Responsibilities
- Manage cybersecurity every day
- Keep the company's computers, servers, cloud systems, networks, Microsoft 365, and employee devices secure.
- Handle security incidents
- When something suspicious happens—such as malware, phishing, a compromised account, or a data breach—you investigate what happened, contain the problem, fix it, and make sure it doesn't happen again.
- Find and fix security weaknesses
- Regularly look for vulnerabilities in systems and applications, monitor security alerts, and make sure important security risks are addressed.
- Manage security policies and compliance
- Create and maintain cybersecurity policies, standards, and procedures, and make sure the company follows them.
- Work with ISO 27001
- Help maintain the company's ISO 27001 Information Security Management System (ISMS), prepare for audits, maintain required documentation, and make sure security controls are working.
- Assess security risks
- Look at potential threats and weaknesses, decide how serious they are, and recommend ways to reduce the risk.
- Work with different teams
- You'll communicate with IT, management/business teams, auditors, and outside security vendors or partners.
- Improve security systems and processes
- Review how the company currently protects its systems and suggest better ways to design, configure, and operate them.
- Teach employees about security
- Help run cybersecurity awareness programs, such as phishing training, security briefings, and employee education.
- Guide junior security staff
- Help less-experienced security engineers develop their technical skills and handle security tasks.
Requirements
- Someone with at least 4-5 years of cybersecurity experience, preferably someone who has worked inside a company rather than mainly works for a consulting company or system integrator.
- Possess hands-on experience with:
- Microsoft 365 — securing email, Teams, SharePoint, etc.
- Entra ID — Microsoft's identity and access management system (formerly Azure AD)
- Endpoint security — protecting laptops, desktops, and other employee devices
- SIEM — collecting and analyzing security logs and alerts
- EDR — detecting and responding to threats on computers
- Security operations — monitoring and responding to security threat
- ISO 27001 — implementing controls and preparing for auditsCertifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor, or Security+ are a plus.
- Excellent communication and presentation skills.
- Strong problem-solving skills and attention to detail.
- Proficient in English and Bahasa (both written and verbal).