Offensive Security Manager

INDODAX - Indonesia Digital Asset Exchange

Jakarta Pusat

On-site

IDR 900,000,000 - 1,500,000,000

Full time

34 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

INDODAX - Indonesia Digital Asset Exchange is seeking a seasoned Information Security Lead to oversee product security, bug bounty programs, and red team/adversary simulation initiatives in Jakarta. You will drive secure coding practices, threat modeling, and proactive vulnerability management.

The role requires deep technical expertise in API security, CI/CD, and incident response, with a track record of translating risk into business terms for stakeholders and management.

Qualifications

  • Minimum S1 IT/Computer Science or equivalent.
  • 7+ years in information security with 3–4+ years as Penetration Tester/Red Teamer/AppSec Engineer; hands-on attack skills (e.g., SQL injection, AD compromise).
  • Deep understanding of modern application stacks, including API security, microservices, and CI/CD pipelines.

Responsibilities

  • Secure SDLC: lead Product Security Engineers, run security reviews, threat modeling, and code scanning (SAST/DAST) before deployment.
  • Bug bounty management: oversee bug bounty programs (HackerOne/Bugcrowd), triage reports, validate severity, pay researchers.
  • Developer education: create a Security Champions program to train developers on secure coding (OWASP Top 10).
  • Red Teaming & adversary simulation: design red team campaigns, define rules of engagement, conduct purple team exercises with blue team.
  • Vulnerability management: prioritize fixes by exploitability, enforce SLAs, ensure scanners cover the environment.

Skills

Penetration Testing
Red Teaming
AppSec / Secure Coding
Threat Modeling
Security Auditing
SLA & Risk Communication
Legal & Ethics Knowledge
Scripting & Automation

Education

Bachelor's degree in Information Technology / Computer Science

Tools

HackerOne
Bug bounty platforms
SAST/DAST tools
OWASP ZAP

Job description

Responsibilities
  • Product Security (AppSec)

    Secure SDLC: Manage the Product Security Engineers who work alongside developers. Ensure security reviews, threat models, and code scanning (SAST/DAST) happen before deployment.

  • Bug Bounty Management

    Oversee the public or private Bug Bounty Program (e.g., HackerOne, Bugcrowd). Triage incoming reports, validate severity, and pay out researchers.

  • Developer Education

    Move beyond \"gatekeeping.\" Create a \"Security Champions\" program to train developers on how to write secure code (e.g., OWASP Top 10 prevention).

  • Red Teaming & Adversary Simulation

    Campaign Management: Design and approve Red Team campaigns (e.g., \"Simulate a ransomware attack starting from a phishing email to Finance\"). Define the \"Rules of Engagement\" to ensure production systems aren't crashed.

    Purple Teaming: Facilitate \"Purple Team\" exercises where your Red Team attacks and sits with the Blue Team (Defenders) to see if they can detect the attack in real-time.

    Physical & Social Engineering: Authorize physical security tests (badge cloning, tailgating) and advanced spear-phishing campaigns to test human resilience.

  • Vulnerability Management

    Prioritization Strategy: Stop the \"patch everything\" noise. Guide the Vulnerability Management Engineer to prioritize fixes based on exploitability (e.g., \"Is there a public exploit available?\" \"Is this server internet-facing?\").

    SLA Enforcement: Act as the \"bad guy\" with IT and Engineering leadership when critical vulnerabilities are not patched within the agreed Service Level Agreement (SLA).

    Asset Coverage: Ensure that scanners (Qualys/Tenable) are actually seeing 100% of the environment, including shadow IT and new cloud deployments.

Requirements
  • Min. S1 Teknik Informatika/System Komputer/atau yang sejenis
  • 7+ years in Information Security, with 3–4+ years as a Penetration Tester, Red Teamer, or AppSec Engineer; hands-on ability to perform attacks like SQL injection or compromise Active Directory.
  • Application Security Fluency: Deep understanding of modern application stacks, including API security, micro services, and CI/CD pipelines.
  • Scripting & Automation: Proficient in Python, Go, or Bash for automating testing and security tools.
  • Leadership & Risk Communication: Ability to explain technical risks (e.g., XSS) in business terms to Product Managers or stakeholders.
  • Legal & Ethics Knowledge: Understanding of legal boundaries for ethical hacking (e.g., CFAA, safe harbor clauses).
  • Preferred Certifications: OSCP / OSCE (technical credibility), GWAPT / GPEN / GXPN (penetration testing), CISSP (management-focused).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Offensive Security Manager
Offensive Security Manager

INDODAX • Jakarta Selatan

On-site
Security Engineer
Security Engineer

MateCareer • Kota Bandung

On-site
IDR 167,400,000 - 312,480,000
Senior Penetration Tester
Senior Penetration Tester

Asiatek Solusi Indonesia • Jakarta Pusat

On-site
IDR 600,000,000 - 900,000,000
IT Security Specialist
IT Security Specialist

Bank Mega • Indonesia

On-site
IDR 180,000,000 - 360,000,000
IT Security
IT Security

Esha Parama Technology • Daerah Khusus Ibukota Jakarta

On-site
IDR 180,000,000 - 300,000,000
Application Security Engineer
Application Security Engineer

MateCareer • Jakarta Pusat

On-site
IDR 223,200,000 - 502,200,000
IT SECURITY
IT SECURITY

PT INDOSAKU DIGITAL TEKNOLOGI • Tangerang Selatan

On-site
IDR 120,000,000 - 240,000,000
Penetration Tester
Penetration Tester

Lancesoft Indonesia • Jakarta Pusat

On-site
IDR 400,000,000 - 700,000,000
Penetration Tester (Red Team)
Penetration Tester (Red Team)

PT ASABA Digital Innotech • Jakarta Selatan

On-site
IDR 180,000,000 - 240,000,000
Cloud Security Engineer
Cloud Security Engineer

PT Sentra Vidya Utama (SEVIMA) • Surabaya ꦱꦸꦫꦧꦪ

On-site
IDR 167,400,000 - 390,600,000