Perusahaan

TravelokaLihat lainnya

addressAlamatJakarta
KategoriIT / Komputer

Uraian Tugas

It's fun to work in a company where people truly BELIEVE in what they're doing!

‎ 

‎ 

Job Description

Product Security Engineer at Traveloka will be required to ensure that our products and services are shipped with high security standards through application security testing, hardening, and secure framework. A Product Security Engineer will be smart and self starter. The person needs to find unique ways to understand complex software architecture and should be able to perform manual security code review. They need to be able to integrate security in the software development process with defense-in-depth strategies such as automated testing in CI/CD pipeline. A Product Security Engineer preferably needs to have a software development background and should have practical programming knowledge.

They will work very closely with our Software Engineering Team to implement Secure SDLC in Traveloka. They will also need to have proficiency in handling multiple projects based on different frameworks and groups.

‎ 

Requirements

Responsibilities

  • Carry out manual and automated review of source code to identify security vulnerabilities and risks

  • Implement automated security testing tools (SAST, DAST, IAST) and their deployment within continuous integration systems

  • Implement hardening and secure framework such as RASP, WAF, safe library, and security decorator functions

  • Perform vulnerability assessment & penetration testing on web API, front-end service, internal RPC, and mobile application

  • Attend design reviews and actively lead the discussions from a security standpoint

  • Analyze possible security incident related to application security such as payment abuse or sensitive data exposure via web API

  • Ensure that product security requirements are identified early on and are being baked into all projects

  • Provide effective recommendations or patches to mitigate security vulnerabilities 

  • Develop in-house tools to integrate with SDLC and to track and derive security metrics

Qualifications

Skills & Experience

  • Academic background in Computer Science or equivalent

  • Relevant professional experience or extensive experience in security activities (e.g. CTF, bug bounty, security research, publications, blog)

  • Practical knowledge of modern software development such as microservices, application containerization, REST architecture, object oriented programming, stateless/stateful authentication, and cloud platform

  • Working knowledge of one or more of these programming languages: Java, JavaScript, Kotlin, C#, Objective-C, Swift

  • Experience in security code review, vulnerability assessment, and penetration testing.

  • Knowledge of common vulnerabilities such as OWASP Top 10 and CWE including business logic issue (e.g. IDOR)

  • Core skill set in two or more of the following areas:

    • JavaScript framework (e.g. React)

    • Java framework (e.g. Spring)

    • Android / iOS platform

    • DevOps

    • AWS

    • Automation tool development

    • Dynamic debugging

    • Unit testing

    • Algorithm & data structure

‎ 

If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!

Refer code: 716210. Traveloka - Hari sebelumnya - 2024-04-01 17:56

Traveloka

Jakarta

Bagikan pekerjaan dengan teman

Pekerjaan terkait

Security Engineer

Security Engineer  

Healthblocks Inc.

Quezon City, Philippines

2 minggu lalu - dilihat

IT Cyber Security Engineer  

Quantyc.ai

Jakarta Selatan, DKI Jakarta

2 minggu lalu - dilihat

Cyber Security Engineer Analyst  

Astra Financial

Central Jakarta City, Indonesia

2 minggu lalu - dilihat

Security Engineer - GRC

Xtremax Pte Ltd

Bandung, Jawa Barat

2 minggu lalu - dilihat

Information Technology Security Engineer

Pt Mitra Solusi Telematika

Indonesia

4 minggu lalu - dilihat

Information Technology Security Engineer

Page Outsourcing

Simpang, Ogan Komering Ulu Selatan, Sumatera Selatan

4 minggu lalu - dilihat

Product Security Engineer

Mekari

Remote

4 minggu lalu - dilihat

Senior Security Engineer

Pt. Visindo Prima Nusantara

Jakarta Barat, DKI Jakarta

4 minggu lalu - dilihat

Network and Security Engineer

Hit Digital Indonesia

Banjarbaru, Kalimantan Selatan

4 minggu lalu - dilihat

Engineer Security Operation Center & Threat Intellegence Analyst & XDR Engineer

Pt Gerbang Sinergi Prima

Jakarta

sebulan yang lalu - dilihat

Network Security Engineer (JLPT N1)

Jac Consulting Indonesia

Kuta, Badung, Bali

sebulan yang lalu - dilihat

Senior Network Engineer LAN (Secret Level/EU Security Clearance)

Serco Group Plc

Brussels, Belgium

sebulan yang lalu - dilihat

Cyber Security Engineer

Dynamics System Integration Solution

Jakarta

sebulan yang lalu - dilihat

IT Security Engineer

Gue Ecosystem

Pondok Aren, Tangerang Selatan, Banten

sebulan yang lalu - dilihat

Information Security Junior Engineer

Ocbc Sekuritas Indonesia

Tangerang, Banten

sebulan yang lalu - dilihat

IT Security Engineer

Phincon

Jakarta Selatan, DKI Jakarta

sebulan yang lalu - dilihat

IT Security Engineer  

Moladin

Jakarta Selatan, DKI Jakarta

sebulan yang lalu - dilihat

IT Security Engineer

Artha Telekomindo

Jakarta Selatan, DKI Jakarta

sebulan yang lalu - dilihat