Yes. You can hire a full-time security engineer, SOC analyst, application security engineer or cloud security engineer in Indonesia on a compliant permanent contract without a local entity, through an Employer of Record (EOR). MixWork recruits the engineer, employs them on a PKWTT permanent contract and runs payroll and statutory contributions, while they work only for you.
Security is the one hire where the access you grant is the risk you are hiring to reduce. A security engineer will see your logs, your open vulnerabilities, how your secrets are stored and the history of everything that has gone wrong. So the way you hire them should look like the controls you want them to run: verified before they are trusted, privileged in stages, working from a managed device, and logged like everyone else. One honest limit belongs up front too. A single in-house hire is not a 24/7 security operations centre, and if round-the-clock monitoring is what you need, buy a managed security service. MixWork does not provide one.
Make the hiring process model the controls
A good test of readiness is whether you would be comfortable with the way you hired and onboarded your security engineer appearing in your next audit.
Control | What it means for this hire | When |
|---|---|---|
Background and reference checks | Employment verification, and references from previous managers on the specific security work and incidents the candidate claims | Before the offer is final |
Staged privilege | Read access to logs and security tooling first, then write access to detection rules and configuration, then administrative rights over identity and security platforms as judgment is shown | Across the first quarter |
Managed device | Security work happens only on a managed, encrypted, centrally patched device, never a personal laptop | From day one |
Logging of the security team’s own access | Privileged sessions and changes made by the security engineer are logged to a store they can read but cannot alter, and reviewed by someone outside security | From day one |
Separation of duties | High-impact actions, such as disabling an alert rule or granting an administrator role, need a second approver | From day one |
Offboarding plan | A written list of which credentials, keys and tokens rotate if the engineer leaves | Before day one |
The logging row is the one smaller companies skip, usually because nobody else is technical enough to read the logs. That is a solvable problem. A monthly summary of privileged actions reviewed by the CTO or a founder makes the control real. What matters is that the person with the most access is not the only person able to see what they did with it.
The device row matters more than it looks: a personal laptop with unknown software on it undoes the rest of the table. MixWork Managed IT supplies managed devices held in-region from USD 99 per device per month, and our guide to remote device security and MDM covers what a managed device should enforce.
Which security role do you need?
SOC analysts, security engineers, application security engineers and cloud security engineers do different work, and the first hire should match your biggest exposure.
Role | Main job | Hire this first when |
|---|---|---|
SOC analyst | Triages alerts, investigates suspicious activity, escalates and documents incidents, usually inside a shift rota | You already have a detection platform producing alerts and a team or rota for the analyst to join |
Security engineer | Builds and runs the controls: identity hardening, endpoint and email security, logging and detection, vulnerability management | Nobody owns security today and the basics need doing properly |
Application security engineer | Secures the software you write: threat modelling, secure code review, dependency and secrets scanning in the build pipeline, fixing issues with developers | Your product is your main attack surface and you ship code every week |
Cloud security engineer | Secures the cloud estate: identity and access policies, network exposure, configuration posture, logging and guardrails written into infrastructure code | Most of your systems run on AWS, Azure or Google Cloud and nobody owns their security configuration |
For most companies making a first security hire, the right answer is a security engineer with cloud depth. The lone SOC analyst is the role most often mis-hired. Analysts are trained to work a queue in shifts, and one analyst without a mature platform or a rota tends to become an expensive inbox for alerts nobody has tuned.
Two adjacent roles get confused with security. If your infrastructure has no owner at all, hire a cloud or infrastructure engineer first, because security controls need someone running the estate they protect. If what you need is someone to set up laptops, manage accounts and run onboarding, that is internal IT support, a different and cheaper hire.
A single security hire is not a 24/7 SOC
If you need someone watching for attacks around the clock, one in-house hire cannot provide it, and MixWork is the wrong partner for that purchase.
A week has 168 hours and one person works a standard working week of them. Continuous monitoring takes a rota of several people before you account for leave, illness and turnover, plus the detection platform, playbooks and escalation paths that make the rota useful. That is what managed detection and response providers and managed security service providers sell, and for most companies under a few hundred people it is the more sensible way to buy round-the-clock cover.
A permanent hire is still worth having alongside a provider, and often makes the provider worth what you pay. The in-house engineer chooses the provider and holds them to their service levels, tunes what gets escalated, handles the alerts that need knowledge of your business, and fixes the underlying causes the provider can only report. Jakarta runs on UTC+7 with no daylight saving, so a Jakarta engineer’s working day covers Asia-Pacific business hours and falls across the European night and the American evening. Southeast Asia timezone coverage has the overlap maths against your own offset.
How much weight to give security certifications
Treat a security certification as evidence that someone has studied a body of knowledge, then test separately whether they can apply it in your environment.
Certification | Issuer | What it shows | What it does not show |
|---|---|---|---|
CompTIA Security+ | CompTIA | Grounding in the practical skills behind core security functions | Depth in your stack, or experience under incident pressure |
Certified Ethical Hacker (CEH) | EC-Council | Knowledge of attack techniques, tested by a multiple-choice exam; a separate optional practical exam leads to CEH Master | Hands-on ability, unless they also passed the practical |
OSCP (OffSec Certified Professional) | OffSec | Passed a 24-hour proctored, hands-on exam exploiting live lab systems | Defensive engineering, detection or architecture skills |
CISSP | ISC2 | Broad security management knowledge, plus at least five years of cumulative experience across two or more of its domains | Hands-on technical depth |
The CISSP detail matters for a mid-career hire. ISC2 requires five years’ experience, so a candidate at the lower end of a three to six year band may have passed the exam and hold Associate of ISC2 status while they build the remaining experience. That is normal and not a mark against them.
No certificate tells you about discretion, judgment, or how someone behaves when they hold access nobody else checks. Those are what the rest of the process has to test.
How to vet a security engineer without creating risk
Test investigation, building and judgment with exercises based on your own environment, and never give a candidate real credentials, live vulnerabilities or production data during the process.
An investigation walk-through. Give them a short, sanitised sequence of log lines: failed sign-ins, a success from a new location, then a new mailbox forwarding rule. Ask what happened and what they would do in the next hour.
A first-ninety-days plan. Describe your identity, endpoint and cloud setup at a high level and ask them to rank what they would fix first. You learn whether they prioritise by risk or by what they find interesting.
A review exercise for specialist roles. For application security, a code snippet with a planted flaw. For cloud security, an access policy that grants more than it should.
The discretion question. Ask what they would do on finding evidence that a senior colleague’s account was compromised, or that an employee had breached policy. You want an answer built on a documented incident process and need-to-know, with no freelancing.
Do not ask candidates to test your live systems as part of an interview. Beyond the legal questions, it teaches the wrong lesson about how your company treats access.
MixWork runs the earlier screening stages before you meet anyone, including a live skills assessment for the role. Ask each candidate's referees about the specific incidents the candidate says they handled. You join for the main interview and the alignment interview.
Offshore security hires and cross-border personal data
If your security engineer in Indonesia will be able to see personal data held outside Indonesia, or personal data about people in Indonesia held elsewhere, take legal advice on the cross-border position before access is granted.
Indonesia’s Personal Data Protection Law is Law No. 27 of 2022 (Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi), enacted on 17 October 2022, and it includes provisions on transferring personal data outside Indonesia. The data protection law of your own jurisdiction will apply as well. This page does not set out what either requires; qualified counsel in each jurisdiction should.
There is an engineering side to this that the hire can own. Security logs collect personal data incidentally: email addresses, IP addresses, device identifiers, sometimes message content. A good security engineer designs logging and retention so that the team keeps what investigations need and no more, which reduces the exposure your lawyers have to assess.
What moves the price of a security engineer in Indonesia
Price follows the responsibility a candidate has carried under real pressure, more than the certificates on their profile.
Incident experience. Someone who has led the response to a real incident prices above someone who has triaged alerts and handed them on.
Depth on your platforms. Hands-on time with your cloud provider, your identity provider and your detection tooling shortens the ramp-up considerably.
Where the experience was earned. Banks, payment companies and multinationals under regular audit teach evidence, change control and reporting discipline that smaller environments rarely demand.
Specialism. Application security and cloud security engineers who can work credibly with developers are scarcer than generalists.
Written English for executives and auditors. A security engineer spends a surprising share of the job explaining risk to people who do not want to hear it.
We do not publish salary figures for security roles. Pay for security engineers in Indonesia reprices faster than any survey can follow, especially for cloud and application security, so a band printed here would mislead you within months. MixWork quotes a current figure on a call for the seniority and specialism you need.
Who you are hiring: remote security engineers from Jakarta
Most of the security professionals MixWork places learnt their habits in multinational or global-agency environments, where audit, evidence and incident process are routine.
More than 80% of the people MixWork places come from multinational or global-agency backgrounds, and we have placed more than 100 professionals in remote roles. Twelve-month retention across MixWork placements runs above 90%, measured on our own placement data. Retention has a security value of its own in this role: every departure means rotating credentials, reviewing access and losing the context behind your detection rules and exceptions. Total Care 360 supports retention, and it is included with the EOR.
Microsoft’s Work Trend Index 2026, published 30 June 2026, found that 62% of Indonesian workers name critical thinking as their priority skill, against 46% globally. Every MixWork placement works with AI tools daily as standard, and in security that is useful only when paired with the habit of questioning what a tool reports, whether it is an AI summary of an alert or a scanner’s severity rating.
English among Jakarta’s professional class is very high, and near-native among the professionals we place. They write incident reports and risk summaries for your executives, present findings to auditors and run meetings with your engineering teams without an intermediary. The technical pipeline runs through universities including Universitas Indonesia, ranked 191st in the QS World University Rankings 2027, Universitas Gadjah Mada (206th) and Institut Teknologi Bandung (287th).
Contracts and employer costs
Security is continuing work, so a security engineer belongs on a PKWTT permanent contract.
Indonesian employment contracts are PKWT (fixed-term) or PKWTT (permanent) under Law No. 13 of 2003 on Manpower, as amended by the Job Creation law (Law No. 6 of 2023), and Government Regulation No. 35 of 2021. A fixed-term contract on a continuing role is a misclassification exposure, and in a privileged role the churn it invites is a security problem as well. The PKWT vs PKWTT guide covers the distinction.
Statutory employer costs sit on top of salary: BPJS contributions and the annual THR religious holiday allowance, while PPh 21 is withheld from salary and administered by MixWork. The cost calculator turns a target salary into an all-in figure, and the full breakdown of employer costs explains each line.
When MixWork is the wrong partner
Several common security purchases are not a permanent hire.
Round-the-clock monitoring. Buy managed detection and response or a managed security service. MixWork does not provide either.
A one-off penetration test or certification audit. Use an independent testing firm. Independence is part of what you are paying for.
An incident happening now. Call an incident response firm today and hire afterwards.
A fractional security lead or a contractor. MixWork provides full-time permanent employment only, not contractors or freelancers.
How MixWork hires cybersecurity engineers
MixWork recruits the security engineer through MixWork Recruit, employs them through MixWork EOR with Total Care 360 included, and can supply the managed device they work from.
MixWork Recruit is success-based, from 10% of first-year salary. Our specialised IT recruitment team works on MixWork’s own platform with proprietary data and AI tools that make our recruiters faster. A first shortlist can arrive as fast as 24 hours for mid-level roles and 48 hours for senior roles, as a best case rather than a guarantee. Recruitment typically takes two to three weeks from brief to an accepted offer, and if the candidate is employed, their 30-day resignation notice comes on top and sets the real start date. We run application review, AI screening, recruiter screening, a pre-screen interview, an HR interview and the live skills assessment; you join for the main interview and the alignment interview.
MixWork EOR starts from USD 249 per employee per month and employs the engineer on a compliant Indonesian contract, running payroll, PPh 21, BPJS and THR. Activation can take as little as 24 hours once you have chosen your hire. Total Care 360 is included at no extra cost: a named HR manager backed by a full HR team, monthly check-in calls with the engineer and separately with you, engagement and dispute resolution, and performance and attendance monitoring.
MixWork Managed IT provides the managed device from USD 99 per device per month, with no deposit or upfront payment and devices held in-region. MixWork Spaces, dedicated workspaces in Jakarta run by MixWork itself, start from USD 199 per workspace per month if you want the engineer working from an office rather than a home.
Getting started
Book a free consultation and we will help you decide which security role to hire first, and give you a current all-in cost. If you are earlier than that, start with the full process for hiring employees in Indonesia.
Sources
Komdigi JDIH, Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi (accessed 8 October 2026)
ISC2, CISSP experience requirements (accessed 8 October 2026)
OffSec, PEN-200 and the OSCP certification (accessed 8 October 2026)
EC-Council, Certified Ethical Hacker (accessed 8 October 2026)
CompTIA, Security+ certification (accessed 8 October 2026)
timeanddate.com, Western Indonesia Time (WIB) time zone (accessed 8 October 2026)
Microsoft, Work Trend Index 2026, published 30 June 2026 (accessed 8 October 2026)
QS World University Rankings 2027, released 18 June 2026 (accessed 8 October 2026)
This page is general information, not legal or tax advice. Indonesian employment, tax and data protection rules change and are open to interpretation, and cross-border handling of personal data depends on the facts and on the law of each country involved. Confirm any statutory, contractual or data protection question with qualified Indonesian legal counsel, and with tax advisers where relevant, before relying on it.


