Apply Mate

Apply
MateApply Mate
  • Pekerjaan
  • Talent
  • Karir Tools

Instal Apply Mate

Dapatkan akses cepat ke Apply Mate. Instal aplikasi kami untuk pengalaman yang lebih cepat dengan dukungan offline.

Apply Mate

Buat CV profesional dan surat lamaran yang sesuai dengan deskripsi pekerjaan tertentu.

Fitur

  • Buat CV
  • Buat Cover Letter
  • Skoring CV

Organisasi

  • Tentang Kami
  • Blog
  • Organisasi Kami

Akun

  • Masuk
  • Akun

© 2026 Apply Mate. All rights reserved.

Kebijakan PrivasiSyarat dan Ketentuan
  • Beranda
  • Tools
  • Lowongan
  • Artikel
  • Profil

Senior Offensive Security Engineer (Penetration Testing)

SMARTM2M Indonesia

Full-timeLamar Posisi Ini
KOTA BANDUNG, JAWA BARAT, IndonesiaSeniorIDR 25,000,000 - IDR 35,000,000Diposting Today

Deskripsi Pekerjaan

Job opportunity for Senior Offensive Security Engineer (Penetration Testing) at SMARTM2M Indonesia in KOTA BANDUNG, JAWA BARAT, Indonesia. Qualification: Responsibilities Plan, scope, and execute penetration tests following NIST SP 800-115 with formal authorization, Rules of Engagement, execution logs, and structured reporting plus retesting. Conduct web and API testing aligned to the OWASP Web Security Testing Guide with traceable test cases and coverage mapping for application and authentication/authorization flows. Structure engagements per PTES phases for consistency across pre-engagement, intelligence gathering, exploitation, post-exploitation, and reporting. Map techniques and findings to MITRE ATT&CK to support SOC/DFIR integration and detection engineering backlogs. Produce PCI-ready deliverables, including Rules of Engagement, segmentation testing where applicable, and evidence artifacts suitable for assessors. Write clear, prioritized remediation guidance with verification steps and retest results suitable for audits and leadership briefings. Collaborate with engineering and security stakeholders to align test scope with risk priorities and SDLC timing, leveraging OWASP guidance for application contexts. Minimum qualifications Demonstrated delivery of end-to-end penetration tests under NIST SP 800-115 and OWASP WSTG, including reporting and retesting workflows. One or more of the following certifications as a minimum: CEH, PNPT, CRTO, CRTP, or CPTS (or equivalent practical credential) to evidence hands-on capability across pentest or adversary tradecraft. Familiarity with PTES for engagement structure and with MITRE ATT&CK for technique mapping and narrative clarity. Ability to produce auditable artifacts suitable for PCI-aligned programs when required by clients. Preferred qualifications OSCP as the primary preferred credential for rigorous, hands-on penetration testing capability recognized by employers globally. Additional plus: GPEN or CREST CRT for methodology depth and external assurance signaling in regulated environments. Experience translating ATT&CK-mapped findings into detection use-cases and engineering backlogs with stakeholders.

Persyaratan

  • Responsibilities
  • Plan, scope, and execute penetration tests following NIST SP 800-115 with formal authorization, Rules of Engagement, execution logs, and structured reporting plus retesting.
  • Conduct web and API testing aligned to the OWASP Web Security Testing Guide with traceable test cases and coverage mapping for application and authentication/authorization flows.
  • Structure engagements per PTES phases for consistency across pre-engagement, intelligence gathering, exploitation, post-exploitation, and reporting.
  • Map techniques and findings to MITRE ATT&CK to support SOC/DFIR integration and detection engineering backlogs.
  • Produce PCI-ready deliverables, including Rules of Engagement, segmentation testing where applicable, and evidence artifacts suitable for assessors.
  • Write clear, prioritized remediation guidance with verification steps and retest results suitable for audits and leadership briefings.
  • Collaborate with engineering and security stakeholders to align test scope with risk priorities and SDLC timing, leveraging OWASP guidance for application contexts.
  • Minimum qualifications
  • Demonstrated delivery of end-to-end penetration tests under NIST SP 800-115 and OWASP WSTG, including reporting and retesting workflows.
  • One or more of the following certifications as a minimum: CEH, PNPT, CRTO, CRTP, or CPTS (or equivalent practical credential) to evidence hands-on capability across pentest or adversary tradecraft.
  • Familiarity with PTES for engagement structure and with MITRE ATT&CK for technique mapping and narrative clarity.
  • Ability to produce auditable artifacts suitable for PCI-aligned programs when required by clients.
  • Preferred qualifications
  • OSCP as the primary preferred credential for rigorous, hands-on penetration testing capability recognized by employers globally.
  • Additional plus: GPEN or CREST CRT for methodology depth and external assurance signaling in regulated environments.
  • Experience translating ATT&CK-mapped findings into detection use-cases and engineering backlogs with stakeholders.

Skill Diperlukan

CybersecurityPenetration testingCertified Information Security Manager (CISM)Information SecurityNetwork SecuritySecurity Audit

Bagikan pekerjaan ini

Share on LinkedInShare on WhatsApp

Ingin peluang lebih besar?

Cek kecocokan CV dengan lowongan iniBuat Cover Letter Sesuai LowonganOptimalkan CV untuk lowongan ini

Informasi Perusahaan

Perusahaan

SMARTM2M Indonesia

Website

Kunjungi Website

Kontak

[email protected]

Untuk meningkatkan peluang Anda terpilih:

  • Tonjolkan pengalaman yang relevan dengan jelas.
  • Sesuaikan CV Anda khusus untuk Senior Offensive Security Engineer (Penetration Testing).
  • Jaga agar resume tetap ringkas (1-2 halaman).
  • Periksa kembali tata bahasa dan format.
  • Pertimbangkan menggunakan Skoring CV Apply-Mate sebelum melamar.

Pertanyaan Umum

Pekerjaan Terkait

Cybersecurity Engineer

PT. Global Infotech Solution

Full-time
KOTA ADM. JAKARTA PUSAT, DKI JAKARTA, IndonesiaEntryIDR 7,000,000 - IDR 9,000,0003 weeks ago

Job opportunity for Cybersecurity Engineer at PT. Global Infotech Solution in KOTA ADM. JAKARTA PUSAT, DKI JAKARTA, Indonesia. Qualification: Global Infotech Solution, established since 2015, is a leading IT services provider serving over 300 customers across diverse industries. With a strong foundation of 70 industry partners and 150 team members, we pride ourselves on driving #LimitlessInnovation. Our commitment to sustainability is underscored by our EcoVadis certification, and we continuously innovate with solutions like Armmada and SoftPOS to meet the digital age's evolving needs. As we expand our cybersecurity capabilities, we seek a talented Cybersecurity Engineer to join our team. Experience Minimum 2–5 years of experience in IT Security, Cybersecurity, or Network Security. Experience in security monitoring, vulnerability assessment, and incident response. Hands-on experience managing firewalls, IDS/IPS, SIEM, and endpoint security systems. Technical Skills Strong understanding of network security, penetration testing, and risk assessment. Proficiency in Linux and Windows Server administration. Solid knowledge of networking protocols such as TCP/IP, DNS, VPN, and SSL/TLS. Experience with security tools such as: SIEM platforms (e.g., Splunk, IBM QRadar) Vulnerability scanners (e.g., Nessus, OpenVAS) Familiarity with cloud security (AWS, Azure, or GCP) is a plus. Understanding of security standards and frameworks such as ISO/IEC 27001 and NIST Cybersecurity Framework. Qualification: We are seeking a male candidate with a Bachelor's degree and between 3 to 5 years of experience in cybersecurity, including proficiency in penetration testing, network security, IT security, and information security. While we value the skills mentioned, we welcome applications from individuals who bring a unique perspective and passion for cybersecurity. Join us at Global Infotech Solution, where your expertise will contribute to our mission of continuous innovation and growth. Certifications (Preferred) Relevant certifications such as: Certified Information Systems Security Professional (CISSP) Certified Ethical Hacker (CEH) CompTIA Security+ Deadline of application on April, 2026. Only candidates who meet these qualifications will be contacted

CybersecurityPenetration testingInformation SecurityNetwork SecuritySecurity Audit

Product Support Engineer

PT Optima Solusindo Informatika

Full-time
KOTA ADM. JAKARTA BARAT, DKI JAKARTA, IndonesiaEntryIDR 5,500,000 - IDR 7,000,0003 days ago

Job opportunity for Product Support Engineer at PT Optima Solusindo Informatika in KOTA ADM. JAKARTA BARAT, DKI JAKARTA, Indonesia. Qualification: Qualifications: Minimum of a Diploma in Information Technology or a related field. 1–2 years of experience in a technical product role. Fresh graduates with relevant internship experience are also encouraged to apply. Solid understanding of cybersecurity concepts such as Anti-Virus, Data Backup, and IT Security. Strong technical aptitude, quick learner, self-motivated, and collaborative team member Roles & Responsibilities: Conduct product presentations, proof of concept (POC) demonstrations, and troubleshooting for clients. Perform product implementation for solutions such as Anti-Virus, Backup, Security, Linux, and Privileged Access Management (PAM). Provide technical support to partners and clients.

LinuxNetworkingCybersecuritykali linuxInformation Security+1 Lainnya

Pentester Internship

PT Widya Adijaya Nusantara (Widya Security)

Internship
Kabupaten Sleman, DI Yogyakarta, IndonesiaEntryCompetitive2 weeks ago

Job opportunity for Pentester Internship at PT Widya Adijaya Nusantara (Widya Security) in Kabupaten Sleman, DI Yogyakarta, Indonesia. Qualification: Jobdesk : Menentukan proses scoping pengujian keamanan (web, mobile, API, network, cloud, internal/external) Menyusun dan menegakkan Rules of Engagement (RoE) serta metodologi pengujian (black box, gray box, white box) Berkoordinasi dengan stakeholder (klien, engineering, product, infra) untuk memahami aset dan tujuan pengujian Melakukan advanced penetration testing & exploitation pada: Web Application Mobile Application (Android/iOS) API Network & Infrastructure Cloud Environment 5. Melakukan simulasi real-world attack scenario, seperti: Phishing simulation Credential harvesting Lateral movement & pivoting Command & Control (C2) scenario 6. Menganalisis tingkat risiko, dampak bisnis, dan kemungkinan eksploitasi dari setiap temuan 7. Menyusun laporan penetration testing yang komprehensif (Executive Summary & Technical Report) 8. Memberikan rekomendasi mitigasi yang realistis, aplikatif, dan sesuai kondisi sistem 9. Melakukan presentasi hasil temuan kepada klien atau stakeholder internal 10. Menjadi mentor / reviewer bagi pentester junior (code review, methodology review, report review) 11. Mengikuti perkembangan terbaru terkait vulnerability, exploit, dan tren keamanan siber Kualifikasi: Mahasiswa aktif & fresh graduate Memahami secara mendalam Cyber Security Fundamentals (Networking, OS, TCP/IP, HTTP/HTTPS) Menguasai Web & API Security, terutama OWASP Top 10 Familiar dengan standar & metodologi: PTES OWASP Testing Guide NIST / MITRE ATT&CK 7. Menguasai tools keamanan seperti: Burp Suite, Nmap, Metasploit SQLmap, Nikto, Gobuster, ffuf Hydra, John the Ripper, Hashcat 8. Memiliki kemampuan scripting (Python, Bash, atau JavaScript) untuk automation & custom exploit 9. Memiliki kemampuan analisis, problem solving, dan dokumentasi yang sangat baik 10. Mampu berkomunikasi teknis maupun non-teknis dengan jelas

CybersecurityPenetration testingInformation SecurityNetwork Security

VP of Information Security

Pt Tilaka Nusa Teknologi

Full-time
Kota Jakarta Barat, DKI Jakarta, IndonesiaEntryCompetitive2 weeks ago

Job opportunity for VP of Information Security at Pt Tilaka Nusa Teknologi in Kota Jakarta Barat, DKI Jakarta, Indonesia. Qualification: Job Qualifications: Lulusan S1 dari Teknik Informatika/Sistem Informasi/Teknologi Informasi Minimal 5–7 tahun pengalaman di bidang Information Security Minimal 2–3 tahun pengalaman dalam posisi leadership / managerial Berpengalaman terlibat dalam audit eksternal dan audit regulator Memiliki rekam jejak dalam membangun atau meningkatkan security posture organisasi Kompetensi & Soft Skills Analytical thinking dan risk-based mindset yang kuat Komunikatif, mampu menjelaskan isu teknis kepada Direksi, regulator, dan tim teknis Keseimbangan antara strategic planning dan technical execution Mampu bekerja secara kolaboratif lintas fungsi (Technology, Product, Compliance, Business) Memiliki leadership yang kuat, khususnya dalam situasi krisis dan incident response Sertifikasi Profesional (Mandatory) Wajib memiliki salah satu sertifikasi berikut (lebih diutamakan jika memiliki lebih dari satu): * CISM (Certified Information Security Manager) * CISA (Certified Information Systems Auditor) * CISSP (Certified Information Systems Security Professional) * CCISO * Security X * GISP Job Descriptions: Menyusun dan mengeksekusi strategi keamanan informasi perusahaan Menjamin kepatuhan terhadap regulasi dan standar internasional Mengelola audit internal dan eksternal Mengawasi security architecture dan security operations Memimpin incident response dan penguatan security control Memberikan laporan berkala kepada Direksi terkait risiko dan posture keamanan perusahaan Job Qualifications: Kompetensi Framework & Governance Memiliki pemahaman mendalam dan pengalaman implementasi terhadap: * ISO/IEC 27001 (ISMS) * ISO/IEC 27701 (PIMS) * NIST Cybersecurity Framework * NIST SP 800 Series * Risk Management Framework * Security policy development dan audit management * Regulatory compliance readiness dan audit handling Kompetensi Teknis Memiliki latar belakang teknis yang kuat dan pengalaman langsung pada area berikut: * Network Security * Application Security * Cloud Security * Vulnerability Management * Incident Response * AI Security (nilai tambah) Kompetensi Spesifik Industri * Pengetahuan dan/atau pengalaman terkait Public Key Infrastructure (PKI) * Memahami lifecycle sertifikat elektronik * Memahami konsep cryptography, key management, dan penggunaan HSM * Pengalaman di industri regulated (Financial Services, Telco, CA/PSrE, Digital Identity) menjadi nilai tambah

Certified Information Systems Auditor (CISA)CybersecurityRisk ManagementVulnerability AssessmentRegulatory Compliance+2 Lainnya

Tier 1 SOC Analyst

PT Neotech Cakrawala Indonesia

Full-time
KOTA YOGYAKARTA, DAERAH ISTIMEWA YOGYAKARTA, IndonesiaEntryCompetitive3 weeks ago

Job opportunity for Tier 1 SOC Analyst at PT Neotech Cakrawala Indonesia in KOTA YOGYAKARTA, DAERAH ISTIMEWA YOGYAKARTA, Indonesia. Qualification: Job Description: Melakukan monitoring keamanan jaringan & sistem 24/7 Menganalisa dan menindaklanjuti insiden keamanan (incident response) Melakukan investigasi dan reporting terhadap security alert Berkoordinasi dengan tim IT terkait mitigasi risiko keamanan Requirements: Pendidikan minimal S1 Teknik Informatika / Sistem Informasi / sejenis Memahami konsep Cyber Security, SIEM, Firewall, IDS/IPS Pengalaman minimal 1 tahun sebagai SOC/IT Security (fresh graduate dipersilakan melamar jika memiliki skill relevan) Mampu bekerja dalam sistem shift Memiliki sertifikasi security menjadi nilai tambah

CybersecurityInformation SecurityNetwork Security

Security Analyst

PT Deptech Digital Indonesia

Contract
Kota Jakarta Barat, DKI Jakarta, IndonesiaEntryCompetitive3 weeks ago

Job opportunity for Security Analyst at PT Deptech Digital Indonesia in Kota Jakarta Barat, DKI Jakarta, Indonesia. Qualification: Qualification : 1. S1 (IT Related Major) 2. Pengalaman sebagai Security Analyst (2 - 3 tahun) 3. Pengalaman dengan Security Requirement terkait dengan Mobile Banking, Internet Banking, Internet Banking Bisnis 4. Pengalaman dengan aktivitas Penetration Testing, Vunerability Assessment terkait E-Channel (MB, IB, IBB, ATM, CMS, EDC, etc) dan memahami berbagai jenis temuan dan standard mitigasinya 5. Paham terkait berbagai macam security layer seperti Root and Jailbreak Detection, SSL Pinning, Code Obfuscation, Emulator Detection, Encryption, API dan Secret Key, Auth Token, 2FA, credential, HSM, code signing, Payload signing , payload encryption, rate limiter etc 6. Paham IT security standards such as ISO 27001, NIST, CIS Benchmark, atau internal IT security policies 7. Paham terkait Project Management, SDLC dan pengalaman menjalankan project terkait security 8. Pengalaman dengan Fraud Detection System 9. Update dengan tren Cyber Security modus 10. Memiliki sertifikasi security (seperti Certified Mobile Application Security Expert (CMASE) atau setara) dan pengalaman di MB IB / Channel 11. Technical Skills: 1. Project Management – Intermediate 2. Analytical, Critical Thinking & Problem Solving –Intermediate 3. Programming – Intermediate 4. Software QA – Intermediate 5. IT Banking Operation – Intermediate 6. Leadership & Decision Making – Intermediate 7. IT Risk Management – Intermediate. Job Desc : 1. Pelaksanaan Project di E-Channel terkait aplikasi (MB, IB, IBB, ATM, CMS, EDC, etc) khususnya pada part terkait Security pada tahap BRD, FSD, Development, SIT, UAT, Penetration Test, Vurnerability Assessment s/d Go Live 2. Aktivitas Annual Pentest rutin di E-Channel bersama dengan IT Security dan vendor pentest 3. Aktivitas terkait Audit, Review, Regulatory untuk aspek2 security di E-Channel bekerjasama dengan IT Security 4. Analisa case Fraud, anomali FDS dsb bekerjasama dengan AFM dan IT Security 5. Review/ assessment terhadap new requirement terkait secuirty policies baik dari Appstore/ playstore, Audit, QA, OJK, BI, Regulatory lainnya 6. Threat Monitoring , monitor terhadap threat2 yang masuk baik dari SLA Report, tools monitoring security lainnya 7. Support terhadap seluruh aktivitas / kebutuhan IT Security yang terkait dengan E-Channel 8. Melakukan dokumentasi2 yang dibutuhkan terkait kebutuhan sertifikasi seperti ISO ataupun Assessment lainnya 9. Melakukan Review terhadap hasil source code review dari vendor 10. Handle Issue2 production dan analisa hubungannya terkait dengan security jika ada 11. Monitoring terhadap update dari security library dan tindak lanjut untuk project impelementasinya

AzureTOGAFAmazon Web Services (AWS)Zero Trust ArchitectureNist Csf+15 Lainnya

Rekomendasi Career Tools

Tingkatkan peluang lamaranmu dengan tools profesional ini.

Template CV Profesional (Word) – ATS Friendly & Editable | CV Single Page #45 - 3 Colours

Template CV Profesional (Word) – ATS Friendly & Editable | CV Single Page #45 - 3 Colours

Productivity ToolsResume Templates
Rp 1.199

Template CV siap pakai yang bisa langsung kamu edit menggunakan Microsoft Word. Dirancang dengan layout yang rapi dan mudah dibaca, template ini membantu kamu membuat CV lebih profesional tanpa perlu desain dari nol. Cukup ganti isi sesuai data kamu, dan CV sudah siap digunakan untuk melamar kerja. ✨ Fitur: - Format .DOCX (Microsoft Word) - Mudah diedit (tanpa skill desain) - Layout rapi & profesional - ATS Friendly (mudah dibaca HR) - Siap kirim untuk berbagai kebutuhan 🎯 Cocok untuk: - Fresh graduate - Job seeker - Profesional - Penggunaan umum 📌 Keunggulan: - Hemat waktu - Tidak perlu desain ulang - Fokus ke isi CV

Template CV Profesional (Word) – ATS Friendly & Editable | CV Single Page #44 - 3 Colours

Template CV Profesional (Word) – ATS Friendly & Editable | CV Single Page #44 - 3 Colours

Productivity ToolsResume Templates
Rp 1.199

Template CV siap pakai yang bisa langsung kamu edit menggunakan Microsoft Word. Dirancang dengan layout yang rapi dan mudah dibaca, template ini membantu kamu membuat CV lebih profesional tanpa perlu desain dari nol. Cukup ganti isi sesuai data kamu, dan CV sudah siap digunakan untuk melamar kerja. ✨ Fitur: - Format .DOCX (Microsoft Word) - Mudah diedit (tanpa skill desain) - Layout rapi & profesional - ATS Friendly (mudah dibaca HR) - Siap kirim untuk berbagai kebutuhan 🎯 Cocok untuk: - Fresh graduate - Job seeker - Profesional - Penggunaan umum 📌 Keunggulan: - Hemat waktu - Tidak perlu desain ulang - Fokus ke isi CV

Template CV Profesional (Word) – ATS Friendly & Editable | CV Single Page #43 - 3 Colours

Template CV Profesional (Word) – ATS Friendly & Editable | CV Single Page #43 - 3 Colours

Productivity ToolsResume Templates
Rp 1.199

Template CV siap pakai yang bisa langsung kamu edit menggunakan Microsoft Word. Dirancang dengan layout yang rapi dan mudah dibaca, template ini membantu kamu membuat CV lebih profesional tanpa perlu desain dari nol. Cukup ganti isi sesuai data kamu, dan CV sudah siap digunakan untuk melamar kerja. ✨ Fitur: - Format .DOCX (Microsoft Word) - Mudah diedit (tanpa skill desain) - Layout rapi & profesional - ATS Friendly (mudah dibaca HR) - Siap kirim untuk berbagai kebutuhan 🎯 Cocok untuk: - Fresh graduate - Job seeker - Profesional - Penggunaan umum 📌 Keunggulan: - Hemat waktu - Tidak perlu desain ulang - Fokus ke isi CV

Lihat Semua Tool

Artikel Terkait

Cara Mencari Pekerjaan yang Benar-Benar Cocok dengan Resume Kamu

Indonesia

Cara Mencari Pekerjaan yang Benar-Benar Cocok dengan Resume Kamu

Bagaimana cara menemukan pekerjaan yang benar-benar sesuai dengan resume kamu, sehingga peluang dipanggil interview bisa meningkat secara signifikan.

Alat Bertenaga AI

Bertenaga AIHasil Instan

Login untuk membuka fitur AI

Bagikan pekerjaan ini

Share on LinkedInShare on WhatsApp

Ingin peluang lebih besar?

Cek kecocokan CV dengan lowongan iniBuat Cover Letter Sesuai LowonganOptimalkan CV untuk lowongan ini

Informasi Perusahaan

Perusahaan

SMARTM2M Indonesia

Website

Kunjungi Website

Kontak

[email protected]