Get more replies from employers
Send a job-specific resume in minutes.
Pengiklan Anonim is seeking a Head of IT Security to own and strengthen security for production servers and office workstations. This hands-on leadership role emphasizes preventing incidents, enforcing best practices, and governing changes across the tech stack.
The ideal candidate has 8+ years in information security, with 3+ years leading a security team in fintech or regulated industries, and hands-on expertise in infrastructure and application security, SIEM/EDR, and secure SDLC.
Head of IT Security to own and strengthen the security of all technology assets — production server farm and office workstation environments. This is a hands-on leadership role with a strong mandate: prevent incidents before they occur, enforce security best practices, and serve as the go/no-go gate over every risky change request. As a payment company, the systems you protect handle sensitive financial data and regulated services.
Key responsibilities:
Gate go/no-go: assess and approve/reject risky changes; authority to block unsafe releases until remediated
Infrastructure and perimeter security: hardening server (Linux/Windows), network segmentation, egress control (default-deny), firewall/WAF/IDS-IPS, secret management, backup security
Workstation security: EDR, patch management, disk encryption, least-privilege, email/web filtering
Secure coding and SDLC: OWASP standards, security gates in CI/CD (SAST/DAST/SCA), threat modeling, developer training
Audit and penetration testing: lead team conducting regular audits and pentests on applications and infrastructure; manage external pentest vendors
Monitoring, detection and incident response: centralized SIEM/logging, proactive threat hunting, lead incident handling
Compliance: align controls with ISO 27001, PCI-DSS, OJK/Bank Indonesia, and UU PDP with Compliance and Legal teams
Team leadership: lead, mentor, and develop the IT Security team; set standards and work priorities
Requirements:
Minimum 8 years in information security/IT, including 3+ years leading a security team or function (preferred: fintech, payments, banking, or regulated industry)
Comprehensive experience in both infrastructure and application security, and remain hands-on technically
Track record of enforcing security governance and change control; experience leading incident response
Understanding of Indonesian financial sector regulations (OJK, Bank Indonesia), UU PDP, ISO 27001, and PCI-DSS
Proficiency in: Linux/Windows hardening, networking and segmentation, WAF/IDS-IPS, SIEM/EDR, IAM/PAM, secret management, secure SDLC (OWASP), and penetration testing
Certifications (value-add): CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor/Implementer, OSCP/GPEN/GCIH/CEH. Cloud certifications optional (GCP)
Bachelor's or Master's degree in related field or equivalent experience
Firm and principled — able to say no when risk demands it and stand by it, high integrity, proactive and always current with latest security threats, communicative with management and technical teams