Senior Penetration Tester

Referensiin_AjaJakarta Selatan, DKI Jakartaglintspublished 09/08/2026
This job is no longer listed
The source has removed this listing — applying via the original link is no longer possible.
Must-have:GraphQLCloudMobileSecurityLead
Nice-to-have:PythonC#

"Warning : Before apply this job posting, please write your account name same with your linkedin account "

From this Platform, we want to help our partners in spreading job vacancy below :

Key Responsibilities :

  1. Leadership: Lead technical scoping, establish Rules of Engagement (RoE) with stakeholders, and execute end-to-end assessments independently
  2. Hands-on Penetration Testing: Perform deep-dive assessments on Web, Mobile (Android/iOS), API (REST/GraphQL), Network, Active 3. Directory, and Cloud/Container environments with manual validation to eliminate false positives
  3. Reporting & Deliverables: Produce clear, two-tiered reports consisting of an Executive Summary for leadership and reproducible technical details with prioritized remediation steps for developers
  4. Debriefs & Stakeholder Communication: Lead debrief sessions, presenting complex technical findings effectively to both non-technical business leaders and technical engineering teams
  5. Remediation & Retesting: Conduct retests to verify fix effectiveness and ensure long-term risk mitigation
  6. Capability Development & Mentoring: Drive continuous improvement by building internal tooling, refining checklists/playbooks, and mentoring junior team members

Person Specifications :

  1. Minimum 4 years of experience in offensive security, OR 7 years in general cybersecurity with at least 4 years exclusively focused on penetration testing, experience bug bounty.
  2. Proven experience independently managing critical engagements within high-risk sectors (Financial Services, Telecommunications, E-Commerce, or Government)
  3. Web & API: In-depth knowledge of OWASP Top 10 and WSTG. Expertise in testing authentication/authorization flaws, IDOR, SSRF, insecure deserialization, business logic bugs, and API vulnerabilities (REST & GraphQL batching/introspection abuse)
  4. Mobile Security: Deep knowledge of OWASP MASTG. Hands-on experience with static/dynamic analysis on Android & iOS, including client-side security bypasses
  5. Scripting & Tooling: Proficient in Python, Bash, or PowerShell (Go or C# is a plus). Ability to modify PoCs and build custom scripts rather than relying solely on automated scanners
  6. Standards & Compliance: Familiarity with PTES, OSSTMM, NIST SP 800-115, MITRE ATT&CK, CVSS v3.1/v4.0, PCI DSS, ISO 27001, as well as Indonesian regulations (POJK/SEOJK and UU PDP)
  7. Preferred Certification (Practical/Hands-on): OSCP (Primary), paired with OSEP, OSWE, GPEN, GWAPT, CRTO, or CREST CRT
  8. Bonus / Advanced: OSCE³, GXPN, CARTP/CARTS, eWPTX, or GMOB
  9. Complementary: CEH, CompTIA PenTest+

Note:

  1. ASAP
  2. Please ensure their English skill properly, since the interview will conduct by our team in Sri Lanka and or Malaysia, depend on the project"

Industry : Tech Location : Jakarta Contract : 6 Months, WFO

Skills: Certified Cybersecurity Technician (cct), Project Implementation, Cybersecurity, Team Management, Project Management, Certified Ethical Hacker (ceh), Project Coordination, Business Intelligence