Deskripsi Pekerjaan
Informasi lengkap tentang posisi dan persyaratan
Ringkasan Yukerja
Lowongan Security Engineer - Penetration Tester di Daya Solutions Innovations kami kurasi dari JobStreet (kategori Teknologi & IT). Perhatikan lokasi kerja (South Jakarta, Jakarta) sebelum melamar. Yukerja.com bukan pemberi kerja — lamaran diproses di situs sumber resmi.
JOB DESCRIPTION:
1. Offensive Operations & Penetration Testing
? Conduct end-to-end penetration testing across our web applications, mobile apps (iOS/Android), and APIs.
? Perform targeted security assessments of our GCP infrastructure, identifying misconfigurations, privilege escalation paths, and IAM flaws.
? Utilize industry-standard offensive tools (e.g., Burp Suite, OWASP ZAP, Metasploit, Nmap) effectively while knowing when to pivot to manual testing techniques.
? Write clear, concise, and actionable penetration testing reports detailing the vulnerabilities found, exploit chains, and business impacts.
? Provide step-by-step reproduction steps or script-based POC so engineering teams can easily replicate and validate the security flaws.
2. Purple Teaming & Collaboration
? Partner closely with our Blue Team / Defensive engineers to validate alerting capabilities, improve SIEM/EDR detection rules, and close security gaps.
? Provide actionable, developer-friendly remediation guidance to software engineering teams.
? Participate in post-assessment debriefs, explaining technical exploit chains clearly to both technical and non-technical stakeholders.
3. Custom Tooling & Development
? Modify, script, and build custom security tools or exploits (using Python, Go, Bash, or similar) when off-the-shelf tools fail to meet project goals or get blocked.
? Automate repetitive testing workflows to improve the efficiency of our offensive operations.
QUALIFICATIONS:
? 3+ years of dedicated experience in penetration testing, ethical hacking, or application security assessments.
? Strong understanding of GCP security concepts (IAM policies, VPC structures, GKE/Kubernetes security) and cloud attack surfaces.
? Deep familiarity with the OWASP Top 10 (Web and Mobile) and API security vulnerabilities.
? Proficient in at least one scripting/programming language (Python or Go preferred) with the ability to read code and write custom exploits.
? Deep understanding of core networking concepts (TCP/IP, DNS, HTTP/S, routing, and switching) and how they apply to cloud architectures.
? Ability to articulate technical risk in writing, ensuring that both software developers (who need technical details) and business leaders (who need risk context) can understand the findings.
CORE BEHAVIOUR ATTRIBUTES:
Have proven ability to work effectively independently within a department
Able to balance tight security controls with the speed of business operations
Have communication skills to translate technical risks to non-technical stakeholders