It's fun to work in a company where people truly BELIEVE in what they're doing!
Job Description
The Security Engineer at Traveloka is responsible to ensure that Traveloka’s products, services, infrastructures, and business operations meet the high-security standards through control, verification, testing, design, monitoring, and implementation of technical security engineering and operation practices.
DevSecOps, an evolving practice, integrates development, security, and operations within the software development, deployment, and operational landscape. Positioned under the Information Security at Traveloka, the DevSecOps team serves as a central unit responsible for delivering security technology across all technology departments. However, DevSecOps transcends mere tool installation or the shift-left paradigm. It embodies the concept of 'shift-everywhere,' seamlessly weaving security into every stage of software and system engineering even before the development and after the deployment. Success in this role demands robust analytical, reasoning, and managerial abilities, crucial for comprehending our environment's unique requirements and crafting bespoke security solutions tailored to these needs.
Requirements
Proven track record of managing software, security, infrastructure, or DevOps engineers to work on implementation and integration of security solutions in large-scale code repositories, services, and platforms with at least 2 years of leadership experience and 3 years as individual contributor.
Experience in managing projects related to software development and DevOps with agile methodologies.
Fluent in programming with any language and shell scripting.
Experience in cloud computing like AWS and GCP.
Experience in Java, Node.js, Python, and mobile (Android/iOS) is a plus.
High technical understanding on web application security vulnerabilities, mobile application security and Linux exploitation.
Able to practically demonstrate various security tests and control implementation such as SAST, DAST, IAST, SCA, WAF, secure-by-design, secure framework, compile-time security check, and runtime application security.
Excellent written and verbal communication skills.
Possessing a self-initiative mindset to bridge the gap between Software Engineering, Infrastructure Engineering, and Security Engineering while providing a framework for the whole technology team and management to perform security assurance.
Dedication to cybersecurity alongside a strong commitment to continuous learning about new technologies.
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!