Job Openings Senior Penetration Tester - RA

About the job Senior Penetration Tester - RA

Overview

The Senior Penetration Tester will lead end-to-end security engagements across web applications, APIs, mobile platforms, internal networks, and cloud infrastructure. This role is responsible for executing technical scoping, hands-on penetration testing, manual exploit validation, and retesting. Beyond identifying vulnerabilities, you will deliver actionable, prioritized remediation guidance for engineering teams while mentoring junior security assessors through report reviews, internal playbook development, and continuous knowledge sharing.

Key Responsibilities

  • Leadership: Lead technical scoping, establish Rules of Engagement (RoE) with stakeholders, and execute end-to-end assessments independently
  • Hands-on Penetration Testing: Perform deep-dive assessments on Web, Mobile (Android/iOS), API (REST/GraphQL), Network, Active Directory, and Cloud/Container environments with manual validation to eliminate false positives
  • Reporting & Deliverables: Produce clear, two-tiered reports consisting of an Executive Summary for leadership and reproducible technical details with prioritized remediation steps for developers
  • Debriefs & Stakeholder Communication: Lead debrief sessions, presenting complex technical findings effectively to both non-technical business leaders and technical engineering teams
  • Remediation & Retesting: Conduct retests to verify fix effectiveness and ensure long-term risk mitigation
  • Capability Development & Mentoring: Drive continuous improvement by building internal tooling, refining checklists/playbooks, and mentoring junior team members

Person Specifications

  • Minimum 5 years of experience in offensive security, OR 7 years in general cybersecurity with at least 4 years exclusively focused on penetration testing
  • Proven experience independently managing critical engagements within high-risk sectors (Financial Services, Telecommunications, E-Commerce, or Government)
  • Web & API: In-depth knowledge of OWASP Top 10 and WSTG. Expertise in testing authentication/authorization flaws, IDOR, SSRF, insecure deserialization, business logic bugs, and API vulnerabilities (REST & GraphQL batching/introspection abuse)
  • Mobile Security: Deep knowledge of OWASP MASTG. Hands-on experience with static/dynamic analysis on Android & iOS, including client-side security bypasses
  • Scripting & Tooling: Proficient in Python, Bash, or PowerShell (Go or C# is a plus). Ability to modify PoCs and build custom scripts rather than relying solely on automated scanners
  • Standards & Compliance: Familiarity with PTES, OSSTMM, NIST SP 800-115, MITRE ATT&CK, CVSS v3.1/v4.0, PCI DSS, ISO 27001, as well as Indonesian regulations (POJK/SEOJK and UU PDP)
  • Preferred Certification (Practical/Hands-on): OSCP (Primary), paired with OSEP, OSWE, GPEN, GWAPT, CRTO, or CREST CRT
  • Bonus / Advanced: OSCE³, GXPN, CARTP/CARTS, eWPTX, or GMOB
  • Complementary: CEH, CompTIA PenTest+

Vendor submissions - 06 months