Skill diminta
Communication
Deskripsi
- Oversee compliance with international security standards (ISO 27001, NIST, OWASP, SOC 2, GDPR, etc.).
- Develop, implement, and enforce information security policies, standards, and incident response frameworks.
- Monitor emerging threats and industry trends to inform risk-based decisions and strengthen overall defenses.
- Manage security-related budgets, tools, vendors, and resource allocation.
- Oversee and ensure the effectiveness of the organization’s penetration testing, vulnerability management, and incident response programs.
Lead the planning, execution, and reporting of complex penetration tests across web, mobile, infrastructure, and cloud environments (both internal and client systems).
- Validate and prioritize vulnerabilities identified by Red Team activities and coordinate Blue Team responses to mitigate risks.
- Supervise the development and continuous improvement of the company’s cybersecurity testing frameworks, tools, and methodologies.
- Review and approve technical reports and ensure recommendations are actionable, risk-based, and aligned with business priorities.
- Evaluate and select security technologies and solutions that enhance detection, prevention, and response capabilities.
Ensure integration of security best practices across the software development lifecycle (DevSecOps)Lead, coach, and develop a team of cybersecurity professionals (Red & Blue Teams), providing technical direction, feedback, and career guidanceSet performance objectives, monitor outcomes, and foster a culture of accountability, innovation, and continuous improvement
- Drive security awareness and preparedness across the organization through training, simulations, and collaboration.
- Coordinate closely with President Director, Head of IT Ops, and Management level positions regarding projects, business, and resources.
- Collaborate with HR to address resource issues and allocations. This includes the task of Identifying underperformers.
- Collaborate with DAnS Academy to determine training gaps and needs.
- Monitor and report IT Security team activities, performance metrics, and incident trends to internal and external stakeholders regularly.
- Bachelor Degree in Computer Science / Information Technology / Cybersecurity or related major from reputable university
- At least 4 years of experience of IT Security
- Have experience in Red and Blue team
- Excellent teamworking and communication skills
- IT Security Certification (CEH, CHFI, CAP, OSCP, etc) will be a plus