Deskripsi pekerjaan
Program magang 6 bulan di Zentara Technologies untuk memperkuat kapasitas lini pertama Managed SOC 24/7. Peserta magang akan menangani antrean peringatan (alert queue) di dalam SIEM, menerapkan runbook, mencatat keputusan dalam tiket, dan melakukan eskalasi ke L2 di bawah bimbingan mentor. Program ini bertujuan melatih analis dalam prosedur keamanan siber standar industri.
Tanggung jawab: Monitor the SIEM alert queue and acknowledge each alert inside the response window for its severity; Triage alerts and classify each as true positive, false positive, or benign. Record the evidence behind every verdict; Enrich indicators such as IP addresses, domains, URLs, and file hashes using approved threat intelligence sources and SIEM context; Escalate confirmed and unresolved incidents to L2 through the defined escalation path. Each escalation carries a complete ticket; Analyze phishing emails reported by client users and return a documented verdict; Check log source health in SIEM and report sources that stop sending events; Keep each ticket current with a timeline, evidence, and actions taken; Write a handover note at every shift change so the incoming analyst starts with full context; Collect and verify data used in the monthly client reports, which run on an executive track and a technical track; Report runbook gaps and unclear detection logic to the SOC Lead with a proposed fix; Handle client data under Zentara's ISO 27001 information security policies.
Kualifikasi: Final-year student or graduate within the last 12 months in Computer Science, Information Technology, Information Systems, Cybersecurity, or a related field; Working knowledge of TCP/IP, DNS, HTTP and HTTPS, and common service ports; Ability to read Windows Event Logs and Linux authentication and syslog entries; Understanding of common attack types: phishing, brute force, malware execution, command and control, and lateral movement; Awareness of the MITRE ATT&CK tactics and how an alert maps to them; Fluent Bahasa Indonesia and professional English. Tickets and handover notes are written in clear, short sentences; Availability for the full 6 months, onsite, on a rotating 24/7 shift roster; CompTIA Security+, CEH, ISC2 Certified in Cybersecurity, or Cisco CyberOps Associate; Hands-on SIEM exposure through coursework or a home lab, such as Wazuh, Elastic, or Splunk; Public lab or CTF activity on platforms such as TryHackMe or Hack The Box, with a profile link; Basic scripting in Python or PowerShell for log parsing; Familiarity with ISO 27001, NIST CSF, or PCI DSS control language.
Tanggung jawab
- Monitor the SIEM alert queue and acknowledge each alert inside the response window for its severity
- Triage alerts and classify each as true positive, false positive, or benign. Record the evidence behind every verdict
- Enrich indicators such as IP addresses, domains, URLs, and file hashes using approved threat intelligence sources and SIEM context
- Escalate confirmed and unresolved incidents to L2 through the defined escalation path. Each escalation carries a complete ticket
- Analyze phishing emails reported by client users and return a documented verdict
- Check log source health in SIEM and report sources that stop sending events
- Keep each ticket current with a timeline, evidence, and actions taken
- Write a handover note at every shift change so the incoming analyst starts with full context
- Collect and verify data used in the monthly client reports, which run on an executive track and a technical track
- Report runbook gaps and unclear detection logic to the SOC Lead with a proposed fix
- Handle client data under Zentara's ISO 27001 information security policies
Kualifikasi
- Final-year student or graduate within the last 12 months in Computer Science, Information Technology, Information Systems, Cybersecurity, or a related field
- Working knowledge of TCP/IP, DNS, HTTP and HTTPS, and common service ports
- Ability to read Windows Event Logs and Linux authentication and syslog entries
- Understanding of common attack types: phishing, brute force, malware execution, command and control, and lateral movement
- Awareness of the MITRE ATT&CK tactics and how an alert maps to them
- Fluent Bahasa Indonesia and professional English. Tickets and handover notes are written in clear, short sentences
- Availability for the full 6 months, onsite, on a rotating 24/7 shift roster
- CompTIA Security+, CEH, ISC2 Certified in Cybersecurity, or Cisco CyberOps Associate
- Hands-on SIEM exposure through coursework or a home lab, such as Wazuh, Elastic, or Splunk
- Public lab or CTF activity on platforms such as TryHackMe or Hack The Box, with a profile link
- Basic scripting in Python or PowerShell for log parsing
- Familiarity with ISO 27001, NIST CSF, or PCI DSS control language
Informasi lowongan
- Tipe pekerjaan
- Contract
- Pendidikan
- S1
- Gaji
- Negosiasi