What You Will Do
- Embed Security into the SDLC: You will integrate and automate a suite of security tooling - including secrets management, Software Composition Analysis (SCA), Static Application Security Testing (SAST), and Infrastructure as Code (IaC) scanning into our CI/CD pipelines.
- Secure the Developer Workflow: A key focus will be securing our development platforms (GitHub/GitLab) from the ground up, implementing security best practices for repository settings, branch protections, and code access.
- Architect Security as Code: You will leverage your deep programming skills in Python, Go, JavaScript, etc., to build custom tooling, automation, integrations, and supporting documentation that help create a frictionless security experience for accelerated development.
- Act as a Security SME: With your keen ability to spot security flaws quickly, you will serve as a subject matter expert for engineering teams, guiding them on secure coding and pragmatic remediation strategies.
- Incorporating AI to enhance security: You will be a key contributor to our efforts on improving our security posture by researching and applying AI-driven solutions to enhance threat detection, automate vulnerability management, and intelligently secure our development lifecycle.
What You Will Need
- 5+ years of proven experience in a hands-on DevSecOps or Application Security role with a strong DevOps foundation.
- Solid Kubernetes experience (deployments, RBAC, basic networking, troubleshooting).
- Development skills at minimum: Python, Go, and JavaScript code.
- Practical & deep understanding of the use of SCA, SAST, secrets, and IaC scanning tools
- Strong Git skills (branching, rebasing, signed commits, access controls).
- Experience securing GitHub or GitLab (tokens, branch protections, CI secrets).
- Excellent written and verbal communication skills tailored for diverse audiences.
GoTo Group Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about GoTo Group and has not been reviewed or approved by GoTo Group.
-
Fair & Transparent Compensation — Pay is considered competitive to above market for many corporate roles across core entities such as Gojek, Tokopedia, and GoTo Financial. Base pay is often characterized as solid or above market in Indonesia tech roles.
-
Healthcare Strength — Medical coverage is characterized as strong in Indonesia and often extends to spouses and children. Company materials also highlight wellness support, parental insurance, and mental‑health counseling for employees and families.
-
Leave & Time Off Breadth — Leave programs are described as generous, including maternity, paternity, and other special leave types at Tokopedia. Broader time‑off and flexibility practices are portrayed as supportive across corporate roles.
GoTo Group Insights
Similar Jobs
What We Do
GoTo is the largest technology group in Indonesia, combining on-demand, e-commerce and financial services through the Gojek, Tokopedia and GoTo Financial brands. It is the first platform in Southeast Asia to host these three essential use cases in one ecosystem, capturing a majority of Indonesian consumer household expenditure. GoTo’s mission is to “Empower Progress” by offering an unparalleled selection of goods and services through a comprehensive merchant and partner network and promoting financial inclusion through its leading payments and financial services business.








