
T&T Consultant - Cloud Security - ID
- Jakarta
- Permanen
- kerja tetap
- Design, Implement, and Optimize Secure Landing Zones: Lead the creation and enhancement of secure landing zones across multiple cloud service providers (CSPs) such as AWS, Azure, and Google Cloud for clients in Southeast Asia.
- DevSecOps Pipelines: Architect and implement DevSecOps pipelines, integrating security controls into CI/CD processes to automate security and compliance testing.
- Infrastructure as Code (IaC): Design and deploy infrastructure as code using tools like Terraform, AWS CloudFormation, and Azure Resource Manager (ARM) templates to automate cloud infrastructure provisioning and enforce security configurations.
- High Availability Architectures: Implement multi-region and high availability architectures to meet performance, scalability, and disaster recovery requirements.
- Security Configurations: Configure Web Application Firewalls (WAFs), DDoS protection (e.g., AWS Shield, Azure DDoS Protection), and network firewalls (e.g., AWS Network Firewall, Azure Firewall).
- Access Control: Implement role-based access control (RBAC), least privilege principles, and multi-factor authentication (MFA) across cloud environments.
- Cloud-Native Security Expertise: Provide subject matter expertise in cloud-native security technologies, including identity and access management (IAM), encryption, security monitoring, and vulnerability management.
- Project Management and Leadership: Ensure the successful delivery of cloud security solutions through strong project management and leadership.
- Business Development: Assist in business development efforts, including proposal creation and identifying opportunities to grow cloud security service offerings.
- Client Relationships: Build and nurture positive working relationships with clients, aiming to exceed their expectations.
- Engagement Profitability: Identify opportunities to improve engagement profitability.
- Mentorship: Mentor and develop junior staff, promoting knowledge sharing and skills development within the team.
- Actively seek out developmental opportunities for growth, act as strong brand ambassadors for the firm as well as share their knowledge and experience with others.
- Understand the goals of our internal and external stakeholder to set personal priorities as well as align their teams' work to achieve the objectives.
- Constantly challenge themselves, collaborate with others to deliver on tasks and take accountability for the results.
- Build productive relationships and communicate effectively in order to positively influence teams and other stakeholders.
- Project integrity and confidence while motivating others through team collaboration as well as recognising individual strengths, differences, and contributions.
- Bachelor's degree in information security, information systems management, computer science, engineering, or other related discipline.
- 5 years of experience in cloud security implementations across multiple CSPs (AWS, Azure, GCP).
- Extensive hands-on experience in designing and implementing Security Landing Zones, cloud security architectures, and securing hybrid/multi-cloud environments.
- Relevant certifications such as AWS Certified Security - Specialty, Microsoft Certified: Azure Security Engineer, Google Cloud Professional Cloud Security Engineer, or CISSP, CCSP are highly desirable.
- Proven experience managing cloud security projects, including landing zone implementations and security automation.
- Expertise in cloud-native security controls, including IAM, key management, network security, and security monitoring tools (e.g., AWS Security Hub, Azure Security Center).
- Strong knowledge of compliance frameworks such as NIST,CSA CCM, and CIS Benchmarks and how to apply them to cloud security implementations.
- Ability to travel 25-50%, on average, based on the work you do and the clients and industries/sectors you serve
- Bachelor's degree in Computer Science, Information Security, or a related field; Master's degree preferred.
- Limited immigration sponsorship may be available.
- Excellent problem-solving skills and proven ability to lead a team of engineers.
- Ability to optimally communicate and advocate key security requirements to senior stakeholders.
- Strong critical-thinking and problem-solving skills with clear communication.