Deskripsi pekerjaan
Transcosmos Indonesia , a joint venture between Transcosmos Inc. and CBN (a member of the Salim Group), is a Global Digital Transformation Partner in Customer Experience Solutions and Digital Marketing Solutions. Our goal is to foster a culture of excellence while shaping a thriving company. We provide a competitive compensation package and ample opportunities for career growth. We believe in giving every employee a fair chance to contribute to our success and to unlock their full potential. We are hiring IT Operations & Security Supervisor - Semarang Site, read more
Tanggung jawab: Lead the transformation of the NOC into a Security Network Operations Center (SNOC) by unifying network, infrastructure, and security monitoring into an operational view, standardized playbooks, and escalation workflows, eliminating siloed incident manage; Oversee 24/7 operational continuity for both internal and client-facing services, including shift handover design, on-call rotation, and escalation matrix management to ensure MTTD and MTTR targets are achieved in accordance with agreed SLA/OLA; Design and lead the implementation of security gates within the CI/CD pipeline, including SAST, DAST, dependency scanning, and container security scanning; Lead threat modeling and risk assessment initiatives for both new and existing systems, including integration with GLPI, Wazuh, and FortiGate environments; Drive automation and multi-tool/multi-platform integration across internal and client environments (e.g., SIEM, ITSM, monitoring solutions, firewalls, and endpoint security) through APIs, webhooks, and SOAR/low-code orchestration to reduce operational ove; Develop and implement compliance-as-code automation to support ISO 27001 audit readiness and certification processes; Ensure compliance with ISO 27001 (Information Security Management System) and ISO 9001 (Quality Management System), including audit evidence preparation, non-conformance remediation, and continuous maintenance of control documentation and Standard Operati; Manage the end-to-end vulnerability management lifecycle, including identification, prioritization, remediation, and validation of security vulnerabilities; Provide technical mentorship to L2 Engineers and lead capability development initiatives for L1/L2 NOC teams to achieve a mature SNOC operating model; Evaluate, recommend, and implement emerging technologies and tools such as secrets management, policy-as-code, AIOps, anomaly detection, and other security and operational automation solutions; Lead incident response activities for both security and operational incidents across internal and client environments, including root cause analysis, post-incident reviews, and post-mortem documentation; Minimum 5 years of experience in Security Engineering, DevOps, or NOC/SOC environments, with at least 2 years in a role combining 24/7 operations and security engineering; Proven experience in designing or operating a converged NOC/SOC (SNOC) model, including unified alerting, event correlation, and single-pane-of-glass monitoring. Familiarity with modern SIEM/XDR platforms such as Wazuh, Splunk, Elastic Security, or Micros; Hands-on experience with CI/CD platforms such as Jenkins, GitLab CI, or GitHub Actions , with the ability to design and implement pipelines from scratch; Strong experience with Infrastructure as Code (IaC) using Terraform or Ansible , including security posture assessment and auditing; Solid knowledge of container security using Docker and Kubernetes , with experience in image scanning tools such as Trivy, Aqua Security, or Clair; Experience securing at least one major cloud platform (AWS, Azure, or GCP) , including IAM hardening and native cloud security services; Strong experience in automation and orchestration , including integrating multi-vendor tools across internal and client environments using REST APIs, webhooks, SOAR platforms (e.g., Shuffle, Tines, Splunk SOAR) , or low-code orchestration tools such as n8; Familiarity with AIOps and modern observability platforms such as Zabbix, Prometheus/Grafana, Elastic , or equivalent solutions, including ML-based anomaly detection to support proactive monitoring and self-healing operations; Hands-on experience with vulnerability management and application security testing tools such as SonarQube, Checkmarx, or OWASP ZAP; Proficiency in Python or Go for developing automation scripts and custom operational tooling; Strong understanding of ISO 27001 and NIST frameworks, with the ability to translate compliance requirements into technical controls and audit evidence; Basic knowledge of ISO 9001 Quality Management System (QMS) , including process documentation, Corrective and Preventive Actions (CAPA), and continuous compliance practices; Proven experience managing 24/7 operations , including shift scheduling, handovers, on-call rotations, SLA/OLA management, and multi-level escalation processes; Demonstrated leadership experience in leading or mentoring engineering teams, with excellent communication and stakeholder management skills across cross-functional teams and client environments. Note: Only shortlisted candidate will be invited to Intervi.
Tanggung jawab
- Lead the transformation of the NOC into a Security Network Operations Center (SNOC) by unifying network, infrastructure, and security monitoring into an operational view, standardized playbooks, and escalation workflows, eliminating siloed incident manage
- Oversee 24/7 operational continuity for both internal and client-facing services, including shift handover design, on-call rotation, and escalation matrix management to ensure MTTD and MTTR targets are achieved in accordance with agreed SLA/OLA
- Design and lead the implementation of security gates within the CI/CD pipeline, including SAST, DAST, dependency scanning, and container security scanning
- Lead threat modeling and risk assessment initiatives for both new and existing systems, including integration with GLPI, Wazuh, and FortiGate environments
- Drive automation and multi-tool/multi-platform integration across internal and client environments (e.g., SIEM, ITSM, monitoring solutions, firewalls, and endpoint security) through APIs, webhooks, and SOAR/low-code orchestration to reduce operational ove
- Develop and implement compliance-as-code automation to support ISO 27001 audit readiness and certification processes
- Ensure compliance with ISO 27001 (Information Security Management System) and ISO 9001 (Quality Management System), including audit evidence preparation, non-conformance remediation, and continuous maintenance of control documentation and Standard Operati
- Manage the end-to-end vulnerability management lifecycle, including identification, prioritization, remediation, and validation of security vulnerabilities
- Provide technical mentorship to L2 Engineers and lead capability development initiatives for L1/L2 NOC teams to achieve a mature SNOC operating model
- Evaluate, recommend, and implement emerging technologies and tools such as secrets management, policy-as-code, AIOps, anomaly detection, and other security and operational automation solutions
- Lead incident response activities for both security and operational incidents across internal and client environments, including root cause analysis, post-incident reviews, and post-mortem documentation
- Minimum 5 years of experience in Security Engineering, DevOps, or NOC/SOC environments, with at least 2 years in a role combining 24/7 operations and security engineering
- Proven experience in designing or operating a converged NOC/SOC (SNOC) model, including unified alerting, event correlation, and single-pane-of-glass monitoring. Familiarity with modern SIEM/XDR platforms such as Wazuh, Splunk, Elastic Security, or Micros
- Hands-on experience with CI/CD platforms such as Jenkins, GitLab CI, or GitHub Actions , with the ability to design and implement pipelines from scratch
- Strong experience with Infrastructure as Code (IaC) using Terraform or Ansible , including security posture assessment and auditing
- Solid knowledge of container security using Docker and Kubernetes , with experience in image scanning tools such as Trivy, Aqua Security, or Clair
- Experience securing at least one major cloud platform (AWS, Azure, or GCP) , including IAM hardening and native cloud security services
- Strong experience in automation and orchestration , including integrating multi-vendor tools across internal and client environments using REST APIs, webhooks, SOAR platforms (e.g., Shuffle, Tines, Splunk SOAR) , or low-code orchestration tools such as n8
- Familiarity with AIOps and modern observability platforms such as Zabbix, Prometheus/Grafana, Elastic , or equivalent solutions, including ML-based anomaly detection to support proactive monitoring and self-healing operations
- Hands-on experience with vulnerability management and application security testing tools such as SonarQube, Checkmarx, or OWASP ZAP
- Proficiency in Python or Go for developing automation scripts and custom operational tooling
- Strong understanding of ISO 27001 and NIST frameworks, with the ability to translate compliance requirements into technical controls and audit evidence
- Basic knowledge of ISO 9001 Quality Management System (QMS) , including process documentation, Corrective and Preventive Actions (CAPA), and continuous compliance practices
- Proven experience managing 24/7 operations , including shift scheduling, handovers, on-call rotations, SLA/OLA management, and multi-level escalation processes
- Demonstrated leadership experience in leading or mentoring engineering teams, with excellent communication and stakeholder management skills across cross-functional teams and client environments. Note: Only shortlisted candidate will be invited to Intervi
Informasi lowongan
- Tipe pekerjaan
- Full-time
- Gaji
- Rp 8.000.000 – Rp 9.000.000 per month