Deskripsi Pekerjaan
Are you a seasoned offensive security expert looking to lead high-impact operations? We are seeking a Lead Security Engineer to anchor our Red Team & Threat Intelligence unit in Jakarta. In this strategic role, you will be at the forefront of identifying sophisticated attack vectors, simulating real-world threat actors, and hardening our infrastructure against evolving cyber risks.
As a key leader, you will collaborate with cross-functional teams to proactively discover vulnerabilities within cloud architectures, CI/CD pipelines, and identity management systems. You will translate complex threat intelligence data into actionable security improvements, effectively acting as an adversary to ensure our defenses are resilient, adaptive, and industry-leading.
Tanggung Jawab
- Lead and execute comprehensive red team exercises across multi-cloud and on-premise environments.
- Develop and maintain advanced offensive tooling to simulate TTPs (Tactics, Techniques, and Procedures) of modern threat actors.
- Analyze CI/CD pipeline security and provide mitigation strategies for supply chain attacks.
- Perform deep-dive penetration testing on endpoint and identity solutions (IAM/PAM).
- Transform threat intelligence feeds into proactive security controls and detection logic.
- Provide strategic security mentorship to internal engineering teams and incident responders.
- Author detailed technical reports and post-mortem analysis for executive leadership.
Kualifikasi
- 5+ years of professional experience in Red Teaming, Penetration Testing, or offensive security research.
- Deep understanding of cloud security (AWS, Azure, or GCP) and container orchestration security (Kubernetes).
- Strong proficiency in scripting languages such as Python, Go, or PowerShell for exploit development.
- Expertise in identifying and exploiting vulnerabilities in CI/CD pipelines and DevOps workflows.
- Solid experience with identity infrastructure, including Active Directory, OAuth, and SAML-based attacks.
- Relevant industry certifications (e.g., OSCP, OSEP, GXPN, or CRT) are highly desirable.
- Exceptional communication skills with the ability to explain high-level risk to technical and non-technical stakeholders.