Tech
Jakarta, Indonesia
Stockbit / Bibit is looking for a Core Security Engineer to strengthen our security capabilities across application development and software delivery processes. You will work closely with Engineering and Infrastructure teams to embed security into the development lifecycle, automate security controls, and ensure our systems are secure by design.
CI/CD Security
Implement and manage security controls across CI/CD pipelines, including code scanning, dependency scanning, secrets detection, vulnerability scanning, and other automated security checks.
Software Supply Chain Security
Strengthen the security of software dependencies, build processes, artifacts, and release workflows to reduce software supply chain risks.
Infrastructure as Code Security
Implement security controls and best practices across Infrastructure as Code (IaC), ensuring infrastructure provisioning and configuration are secure and compliant with security standards.
Container Security
Manage container security controls, including container image scanning, vulnerability management, and security standards for containerized workloads.
Security Findings & Vulnerability Management
Manage security findings generated through automated security tools, prioritize risks, and work closely with Engineering teams to drive remediation and track vulnerabilities through resolution.
Security Automation & Continuous Improvement
Identify opportunities to automate security processes and continuously improve security tooling, controls, and practices across the software development lifecycle.
Security Architecture
Conduct security architecture reviews and provide security design guidance for new initiatives, ensuring security requirements are incorporated from the beginning.
3+ years of experience in DevSecOps, Cloud Security, or a related field.
Strong understanding of secure software development lifecycle (SSDLC) and DevSecOps practices.
Hands-on experience implementing security controls within CI/CD pipelines using GitLab CI/CD.
Familiarity with SAST, DAST, SCA/dependency scanning, secrets detection, and vulnerability management tools.
Experience with Docker/container security and container image scanning.
Experience securing Infrastructure as Code (IaC) such as Terraform or similar technologies.
Good understanding of software supply chain security, including dependency, artifact, and build security.
Understanding OWASP Devsecops Maturity Model (DSOMM).
Strong analytical and problem-solving skills, with the ability to work collaboratively with Engineering and Infrastructure teams.
Comfortable working in a fast-paced environment and able to balance security, engineering velocity, and business requirements.
Experience with Kubernetes security and cloud security.
Experience with AWS/GCP security services and cloud security best practices.
Familiarity with tools such as Snyk, Semgrep, Trivy or similar security tooling.
Experience with threat modeling and security architecture frameworks.
Experience building or maintaining security automation using scripting or programming languages such as Python or Go.
Relevant security certifications such as CDP, CSSLP, Security+, or equivalent are a plus.
Share This Job