Manager, Defensive Security Operation

bank saqu

Indonesia

On-site

IDR 2,500,000,000 - 4,500,000,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

bank saqu is seeking an experienced Senior Cybersecurity Leader to head Defensive Operations. You will oversee SOC analysts, incident responders, hunters, and security engineers, ensuring continuous monitoring of networks, endpoints, and cloud environments.

Your role includes developing detection use cases and driving incident response across the organization. You will guide threat hunting, integrate threat intelligence into processes, and design secure architectures to support defensive

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, or a related field.
  • Minimum 7 years in cybersecurity, with at least 3 years in a managerial SOC/defensive ops role.
  • Strong knowledge of SIEM, SOAR, EDR, IDS/IPS, NDR, firewalls, and DLP.
  • Well-versed in incident response lifecycle and threat hunting.
  • Familiar with MITRE ATT&CK, Cyber Kill Chain, and NIST IR.
  • Relevant certifications (CISSP, GCIA, GCIH, GMON, CCISO) preferred.

Responsibilities

  • Lead the Defensive Operations team, including SOC Analysts, Incident Responders, Threat Hunters, and Security Engineers.
  • Manage 24/7 security monitoring across networks, endpoints, applications, cloud environments, and critical infrastructure.
  • Develop and optimize detection use cases within SIEM, EDR, IDS/IPS, WAF, DLP, and other security solutions.
  • Oversee incident response activities from detection and analysis through containment, eradication, and recovery.
  • Conduct proactive threat hunting to identify suspicious activities before incidents develop.
  • Manage integration of threat intelligence into detection and response processes.
  • Design, develop, and implement security architectures across network, endpoint, cloud, IAM, PAM, encryption, and related technologies.
  • Manage log source integration, use case development, and automation through SOAR.
  • Prepare incident reports, threat trend analyses, and defensive control reports for management and regulators.
  • Develop playbooks, SOPs, and automation to accelerate SOC and incident response processes.
  • Build and enhance team capabilities through training and tabletop exercises.

Skills

Cybersecurity
SOC management
Threat hunting
Incident response
Security engineering

Education

Bachelor's degree in Computer Science / Information Systems

Tools

SIEM
SOAR
EDR
IDS/IPS
NDR
Firewalls
DLP

Job description

  • You're a go-getter with mad juggling skills (or multiple hats) who can thrive in a fast-paced, agile environment
  • You enjoy doing purpose-led and meaningful work
  • You have a strong thirst for knowledge and are driven to find solutions that don't exist yet
  • You are comfortable with ambiguity and extremely resourceful (in your past life, you could've been a detective)
  • You always find a way to get things done without sacrificing the quality of your work, integrity, and values
  • No task is off limits for you
  • You are humble and prioritize the success of the team over your own with an eagerness to help those around you
  • You don't shy away from challenges and can bounce back from setbacks
  • We strongly encourage individuals with disabilities to apply. We believe in equal opportunity and strive to create an inclusive workplace where everyone can thrive.

What you'll do and what success looks like in this role:

  • Lead the Defensive Operations team, including SOC Analysts, Incident Responders, Threat Hunters, and Security Engineers.
  • Manage 24/7 security monitoring across networks, endpoints, applications, cloud environments, and critical infrastructure.
  • Develop and optimize detection use cases within SIEM, EDR, IDS/IPS, WAF, DLP, and other security solutions.
  • Oversee incident response activities from detection and analysis through containment, eradication, and recovery.
  • Conduct proactive threat hunting to identify suspicious activities before they develop into security incidents.
  • Manage the integration of threat intelligence into detection and response processes.
  • Design, develop, and implement security architectures and engineering solutions, including network security, endpoint security, cloud security, application security, IAM, PAM, encryption, and related technologies to support defensive operations.
  • Manage log source integration, use case development, and automation through SOAR to improve SOC efficiency.
  • Prepare incident reports, threat trend analyses, threat hunting findings, and defensive control effectiveness reports for management and regulatory authorities (such as OJK and BI).
  • Develop playbooks, SOPs, and automation initiatives to accelerate and standardize SOC and incident response processes.
  • Build and enhance team capabilities through technical training programs and tabletop exercises.

What Is Required and What We're Looking For

  • Bachelor's degree in Computer Science, Information Systems, or a related field.
  • Minimum 7 years of experience in cybersecurity, including at least 3 years in a managerial role within a SOC or defensive operations environment.
  • Strong knowledge of security technologies, including SIEM, SOAR, EDR, IDS/IPS, NDR, firewalls, and DLP.
  • In-depth understanding of the incident response lifecycle and threat hunting methodologies.
  • Familiarity with frameworks such as MITRE ATT&CK, Cyber Kill Chain, and NIST Incident Response.
  • Relevant certifications such as CISSP, GCIA, GCIH, GMON, CCISO, or equivalent are highly preferred.
  • Strong analytical capabilities and effective communication skills for incident escalation and stakeholder engagement.
  • Knowledge of security regulations issued by OJK, BI, and international standards such as ISO 27001 and PCI DSS.
  • Ability to develop and implement a balanced defensive security strategy across technology, processes, and people.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operation Departement Head
Security Operation Departement Head

Techconnect • Jakarta Pusat

On-site
IDR 360,000,000 - 540,000,000
TC - SOC Cybersecurity Consultant Manager
TC - SOC Cybersecurity Consultant Manager

Ernst & Young Advisory Services Sdn Bhd • Daerah Khusus Ibukota Jakarta

On-site
IDR 1,005,361,000 - 1,508,043,000
Security Operation Departement Head
Security Operation Departement Head

Techconnect.id • Jakarta Pusat

On-site
IDR 300,000,000 - 540,000,000
TC - SOC Cybersecurity Consultant Manager
TC - SOC Cybersecurity Consultant Manager

EY • Daerah Khusus Ibukota Jakarta

On-site
SOC L2 Analyst - Cybersecurity Technology Consulting
SOC L2 Analyst - Cybersecurity Technology Consulting

Ernst & Young Advisory Services Sdn Bhd • Daerah Khusus Ibukota Jakarta

On-site
IDR 180,000,000 - 240,000,000
Head of IT Security
Head of IT Security

Pengiklan Anonim • Tangerang

On-site
IDR 400,000,000 - 800,000,000
SOC L1 Analyst - Cybersecurity Technology Consulting
SOC L1 Analyst - Cybersecurity Technology Consulting

Ernst & Young Advisory Services Sdn Bhd • Daerah Khusus Ibukota Jakarta

On-site
IDR 12,000,000 - 15,000,000
SOC L1 Analyst
SOC L1 Analyst

PT Duta Firza • Jakarta Utara

On-site
IDR 72,000,000 - 120,000,000
SOC Cyber Defense & Incident Response Analyst
SOC Cyber Defense & Incident Response Analyst

PT. Meratus Line & Group • Kebayoran Baru

On-site
IDR 167,400,000 - 312,480,000
Offensive Security Manager
Offensive Security Manager

INDODAX - Indonesia Digital Asset Exchange • Jakarta Pusat

On-site
IDR 900,000,000 - 1,500,000,000