Penetration Tester (Offensive Security) – Telco Industry
We're Hiring: Senior Penetration Tester
Company: PT Digital Tech Asia Client Industry: Telecommunications (Telco) Location: South Jakarta, Indonesia Work Arrangement: Onsite (WFO) Employment Type: 6-Month Contract (extendable) Experience: Minimum 3 Years in Offensive Security / Penetration Testing
About the Role
Digital Tech Asia is seeking a highly skilled and experienced Senior Penetration Tester to join our client in the Telecommunications Industry. The ideal candidate will have strong hands-on expertise in offensive security, vulnerability exploitation, and penetration testing across Web Applications, APIs, Mobile Applications, Networks, Active Directory, and Cloud Infrastructure. In this role, you will independently lead end-to-end penetration testing engagements, identify and validate security vulnerabilities, deliver actionable remediation recommendations, and collaborate with technical teams to strengthen enterprise security.
Key Responsibilities
- End-to-End Penetration Testing: Lead security assessments from technical scoping and Rules of Engagement (RoE) through execution, reporting, and retesting.
- Security Assessments: Conduct penetration testing across Web Applications, Mobile Applications (Android/iOS), REST/GraphQL APIs, Networks, Active Directory, and Cloud/Container environments.
- Vulnerability Identification: Identify, exploit, and manually validate security vulnerabilities, including authentication/authorization flaws, IDOR, SSRF, insecure deserialization, and business logic vulnerabilities.
- Security Reporting: Prepare detailed penetration testing reports, including executive summaries, technical findings, proof of concepts (PoCs), risk ratings, and remediation recommendations.
- Stakeholder Collaboration: Present findings to technical and non-technical stakeholders and work closely with developers, infrastructure teams, and security teams.
- Remediation & Retesting: Verify remediation effectiveness through vulnerability retesting.
- Security Improvement: Develop internal testing tools, scripts, checklists, and security playbooks.
- Technical Leadership: Provide guidance, mentoring, and knowledge sharing to junior security professionals.
Requirements
Mandatory Qualifications
- Minimum 3 years of professional experience in Offensive Security/Penetration Testing, or 7 years in general Cybersecurity with at least 4 years specifically focused on Penetration Testing.
- Proven ability to independently conduct end-to-end penetration testing engagements.
- Strong hands-on experience in Web Application, API, Mobile Application (Android/iOS), and Network Penetration Testing.
- In-depth understanding of OWASP Top 10, OWASP WSTG, and OWASP MASTG.
- Experience identifying and exploiting vulnerabilities such as IDOR, SSRF, authentication bypass, insecure deserialization, and business logic flaws.
- Experience with manual exploitation, vulnerability validation, and proof-of-concept development.
- Proficiency in at least one scripting language: Python, Bash, or PowerShell.
- Familiarity with Active Directory, Cloud Security, and Container Security assessments.
- Strong knowledge of vulnerability severity classification and remediation recommendations.
- Experience working in Telecommunications, Banking, Financial Services, E-Commerce, Government, or other high-risk industries.
- Strong analytical, communication, documentation, and reporting skills.
- Willing to work onsite in South Jakarta under a 6-month contract.
Preferred Qualifications
Certifications:
- OSCP – Highly Preferred
- OSEP, OSWE, GPEN, GWAPT, CRTO, or CREST CRT
- Advanced certifications such as OSCE³, GXPN, CARTP/CARTS, eWPTX, or GMOB are an advantage.
- CEH or CompTIA PenTest+ as complementary certifications.
Technical Knowledge:
- PTES, OSSTMM, NIST SP 800-115, and MITRE ATT&CK.
- CVSS v3.1/v4.0 for vulnerability risk classification.
- PCI DSS and ISO 27001.
- Indonesian cybersecurity and data protection regulations, including POJK/SEOJK where applicable and UU PDP.
- Experience with REST/GraphQL API security testing.
- Experience creating custom exploitation scripts and modifying existing PoCs.
- Familiarity with telecommunications infrastructure, subscriber-facing platforms, and enterprise network security is an advantage.
Skills: Cybersecurity, Bash, PowerShell, Oscp Certification, Python, Offensive Security, Penetration Testing