Back to jobs
New

Security Engineer, Penetration Tester

Jakarta, Jakarta, Indonesia

About The Role

We are looking for a mid-level Security Engineer (Penetration Tester) to join our Security team in Jakarta, Indonesia. You will play a key role in strengthening our security posture by performing hands-on penetration testing, identifying real-world risks, and working closely with engineering teams to drive remediation. This role is ideal for someone who is technically strong, detail-oriented, and eager to continuously sharpen their offensive security skills in a collaborative environment.

What You Will Do

  • Plan and execute penetration tests across networks, systems, and web/mobile applications
  • Lead or independently handle penetration testing engagements from scoping to reporting
  • Analyze vulnerabilities, assess risk impact, and produce clear, actionable remediation recommendations
  • Collaborate with developers, infrastructure, and security teams to address findings throughout the SDLC
  • Support security incident response activities when required
  • Continuously research emerging threats, attack techniques, and testing methodologies
  • Contribute to improving internal penetration testing tools, playbooks, and processes

What We Are Looking For

  • Bachelor’s degree in Computer Science, Information Security, or a related technical field
  • Minimum 2 years of hands-on experience in penetration testing or offensive security roles
  • Proven experience conducting penetration tests for web and mobile applications
  • Certification: OSCP or CREST (or equivalent recognized offensive security cert)
  • Strong proficiency with tools such as Burp Suite, Metasploit, Nmap, and Wireshark
  • Solid understanding of security standards and frameworks (OWASP Top 10, NIST, CIS)
  • Strong analytical skills with the ability to clearly explain security risks to technical and non-technical stakeholders
  • Experience with secure coding practices, code review, or SAST/DAST tools is a plus
  • Ability to script or automate using Python, Golang, Ruby, or JavaScript is a plus
  • Familiarity with cloud security concepts (AWS, GCP, or Azure) is a plus
  • Experience with CTF competitions, bug bounty triage, or vulnerability disclosure programs is a plus

Create a Job Alert

Interested in building your career at StraitsX? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...

 

When you apply to a job on this site, the personal data contained in your application will be collected by Fazz Financial Group Pte. Ltd. and/or its associated companies (“Controller”). The Controller’s data protection officer can be contacted at dataprotection@straitsx.com. Your personal data will be processed for the purposes of managing Controller’s recruitment related activities, which include setting up and conducting interviews and tests for applicants, evaluating and assessing the results thereto, and as is otherwise needed in the recruitment and hiring processes. Such processing is legally permissible under the First Schedule, Part 3, Paragraph 10 of the Personal Data Protection Act (PDPA) as necessary for the purposes of the legitimate interests pursued by the Controller, which are the solicitation, evaluation, and selection of applicants for employment. You are responsible for ensuring that the personal data you provide is accurate and complete. If you provide us with personal data relating to another individual (for example, as a referee or emergency contact), you represent and warrant that you have obtained that individual’s consent in accordance with applicable data protection laws (including the PDPA) for us to collect, use, and disclose their personal data for the purposes described above. You also confirm that you have retained proof of such consent and will provide it to us upon request.

Access to your personal data will be limited to authorized personnel involved in the recruitment and hiring process. Your personal data will be shared with Greenhouse Software, Inc., a cloud services provider located in the United States of America and engaged by Controller to help manage its recruitment and hiring process on Controller’s behalf. Accordingly, if you are located outside of the United States, your personal data will be transferred to the United States once you submit it through this site. The Controller will ensure that such transfers are subject to arrangements that provide a standard of protection comparable to that under the PDPA.

In accordance with Section 25 of the PDPA, the Controller will cease to retain documents containing your personal data, or remove the means by which the data can be associated with you, as soon as it is no longer required for (a) the purposes for which it was collected, or (b) for legal or business purposes, including considering you for future opportunities. Under the PDPA, you have the right to request access to your personal data, to request that your personal data be rectified, and to withdraw your consent to the processing of your personal data. To exercise these rights or to withdraw your consent, you may contact the Controller’s data protection officer using the details above.

Please note that providing your personal data is necessary for us to evaluate your job application. If you do not provide the required personal data, or if you later withdraw your consent to its collection, use, or disclosure, the Controller will not be able to process your application, and your candidacy for employment will not be considered. For more information on how we handle personal data, please refer to our Privacy Policy at https://www.straitsx.com/legal/privacy-policy