Company Logo

Senior Offensive Security Engineer (Penetration Testing)

Rp25.000.000 - 35.000.000/Bulan
Penuh Waktu · Kerja di lokasi
Minimal Sarjana (S1)
5 - 10 tahun pengalaman
Lowongan ini telah ditutup

Persyaratan

Kerja di lokasi
5 - 10 tahun pengalaman
Minimal Sarjana (S1)

Skills

Cybersecurity

Penetration Testing

Network Security

Information Security

Certified Information Security Manager (CISM)

Security Audit

Benefit Kerja

Health Insurance

Career Path

Laptop Provided

Lifetime Savings

Insurance

Annual Leave

Loker ini dikelola oleh

R
Rekruter

Deskripsi pekerjaan Senior Offensive Security Engineer (Penetration Testing) SMARTM2M Indonesia

Responsibilities

  • Plan, scope, and execute penetration tests following NIST SP 800-115 with formal authorization, Rules of Engagement, execution logs, and structured reporting plus retesting.
  • Conduct web and API testing aligned to the OWASP Web Security Testing Guide with traceable test cases and coverage mapping for application and authentication/authorization flows.
  • Structure engagements per PTES phases for consistency across pre-engagement, intelligence gathering, exploitation, post-exploitation, and reporting.
  • Map techniques and findings to MITRE ATT&CK to support SOC/DFIR integration and detection engineering backlogs.
  • Produce PCI-ready deliverables, including Rules of Engagement, segmentation testing where applicable, and evidence artifacts suitable for assessors.
  • Write clear, prioritized remediation guidance with verification steps and retest results suitable for audits and leadership briefings.
  • Collaborate with engineering and security stakeholders to align test scope with risk priorities and SDLC timing, leveraging OWASP guidance for application contexts.

Minimum qualifications

  • Demonstrated delivery of end-to-end penetration tests under NIST SP 800-115 and OWASP WSTG, including reporting and retesting workflows.
  • One or more of the following certifications as a minimum: CEH, PNPT, CRTO, CRTP, or CPTS (or equivalent practical credential) to evidence hands-on capability across pentest or adversary tradecraft.
  • Familiarity with PTES for engagement structure and with MITRE ATT&CK for technique mapping and narrative clarity.
  • Ability to produce auditable artifacts suitable for PCI-aligned programs when required by clients.

Preferred qualifications

  • OSCP as the primary preferred credential for rigorous, hands-on penetration testing capability recognized by employers globally.
  • Additional plus: GPEN or CREST CRT for methodology depth and external assurance signaling in regulated environments.
  • Experience translating ATT&CK-mapped findings into detection use-cases and engineering backlogs with stakeholders.
Tentang Perusahaan
SMARTM2M Indonesia
11 - 50 karyawan

SmartM2M is a Korean digital security company that specializes in Blockchain, Artificial Intelligence, and security solutions and services.

Since its establishment in 2012, SmartM2M has grown into a professional research and development company, leading technology development in the core technology field of the 4th industrial revolution. We have been developing enterprise-grade blockchain-based solutions in various domains including but not limited to smart cities, supply chain, medical, and energy trading fields.

We are currently expanding our operations in Indonesia and seeking talented people who are enthusiastic with the challenges of the next generation of ICT to lead future innovation.

Alamat kantor

16th Floor HQuarters Business Residence , Jl. Asia Afrika 158

Galeri Perusahaan

Tips Aman Cari Kerja

Pemberi kerja yang benar tidak akan meminta akun Telegram, top-ups atau pembayaran dalam bentuk apapun. Jangan berikan kontak pribadi, informasi bank, maupun kartu kredit kamu.

Pelajari Selengkapnya

Senior Offensive Security Engineer (Penetration Testing)