practices
- Identify, validate, and assess security vulnerabilities, providing risk ratings and remediation recommendations.
Evaluate application security controls, including authentication, authorization, encryption, session management, API security, and sensitive data protection.
- Perform secure code reviews to identify security weaknesses and recommend secure coding improvements.
- Integrate and optimize security testing within
- CI/CD pipelines
- to support secure software development practices.
- Validate security features and perform logical security testing to ensure applications are protected against bypasses and abuse scenarios.
Collaborate closely with Development, QA, and Infrastructure teams to resolve identified vulnerabilities and improve application security posture.
Conduct security re-testing to verify the effectiveness of remediation efforts.
Prepare comprehensive security assessment reports, including executive summaries, technical findings, risk classifications, remediation status, and final recommendations.
- Provide security sign-off and recommendations prior to application deployment or production release.
- Ensure applications comply with organizational security policies,
- BSSN security frameworks
- , and applicable regulations such as
- UU PDP, OJK, and Bank Indonesia
Monitor emerging cybersecurity threats, vulnerabilities, and security best practices to continuously improve the organization's application security posture.