Назад
Company hidden
22 часа назад

Offensive Security Engineer/Lead (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Indonesia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Offensive Security Engineer/Lead (Cybersecurity): Leading adversarial simulation, penetration testing, and vulnerability research programs for a financial technology platform with an accent on red team operations, MITRE ATT&CK mapping, and detection validation. Focus on designing multi-stage attack campaigns, exploiting vulnerabilities across cloud and application environments, and building offensive security tooling.

Location: Hybrid in Jakarta, Indonesia

Company

Build financial inclusion solutions for Indonesia.

What you will do

  • Lead the strategy, scope, and execution roadmap for penetration testing, red teaming, and adversary simulation programs.
  • Design multi-stage red team operations emulating real-world threat actors and APTs, mapping techniques to MITRE ATT&CK.
  • Validate defenses across the Lockheed Martin Cyber Kill Chain and identify gaps in boundary protection and internal monitoring.
  • Collaborate with SOC and Incident Response teams on Purple Team exercises to improve detection engineering, SIEM alerts, and response playbooks.
  • Exploit vulnerabilities across network infrastructure, cloud environments, and applications, then produce prioritized remediation reports.
  • Oversee offensive security tools, scripts, and command-and-control frameworks.

Requirements

  • 8+ years of technical experience in offensive security, ethical hacking, or penetration testing, including 2+ years leading a red team or offensive security function.
  • Mastery of the MITRE ATT&CK matrix across Enterprise, Cloud, and Mobile environments, with deep knowledge of the Lockheed Martin Cyber Kill Chain.
  • Proficiency with offensive tools such as Cobalt Strike, Burp Suite, and Metasploit, plus cloud-native security across AWS, GCP, or Azure.
  • Strong scripting and programming skills in Python, Go, PowerShell, or Bash for attack automation, security-control bypasses, and custom exploit development.
  • Ability to communicate complex attack vectors and business impacts to technical and non-technical stakeholders.

Nice to have

  • Advanced offensive security certification such as OSCE, OSEP, OSWE, GXPN, or CRTO.

Culture & Benefits

  • Hybrid work arrangement in Jakarta.
  • Opportunity to contribute to increasing financial inclusion in Indonesia.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →