Penetration Tester (Offensive Security) – Telco Industry

PT Digital Tech AsiaJakarta Selatan, DKI Jakartaglintspublished 10/09/2026
Must-have:PythonGraphQLCloudMobileFinTechE-CommerceSecuritySeniorLeadJunior

We're Hiring: Senior Penetration Tester

Company: PT Digital Tech Asia Client Industry: Telecommunications (Telco) Location: South Jakarta, Indonesia Work Arrangement: Onsite (WFO) Employment Type: 6-Month Contract (extendable) Experience: Minimum 3 Years in Offensive Security / Penetration Testing

About the Role

Digital Tech Asia is seeking a highly skilled and experienced Senior Penetration Tester to join our client in the Telecommunications Industry. The ideal candidate will have strong hands-on expertise in offensive security, vulnerability exploitation, and penetration testing across Web Applications, APIs, Mobile Applications, Networks, Active Directory, and Cloud Infrastructure. In this role, you will independently lead end-to-end penetration testing engagements, identify and validate security vulnerabilities, deliver actionable remediation recommendations, and collaborate with technical teams to strengthen enterprise security.

Key Responsibilities

  • End-to-End Penetration Testing: Lead security assessments from technical scoping and Rules of Engagement (RoE) through execution, reporting, and retesting.
  • Security Assessments: Conduct penetration testing across Web Applications, Mobile Applications (Android/iOS), REST/GraphQL APIs, Networks, Active Directory, and Cloud/Container environments.
  • Vulnerability Identification: Identify, exploit, and manually validate security vulnerabilities, including authentication/authorization flaws, IDOR, SSRF, insecure deserialization, and business logic vulnerabilities.
  • Security Reporting: Prepare detailed penetration testing reports, including executive summaries, technical findings, proof of concepts (PoCs), risk ratings, and remediation recommendations.
  • Stakeholder Collaboration: Present findings to technical and non-technical stakeholders and work closely with developers, infrastructure teams, and security teams.
  • Remediation & Retesting: Verify remediation effectiveness through vulnerability retesting.
  • Security Improvement: Develop internal testing tools, scripts, checklists, and security playbooks.
  • Technical Leadership: Provide guidance, mentoring, and knowledge sharing to junior security professionals.

Requirements

Mandatory Qualifications

  • Minimum 3 years of professional experience in Offensive Security/Penetration Testing, or 7 years in general Cybersecurity with at least 4 years specifically focused on Penetration Testing.
  • Proven ability to independently conduct end-to-end penetration testing engagements.
  • Strong hands-on experience in Web Application, API, Mobile Application (Android/iOS), and Network Penetration Testing.
  • In-depth understanding of OWASP Top 10, OWASP WSTG, and OWASP MASTG.
  • Experience identifying and exploiting vulnerabilities such as IDOR, SSRF, authentication bypass, insecure deserialization, and business logic flaws.
  • Experience with manual exploitation, vulnerability validation, and proof-of-concept development.
  • Proficiency in at least one scripting language: Python, Bash, or PowerShell.
  • Familiarity with Active Directory, Cloud Security, and Container Security assessments.
  • Strong knowledge of vulnerability severity classification and remediation recommendations.
  • Experience working in Telecommunications, Banking, Financial Services, E-Commerce, Government, or other high-risk industries.
  • Strong analytical, communication, documentation, and reporting skills.
  • Willing to work onsite in South Jakarta under a 6-month contract.

Preferred Qualifications

Certifications:

  • OSCP – Highly Preferred
  • OSEP, OSWE, GPEN, GWAPT, CRTO, or CREST CRT
  • Advanced certifications such as OSCE³, GXPN, CARTP/CARTS, eWPTX, or GMOB are an advantage.
  • CEH or CompTIA PenTest+ as complementary certifications.

Technical Knowledge:

  • PTES, OSSTMM, NIST SP 800-115, and MITRE ATT&CK.
  • CVSS v3.1/v4.0 for vulnerability risk classification.
  • PCI DSS and ISO 27001.
  • Indonesian cybersecurity and data protection regulations, including POJK/SEOJK where applicable and UU PDP.
  • Experience with REST/GraphQL API security testing.
  • Experience creating custom exploitation scripts and modifying existing PoCs.
  • Familiarity with telecommunications infrastructure, subscriber-facing platforms, and enterprise network security is an advantage.

Skills: Cybersecurity, Bash, PowerShell, Oscp Certification, Python, Offensive Security, Penetration Testing