Deskripsi Pekerjaan
Informasi lengkap tentang posisi dan persyaratan
Ringkasan Yukerja
Lowongan Ethical Hacker / Penetration Tester — OSINT Investigations & Digital Forensics di PT Cnf Global Talenta kami kurasi dari JobStreet (kategori Kerja Remote). Posisi ini ditandai sebagai remote — pastikan timezone dan syarat lokasi kandidat di deskripsi resmi. Yukerja.com bukan pemberi kerja — lamaran diproses di situs sumber resmi.
About us
ICTechnology is an Australian managed services provider with offices in Sydney and Dubai, supporting government, commercial and not-for-profit clients across NSW and beyond. Reliability is our core value — our clients trust us as their in-house IT team, and increasingly they are asking us to prove their defences actually hold.
About the role
This is a full-time, fully remote position. You will be the person who breaks things on purpose — safely, in scope, and with a report good enough that a client's board can read it.
Key responsibilities
Plan and execute penetration tests against client networks internal, external, wireless and segmentation testing
Test web applications and websites for the OWASP Top 10 and beyond: authentication and session flaws, injection, access control failures, business logic abuse, API weaknesses
Conduct OSINT investigations into online personas — attributing accounts and aliases to real-world identities, mapping networks of linked profiles, resolving anonymous or pseudonymous actors, and documenting the evidence trail that supports the conclusion
Build and operate research personas and sock puppet accounts with sound operational security, and maintain the infrastructure that keeps investigative activity separated from ICTechnology and our clients
Run dark web research — monitoring Tor and I2P marketplaces, forums and leak sites for client data, credentials, brand abuse and threat actor chatter, and tracking actor handles and reputations across platforms
Handle attack surface and exposure intelligence — credential and data leak discovery, executive and brand threat monitoring, supply chain reconnaissance
Perform digital forensics and incident response work: evidence acquisition and preservation, timeline analysis, malware triage, and clear findings that stand up to scrutiny
Run phishing simulations and social engineering assessments where clients have authorised them
Write the deliverables that matter — a technical findings report with reproducible steps and evidence, plus an executive summary a non-technical stakeholder can act on
Retest remediations and confirm fixes actually closed the gap
Contribute to our security tooling, methodology and internal knowledge base
Work with our engineering team so findings turn into hardened systems, not just PDFs
About you
Demonstrable commercial experience conducting penetration tests on networks and web applications
Strong working knowledge of the OWASP Top 10, MITRE ATT&CK and a recognised testing methodology (PTES, OSSTMM or similar)
Hands-on capability with the standard toolkit — Burp Suite, Nmap, Metasploit, Wireshark, Nessus/OpenVAS, Kali — and the judgement to know when the tool is wrong
Scripting ability in Python, Bash or PowerShell for tooling and automation
Solid fundamentals across Windows, Linux, Active Directory, networking and cloud (Azure/AWS/M365)
Demonstrated OSINT investigation experience with a focus on people and online personas — not just domain and infrastructure reconnaissance
Practical dark web experience: safe access and handling of Tor/I2P, marketplace and forum research, credential leak analysis, and the operational discipline that keeps that work contained
Sound persona tradecraft and OPSEC — attribution avoidance, isolated research environments, careful separation of investigative identities
Ability to work autonomously in a remote team, with reliable internet and a private, secure work environment
Hold at least one current, industry-recognised certification. We will verify it, so your credential must be publicly checkable — a Credly badge, an OffSec or CREST credential ID, or an equivalent public verification link included in your application.
We recognise:
OSCP / OSWE / OSEP (OffSec)
CREST CPSA / CRT / CCT
GPEN, GWAPT, GCIH, GCFA, GCFE (GIAC/SANS)
CEH (Practical preferred over the multiple-choice exam)
CompTIA PenTest+ / CySA+
eJPT / eWPT / eCPPT (INE Security)
GCFA, EnCE or CCE for the forensics side
GOSI, GCTI, SANS SEC497/SEC587 (OSINT) or McAfee Institute CCII/CORI for the investigations side
cCDFP Digital Forensic Professional
eCPPT Professional Penetration Tester
wWPT Web App Pentration Tester
OSWP Offensive Security Wireless Professional
Also strongly regarded — show us your work online
An active HackTheBox, TryHackMe, PortSwigger Web Security Academy or Proving Grounds profile
Published CVEs, responsible disclosures or bug bounty results (HackerOne, Bugcrowd, Intigriti)
Open-source security tooling on GitHub, a technical blog, CTF placings or conference talks
Trace Labs Search Party CTF placings, or other documented OSINT competition or volunteer investigation work
Familiarity with the investigative toolkit — Maltego, SpiderFoot, Shodan, Sherlock/WhatsMyName, reverse image and facial similarity search, Hunchly, breach data platforms