Offensive Security Manager

indodax - indonesia digital asset exchange

Indonesia

On-site

IDR 30,000,000 - 50,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Indodax - Indonesia Digital Asset Exchange is seeking a seasoned professional in Product Security. You will manage the Product Security Engineers and lead initiatives such as Bug Bounty Management and Red Team campaigns to enhance security.

The ideal candidate requires over 7 years of experience in Information Security, with expertise in application security and risk communication. This position is crucial for ensuring the security of digital assets.

Qualifications

  • 7+ years in Information Security.
  • Hands-on experience with SQL injection.
  • Deep understanding of modern application stacks.

Responsibilities

  • Manage Product Security Engineers and ensure security reviews.
  • Oversee Bug Bounty Management.
  • Design and approve Red Team campaigns.

Skills

SQL injection
API security
Python
Risk communication

Education

7+ years in Information Security
3-4+ years as a Penetration Tester or Red Teamer

Tools

Qualys
Tenable

Job description

Responsibilities

Product Security (AppSec)

Secure SDLC: Manage the Product Security Engineers who work alongside developers. Ensure security reviews, threat models, and code scanning (SAST/DAST) happen before deployment.

Bug Bounty Management: Oversee the public or private Bug Bounty Program (e.g., HackerOne, Bugcrowd). Triage incoming reports, validate severity, and pay out researchers.

Developer Education: Move beyond "gatekeeping." Create a "Security Champions" program to train developers on how to write secure code (e.g., OWASP Top 10 prevention).

Red Teaming & Adversary Simulation

Campaign Management: Design and approve Red Team campaigns (e.g., "Simulate a ransomware attack starting from a phishing email to Finance"). Define the "Rules of Engagement" to ensure production systems aren't crashed.

Purple Teaming: Facilitate "Purple Team" exercises where your Red Team attacks and sits with the Blue Team (Defenders) to see if they can detect the attack in real-time.

Physical & Social Engineering: Authorize physical security tests (badge cloning, tailgating) and advanced spear-phishing campaigns to test human resilience.

Vulnerability Management

Prioritization Strategy: Stop the "patch everything" noise. Guide the Vulnerability Management Engineer to prioritize fixes based on exploitability (e.g., "Is there a public exploit available?" "Is this server internet-facing?").

SLA Enforcement: Act as the "bad guy" with IT and Engineering leadership when critical vulnerabilities are not patched within the agreed Service Level Agreement (SLA).

Asset Coverage: Ensure that scanners (Qualys/Tenable) are actually seeing 100% of the environment, including shadow IT and new cloud deployments.

Requirements
  • 7+ years in Information Security, with 3–4+ years as a Penetration Tester, Red Teamer, or AppSec Engineer; hands‑on ability to perform attacks like SQL injection or compromise Active Directory.
  • Application Security Fluency: Deep understanding of modern application stacks, including API security, micro services, and CI/CD pipelines.
  • Scripting & Automation: Proficient in Python, Go, or Bash for automating testing and security tools.
  • Leadership & Risk Communication: Ability to explain technical risks (e.g., XSS) in business terms to Product Managers or stakeholders.
  • Legal & Ethics Knowledge: Understanding of legal boundaries for ethical hacking (e.g., CFAA, safe harbor clauses).
  • Preferred Certifications: OSCP / OSCE (technical credibility), GWAPT / GPEN / GXPN (penetration testing), CISSP (management-focused).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Offensive Security Manager
Offensive Security Manager

INDODAX • Jakarta Selatan

On-site
Cyber Security Specialist
Cyber Security Specialist

Indivara Group • Indonesia

On-site
IDR 180,000,000 - 280,000,000
Penetration Tester
Penetration Tester

VLink Inc • Jakarta Pusat

On-site
IDR 300,000,000 - 600,000,000
Information Technology Security Engineer
Information Technology Security Engineer

PHINCON • Kota Bandung

On-site
IDR 180,000,000 - 320,000,000
Senior Penetration Tester - RA
Senior Penetration Tester - RA

Axonect • Jakarta Pusat

On-site
IDR 150,000,000 - 260,000,000
Senior Penetration Tester
Senior Penetration Tester

Asiatek Solusi Indonesia • Jakarta Pusat

On-site
IDR 600,000,000 - 900,000,000
Cybersecurity Engineer (Redteam)
Cybersecurity Engineer (Redteam)

Blibli • Jakarta Timur

On-site
IDR 525,210,000 - 875,351,000
Penetration Tester
Penetration Tester

Telkom Indonesia • Indonesia

On-site
IDR 300,000,000 - 600,000,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Paper • Jakarta Barat

On-site
IDR 700,000,000 - 1,100,000,000
IT CYBERSECURITY
IT CYBERSECURITY

Confidential • Jakarta Timur

On-site
IDR 200,880,000 - 357,120,000