Deskripsi Pekerjaan
Are you a seasoned security professional looking to make a global impact? Foodpanda is seeking a highly skilled Staff Security Engineer to join our elite Security Engineering team. In this pivotal role, you will be the architectural backbone protecting our multi-brand ecosystem, spanning foodpanda, foodora, and Yemeksepeti. You will lead cross-functional initiatives to harden our infrastructure, mitigate sophisticated threats, and drive security-by-design principles across our engineering organization.
As a Staff-level contributor, you won't just react to threats; you will proactively architect robust, scalable security solutions that enable our business to innovate at speed. You will work in a fast-paced environment where your technical leadership will influence the security posture of millions of transactions daily.
Tanggung Jawab
- Architect and implement secure infrastructure solutions across cloud-native environments (AWS/GCP).
- Lead security incident response and threat hunting operations to mitigate high-level risks.
- Drive the adoption of DevSecOps practices within CI/CD pipelines to ensure automated security guardrails.
- Mentor senior and mid-level engineers to elevate the security maturity of the organization.
- Conduct deep-dive security assessments, threat modeling, and code reviews for complex microservices.
- Collaborate with global stakeholders to align security roadmaps with business objectives across foodpanda, foodora, and Yemeksepeti brands.
- Define and implement security standards, policies, and best practices to ensure compliance and data privacy.
Kualifikasi
- 10+ years of experience in Security Engineering, with at least 3 years in a senior or staff-level capacity.
- Expert-level knowledge of cloud security (AWS/GCP), container security (Kubernetes/Docker), and API security.
- Proven experience in building and managing security operations in a high-traffic, large-scale consumer platform.
- Strong programming proficiency in languages such as Python, Go, or Java for automation and security tool development.
- Deep understanding of web application vulnerabilities (OWASP Top 10) and mitigation strategies.
- Strong problem-solving skills with the ability to communicate complex security concepts to technical and non-technical stakeholders.
- Relevant industry certifications (e.g., CISSP, OSCP, AWS Certified Security) are highly preferred.