Deskripsi pekerjaan Security Engineer Sysbraykr
We are seeking a proactive and detail-oriented Security Engineer to join our cybersecurity team. Conducting comprehensive security assessments on client systems, including mobile applications, web applications, and infrastructure environments (both cloud and on-premise). These assessments should identify vulnerabilities and potential security risks.
Perform full-spectrum penetration testing, adhering to the highest standards of practice and quality as upheld by SysBraykr. This includes but is not limited to:
Exploitation of identified vulnerabilities to understand the potential impact.
Thorough testing of network security, application security, and physical security measures.
Utilizing both automated tools and manual techniques to identify security weaknesses.
Responsibilities
- Develop and execute detailed testing plans tailored to each client’s specific environment and needs. This involves understanding the unique aspects of their systems and potential threat landscapes.
- Stay up-to-date with the latest security threats, trends, and technologies to ensure the most current and effective testing methods are employed. This includes continuous learning and adaptation of new testing tools and methodologies.
- Collaborate closely with client stakeholders to understand their security requirements and objectives. Provide clear and actionable insights to improve their security posture.
- Produce comprehensive and detailed reports that document the findings of the security assessments. These reports should include:
- The objectives and scope of the tests conducted.
- Detailed findings with evidence, such as screenshots and logs.
- Clear, practical recommendations for remediation of identified vulnerabilities.
- An executive summary that highlights key issues and recommended actions in a manner understandable to non-technical stakeholders.
- Present findings to clients in a professional manner, both in written form and verbally during debrief meetings. Ensure that communication is clear, concise, and tailored to the audience, whether technical or executive-level.
- Adhere to ethical hacking standards and guidelines, maintaining the highest level of integrity and professionalism in all interactions and activities. Ensure that all testing is performed legally and ethically, respecting client confidentiality and data privacy.
- Work in collaboration with other members of the SysBraykr team, sharing knowledge and supporting each other to enhance overall team capability and performance.
- Continuously improve SysBraykr’s methodologies and processes by contributing to internal knowledge bases, participating in training sessions, and staying engaged with the cybersecurity community.
- Provide post-assessment support to clients, assisting them in understanding the vulnerabilities and implementing the recommended security improvements. Offer guidance and best practices for ongoing security management and risk mitigation.
Required Qualifications:
- Willing to work on-site in DKI Jakarta.
- Minimum 1 years of work experience in a relevant field.
- Understanding of the OWASP and OSSTMM testing frameworks.
- Ability to read and understand multiple programming languages.
- Command-line experience with Linux, Unix, and Windows operating systems.
- Experience with vulnerabilities in at least two of the following areas: Web applications, Mobile applications, Infrastructure environments (cloud/on-premise)
- Ability to write detailed reports that include the objectives and results of tests, including observations and recommendations.
- Excellent and professional communication skills (written and verbal), with proficiency in English.

