Deskripsi pekerjaan SENIOR PENETRATION TESTER MSBU
Minimum 4 years of experience in offensive security, OR 7 years in general cybersecurity with at least 4 years exclusively focused on penetration testing, experience bug bounty.
Proven experience independently managing critical engagements within high-risk sectors (Financial Services, Telecommunications, E-Commerce, or Government)
Web & API: In-depth knowledge of OWASP Top 10 and WSTG. Expertise in testing authentication/authorization flaws, IDOR, SSRF, insecure deserialization, business logic bugs, and API vulnerabilities (REST & GraphQL batching/introspection abuse)
Mobile Security: Deep knowledge of OWASP MASTG. Hands-on experience with static/dynamic analysis on Android & iOS, including client-side security bypasses
Scripting & Tooling: Proficient in Python, Bash, or PowerShell (Go or C# is a plus). Ability to modify PoCs and build custom scripts rather than relying solely on automated scanners
Standards & Compliance: Familiarity with PTES, OSSTMM, NIST SP 800-115, MITRE ATT&CK, CVSS v3.1/v4.0, PCI DSS, ISO 27001, as well as Indonesian regulations (POJK/SEOJK and UU PDP)
Preferred Certification (Practical/Hands-on): OSCP (Primary), paired with OSEP, OSWE, GPEN, GWAPT, CRTO, or CREST CRT
Bonus / Advanced: OSCE³, GXPN, CARTP/CARTS, eWPTX, or GMOB
Complementary: CEH, CompTIA PenTest+





