Skill diminta
AWSAccurateKubernetesLinuxPython
Deskripsi
Job Description
The SDET - 1 (Security) at Halodoc is responsible for designing, implementing, and continuously improving security controls across Halodoc's AWS cloud infrastructure, Kubernetes (EKS) environments, applications, databases, endpoints, and enterprise systems. As a healthcare technology company handling highly sensitive patient information, prescriptions, and consultation data, protecting confidentiality, integrity, and availability is a top priority.
This role focuses on strengthening Halodoc's security posture through threat detection engineering, security monitoring, incident response, cloud security, vulnerability management, and security automation. The engineer collaborates closely with Security Operations, DevOps, Platform Engineering, Infrastructure, and Application teams to detect threats, respond to incidents, improve visibility, and implement proactive security controls.
- Key Responsibilities
- Support daily security operations across AWS cloud infrastructure, Kubernetes (EKS), applications, databases, endpoints, and network environments.
- Monitor and investigate security alerts generated by OpenSearch/ELK, AWS GuardDuty, Security Hub, CloudTrail, endpoint protection platforms, and other security tools.
- Perform initial investigation and validation of security events, determine potential impact, and escalate incidents when necessary.
- Assist in implementing and maintaining security controls across AWS services, Kubernetes clusters, IAM, S3, and cloud workloads.
- Support vulnerability management activities, including validating findings, coordinating remediation with engineering teams, and tracking remediation progress.
- Assist in maintaining security dashboards, detection rules, and monitoring configurations under the guidance of senior security engineers.
- Perform routine security reviews, including IAM permissions, cloud configurations, security group rules, S3 bucket permissions, and compliance checks.
- Support incident response activities by collecting logs, preserving evidence, documenting findings, and assisting with remediation efforts.
- Maintain accurate documentation, runbooks, standard operating procedures, and incident records in Jira or other ticketing platforms.
- Work closely with DevOps, Platform Engineering, Infrastructure, and Application teams to support secure cloud deployments and operational improvements.
- Participate in on-call support and assist during security incidents when required.
- Continuously learn new security technologies, cloud services, and defensive security practices.
- Knowledge and Skills Required
- Basic understanding of SIEM platforms such as OpenSearch, ELK Stack, Splunk, Microsoft Sentinel, or similar.
- Familiarity with AWS security services including GuardDuty, Security Hub, CloudTrail, AWS Config, S3, and CloudWatch.
- Understanding of Identity and Access Management (IAM), privileged access, and least privilege principles.
- Knowledge of Security Information and Event Management (SIEM) platforms such as OpenSearch, ELK, Splunk, or Microsoft Sentinel.
- Knowledge of Linux and Windows administration fundamentals.
- Understanding of networking concepts including TCP/IP, DNS, HTTP/HTTPS, firewalls, VPNs, and common network protocols.
- Familiarity with log analysis and security event investigation.
- Hands-on experience in working with AI native workloads, securing AI agents, MCP servers, and creating new AI security skills.
- Basic scripting knowledge in Python or Bash is desirable.
- Knowledge of endpoint security solutions such as CrowdStrike Falcon, Manage Engine.
- Understanding of security principles including least privilege, defense in depth, and secure configuration practices.