22 часа назад
Offensive Security Engineer/Lead (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Offensive Security Engineer/Lead (Cybersecurity): Leading adversarial simulation, penetration testing, and vulnerability research programs for a financial technology platform with an accent on red team operations, MITRE ATT&CK mapping, and detection validation. Focus on designing multi-stage attack campaigns, exploiting vulnerabilities across cloud and application environments, and building offensive security tooling.
Location: Hybrid in Jakarta, Indonesia
Company
Build financial inclusion solutions for Indonesia.
What you will do
- Lead the strategy, scope, and execution roadmap for penetration testing, red teaming, and adversary simulation programs.
- Design multi-stage red team operations emulating real-world threat actors and APTs, mapping techniques to MITRE ATT&CK.
- Validate defenses across the Lockheed Martin Cyber Kill Chain and identify gaps in boundary protection and internal monitoring.
- Collaborate with SOC and Incident Response teams on Purple Team exercises to improve detection engineering, SIEM alerts, and response playbooks.
- Exploit vulnerabilities across network infrastructure, cloud environments, and applications, then produce prioritized remediation reports.
- Oversee offensive security tools, scripts, and command-and-control frameworks.
Requirements
- 8+ years of technical experience in offensive security, ethical hacking, or penetration testing, including 2+ years leading a red team or offensive security function.
- Mastery of the MITRE ATT&CK matrix across Enterprise, Cloud, and Mobile environments, with deep knowledge of the Lockheed Martin Cyber Kill Chain.
- Proficiency with offensive tools such as Cobalt Strike, Burp Suite, and Metasploit, plus cloud-native security across AWS, GCP, or Azure.
- Strong scripting and programming skills in Python, Go, PowerShell, or Bash for attack automation, security-control bypasses, and custom exploit development.
- Ability to communicate complex attack vectors and business impacts to technical and non-technical stakeholders.
Nice to have
- Advanced offensive security certification such as OSCE, OSEP, OSWE, GXPN, or CRTO.
Culture & Benefits
- Hybrid work arrangement in Jakarta.
- Opportunity to contribute to increasing financial inclusion in Indonesia.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →