Turn this role into an interview — a resume and cover letter built around what this employer wants.
Phintraco Consulting (PhinCon) is seeking security-focused professionals to perform penetration testing and red teaming on internal applications. You will map risks from dependencies and validate findings to drive mitigations.
Responsibilities include secure SDLC reviews, detailed reporting, and governance guidance based on CIS Controls, ISO27001, OWASP, PTES, and NIST frameworks. Phintraco Consulting is a trusted Oracle partner in Indonesia.
Bachelor’s Degree in Software Engineering / Computer Science / Information Technology / equivalent or relevant work experience.
Good at managing sensitive and confidential data, workstation devices, patching and upgrading systems, applications, services, and other infrastructure foundational components.
Familiar with ISO27001
Familiar with Linux and Windows OS
Familiar with cloud security services such as AWS, Azure, and GCP
Able to create some script, i.e., bash, python
Having certification in cloud security area is a plus
Penetration Testing & Red Teaming: Conducted attack simulations and red teaming activities on internal applications to identify critical security vulnerabilities (e.g., SQLi, XSS, brute force, authorization flaws) and developed PoCs detailing technical and business impacts.
Dependency Analysis & Validation: Identified and analyzed over 100 packages/dependencies per application using CVE databases, GHSA, and CVSS score metrics to map third-party component risks.
False Positive Elimination: Performed manual source code reviews and manual exploit replications based on CVEs to ensure vulnerabilities were true positives, optimizing mitigation priorities.
Secure SDLC Implementation: Executed security reviews and rigorous testing for every feature addition or application change prior to production deployment.
Reporting & Cross-Divisional Collaboration: Authored detailed penetration testing reports (findings, risk levels, mitigations) and presented them to both technical teams and non-technical management in clear, accessible language.
Security Standards Consultation: Provided architecture and security governance compliance recommendations based on CIS Controls, ISO 27001, OWASP, PTES, and NIST SP 800-115 frameworks.
Phintraco Consulting (PhinCon), a member of Phintraco Group, is an Information Technology (IT) consulting and services company, specializing in Customer Relationship Management (CRM) and Middleware solutions as well as related services.
Currently we are recognized as the Oracle Certified Partner in Indonesia for Oracle Siebel CRM and Oracle Fusion Middleware products. We are committed to continue our supports and improve our operations to become more sustainable. With our proven methodology and approach combined with knowledgeable and experienced consultants, we believe that we can bring substantial benefits to our customers.
Phintraco Consulting (PhinCon), a member of Phintraco Group, is an Information Technology (IT) consulting and services company, specializing in Customer Relationship Management (CRM) and Middleware solutions as well as related services.
Currently we are recognized as the Oracle Certified Partner in Indonesia for Oracle Siebel CRM and Oracle Fusion Middleware products. We are committed to continue our supports and improve our operations to become more sustainable. With our proven methodology and approach combined with knowledgeable and experienced consultants, we believe that we can bring substantial benefits to our customers.
To help fast track investigation, please include here any other relevant details that prompted you to report this job ad as fraudulent / misleading / discriminatory / salary below minimum wage.
Researching careers? Find all the information and tips you need on career advice.