Deskripsi pekerjaan Senior Offensive Security Engineer (Penetration Testing) SMARTM2M Indonesia
Responsibilities
- Plan, scope, and execute penetration tests following NIST SP 800-115 with formal authorization, Rules of Engagement, execution logs, and structured reporting plus retesting.
- Conduct web and API testing aligned to the OWASP Web Security Testing Guide with traceable test cases and coverage mapping for application and authentication/authorization flows.
- Structure engagements per PTES phases for consistency across pre-engagement, intelligence gathering, exploitation, post-exploitation, and reporting.
- Map techniques and findings to MITRE ATT&CK to support SOC/DFIR integration and detection engineering backlogs.
- Produce PCI-ready deliverables, including Rules of Engagement, segmentation testing where applicable, and evidence artifacts suitable for assessors.
- Write clear, prioritized remediation guidance with verification steps and retest results suitable for audits and leadership briefings.
- Collaborate with engineering and security stakeholders to align test scope with risk priorities and SDLC timing, leveraging OWASP guidance for application contexts.
Minimum qualifications
- Demonstrated delivery of end-to-end penetration tests under NIST SP 800-115 and OWASP WSTG, including reporting and retesting workflows.
- One or more of the following certifications as a minimum: CEH, PNPT, CRTO, CRTP, or CPTS (or equivalent practical credential) to evidence hands-on capability across pentest or adversary tradecraft.
- Familiarity with PTES for engagement structure and with MITRE ATT&CK for technique mapping and narrative clarity.
- Ability to produce auditable artifacts suitable for PCI-aligned programs when required by clients.
Preferred qualifications
- OSCP as the primary preferred credential for rigorous, hands-on penetration testing capability recognized by employers globally.
- Additional plus: GPEN or CREST CRT for methodology depth and external assurance signaling in regulated environments.
- Experience translating ATT&CK-mapped findings into detection use-cases and engineering backlogs with stakeholders.







