Offensive Security Manager

INDODAX

Jakarta Selatan

On-site

IDR 279,000,000 - 446,400,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

INDODAX is looking for a Product Security Lead to manage security engineers and oversee various security initiatives, from bug bounty programs to Red Team exercises. Candidates should have a strong background in Information Security and hands-on experience in application security and penetration testing.

The ideal applicant will bring over 7 years in the field, with proven capabilities in leading security assessments and communicating risks effectively within teams.

Qualifications

  • Deep understanding of modern application stacks, including API security.
  • Hands-on ability to perform attacks like SQL injection.
  • Understanding of legal boundaries for ethical hacking.

Responsibilities

  • Manage the Product Security Engineers.
  • Oversee the Bug Bounty Program.
  • Design and approve Red Team campaigns.

Skills

Penetration Testing
Application Security
Scripting
Risk Communication
Vulnerability Management

Education

7+ years in Information Security
3–4+ years as a Penetration Tester, Red Teamer, or AppSec Engineer

Tools

Qualys
Tenable
Python
Go
Bash

Job description

1. Product Security (AppSec)

Secure SDLC: Manage the Product Security Engineers who work alongside developers. Ensure security reviews, threat models, and code scanning (SAST/DAST) happen before deployment.

Bug Bounty Management: Oversee the public or private Bug Bounty Program (e.g., HackerOne, Bugcrowd). Triage incoming reports, validate severity, and pay out researchers.

Developer Education: Move beyond "gatekeeping." Create a "Security Champions" program to train developers on how to write secure code (e.g., OWASP Top 10 prevention).

2. Red Teaming & Adversary Simulation

Campaign Management: Design and approve Red Team campaigns (e.g., "Simulate a ransomware attack starting from a phishing email to Finance"). Define the "Rules of Engagement" to ensure production systems aren't crashed.

Purple Teaming: Facilitate "Purple Team" exercises where your Red Team attacks and sits with the Blue Team (Defenders) to see if they can detect the attack in real-time.

Physical & Social Engineering: Authorize physical security tests (badge cloning, tailgating) and advanced spear-phishing campaigns to test human resilience.

3. Vulnerability Management

Prioritization Strategy: Stop the "patch everything" noise. Guide the Vulnerability Management Engineer to prioritize fixes based on exploitability (e.g., "Is there a public exploit available?" "Is this server internet-facing?").

SLA Enforcement: Act as the "bad guy" with IT and Engineering leadership when critical vulnerabilities are not patched within the agreed Service Level Agreement (SLA).

Asset Coverage: Ensure that scanners (Qualys/Tenable) are actually seeing 100% of the environment, including shadow IT and new cloud deployments.

  • 7+ years in Information Security, with 3–4+ years as a Penetration Tester, Red Teamer, or AppSec Engineer; hands-on ability to perform attacks like SQL injection or compromise Active Directory.
  • Application Security Fluency: Deep understanding of modern application stacks, including API security, micro services, and CI/CD pipelines.
  • Scripting & Automation: Proficient in Python, Go, or Bash for automating testing and security tools.
  • Leadership & Risk Communication: Ability to explain technical risks (e.g., XSS) in business terms to Product Managers or stakeholders.
  • Legal & Ethics Knowledge: Understanding of legal boundaries for ethical hacking (e.g., CFAA, safe harbor clauses).
  • Preferred Certifications: OSCP / OSCE (technical credibility), GWAPT / GPEN / GXPN (penetration testing), CISSP (management-focused).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Specialist
Cyber Security Specialist

Indivara Group • Indonesia

On-site
IDR 180,000,000 - 280,000,000
Penetration Tester
Penetration Tester

VLink Inc • Jakarta Pusat

On-site
IDR 300,000,000 - 600,000,000
Information Technology Security Engineer
Information Technology Security Engineer

PHINCON • Kota Bandung

On-site
IDR 180,000,000 - 320,000,000
Cybersecurity Engineer (Redteam)
Cybersecurity Engineer (Redteam)

Blibli • Jakarta Timur

On-site
IDR 525,210,000 - 875,351,000
Penetration Tester
Penetration Tester

Lancesoft Indonesia • Jakarta Pusat

On-site
IDR 400,000,000 - 700,000,000
Penetration Tester
Penetration Tester

Telkom Indonesia • Indonesia

On-site
IDR 300,000,000 - 600,000,000
Senior Penetration Tester
Senior Penetration Tester

Asiatek Solusi Indonesia • Jakarta Pusat

On-site
IDR 600,000,000 - 900,000,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Paper • Jakarta Barat

On-site
IDR 700,000,000 - 1,100,000,000
IT CYBERSECURITY
IT CYBERSECURITY

Confidential • Jakarta Timur

On-site
IDR 200,880,000 - 357,120,000
Analyst IT Resilience, Security & Sustainability (Blue Team)
Analyst IT Resilience, Security & Sustainability (Blue Team)

Medco E&P Indonesia • Jakarta Pusat

On-site
IDR 300,000,000 - 600,000,000