Deskripsi Pekerjaan
Informasi lengkap tentang posisi dan persyaratan
Ringkasan Yukerja
Lowongan Security Engineer - Penetration Tester di Daya Solutions Innovations kami kurasi dari JobStreet (kategori Teknologi & IT). Perhatikan lokasi kerja (South Jakarta, Jakarta) sebelum melamar. Yukerja.com bukan pemberi kerja — lamaran diproses di situs sumber resmi.
JOB DESCRIPTION:
1. Offensive Operations & Penetration Testing
● Conduct end-to-end penetration testing across our web applications, mobile apps (iOS/Android), and APIs.
● Perform targeted security assessments of our GCP infrastructure, identifying misconfigurations, privilege escalation paths, and IAM flaws.
● Utilize industry-standard offensive tools (e.g., Burp Suite, OWASP ZAP, Metasploit, Nmap) effectively while knowing when to pivot to manual testing techniques.
● Write clear, concise, and actionable penetration testing reports detailing the vulnerabilities found, exploit chains, and business impacts.
● Provide step-by-step reproduction steps or script-based POC so engineering teams can easily replicate and validate the security flaws.
2. Purple Teaming & Collaboration
● Partner closely with our Blue Team / Defensive engineers to validate alerting capabilities, improve SIEM/EDR detection rules, and close security gaps.
● Provide actionable, developer-friendly remediation guidance to software engineering teams.
● Participate in post-assessment debriefs, explaining technical exploit chains clearly to both technical and non-technical stakeholders.
3. Custom Tooling & Development
● Modify, script, and build custom security tools or exploits (using Python, Go, Bash, or similar) when off-the-shelf tools fail to meet project goals or get blocked.
● Automate repetitive testing workflows to improve the efficiency of our offensive operations.
QUALIFICATIONS:
● 3+ years of dedicated experience in penetration testing, ethical hacking, or application security assessments.
● Strong understanding of GCP security concepts (IAM policies, VPC structures, GKE/Kubernetes security) and cloud attack surfaces.
● Deep familiarity with the OWASP Top 10 (Web and Mobile) and API security vulnerabilities.
● Proficient in at least one scripting/programming language (Python or Go preferred) with the ability to read code and write custom exploits.
● Deep understanding of core networking concepts (TCP/IP, DNS, HTTP/S, routing, and switching) and how they apply to cloud architectures.
● Ability to articulate technical risk in writing, ensuring that both software developers (who need technical details) and business leaders (who need risk context) can understand the findings.
CORE BEHAVIOUR ATTRIBUTES:
Have proven ability to work effectively independently within a department
Able to balance tight security controls with the speed of business operations
Have communication skills to translate technical risks to non-technical stakeholders