Penetration Tester

VLink Inc

Jakarta Pusat

On-site

IDR 300,000,000 - 600,000,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

VLink Inc is seeking an experienced Security Engineer focused on offensive security and penetration testing across web apps, APIs, mobile platforms, and cloud ecosystems. You will perform recon, manual and automated testing, and deliver detailed risk-based reports with remediation steps.

The role requires 5+ years in offensive security, strong knowledge of OWASP Top 10, and hands-on experience with Nessus, Burp Suite, Metasploit, and related tooling.

Qualifications

  • Bachelor’s degree in CS/IT/Cybersecurity or related field.
  • Minimum 5 years of professional offensive security experience.
  • Strong knowledge of OWASP Top 10 and security testing methodologies.

Responsibilities

  • Perform end-to-end penetration testing across web apps, APIs, mobile platforms, networks, cloud, and core systems.
  • Conduct recon and validation to gather intelligence while minimizing false positives.
  • Deliver detailed reports with root cause analyses, CVSS scores, and remediation guidance.
  • Collaborate with developers, IT, and PMO to validate fixes and retest.
  • Mentor juniors and contribute to internal tooling and playbooks.

Skills

Python
Bash
PowerShell
Analytical thinking
Communication skills

Education

Bachelor’s Degree in Computer Science/Information Technology/Cybersecurity

Tools

Nessus
OpenVAS
Burp Suite
Metasploit

Job description

  • Perform end-to-end penetration testing and vulnerability assessments across web applications, APIs, mobile platforms (iOS & Android), internal networks, cloud infrastructure, and core systems.
  • Conduct initial reconnaissance and manual validation to gather intelligence on target assets, domains, IP addresses, and underlying technology stacks while minimizing false positives.
  • Execute automated and manual system scanning using industry-standard tools (e.g., Nessus, OpenVAS, Burp Suite, Metasploit) to uncover complex vulnerabilities, authentication/authorization flaws, IDOR, SSRF, and business logic errors.
  • Evaluate privilege escalation paths (Windows and Linux), lateral movement, Active Directory attacks (Kerberoasting, delegation abuse, ACL abuse), cloud misconfigurations (AWS, Azure, GCP), and container/Kubernetes security.
  • Deliver comprehensive, two-layered technical reports detailing vulnerabilities, root cause analyses, associated business risks, CVSS scoring, and prioritized remediation strategies.
  • Collaborate directly with application developers, IT management, and PMO teams to validate fixes, conduct retests, and optimize application security practices.
  • Mentor junior team members through report reviews, playbook creation, and knowledge sharing while building internal tooling and modifying proof-of-concept exploits.
  • Stay updated on modern exploitation techniques, emerging threat vectors, adversary emulation, and evolving security frameworks.

Qualifications & Requirements

  • Minimum of a Bachelor’s Degree (S1) in Computer Science, Information Technology, Cybersecurity, Computer Engineering, or a related field.
  • Minimum of 5 years of professional experience in offensive security
  • Strong mastery of OWASP Top 10, WSTG, MASTG, PTES, OSSTMM, and NIST guidelines.
  • Hands-on expertise across Web, APIs, Mobile (iOS/Android static/dynamic analysis), Network Infrastructure, Cloud, and Containers.
  • Proficiency in scripting languages such as Python, Bash, and PowerShell (Go or C# are a plus).
  • Strong knowledge of network security protocols, system architectures, and risk scoring standards (CVSS v3.1/v4.0).
  • Excellent analytical, problem-solving, and communication skills to articulate technical risks to both technical and non-technical stakeholders.
  • High ethical standards, strict discipline regarding testing scopes, and readiness to handle high-risk or production-window environments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

Telkom Indonesia • Indonesia

On-site
IDR 300,000,000 - 600,000,000
Penetration Tester
Penetration Tester

Lancesoft Indonesia • Jakarta Pusat

On-site
IDR 400,000,000 - 700,000,000
Senior Penetration Tester
Senior Penetration Tester

Asiatek Solusi Indonesia • Jakarta Pusat

On-site
IDR 600,000,000 - 900,000,000
Penetration Tester (Red Team)
Penetration Tester (Red Team)

PT ASABA Digital Innotech • Jakarta Selatan

On-site
IDR 180,000,000 - 240,000,000
Senior Penetration Tester - Offensive Security Architect
Senior Penetration Tester - Offensive Security Architect

VLink Inc • Jakarta Pusat

On-site
IDR 300,000,000 - 600,000,000
Information Technology Security Engineer
Information Technology Security Engineer

PHINCON • Kota Bandung

On-site
IDR 180,000,000 - 320,000,000
Offensive Security Manager
Offensive Security Manager

INDODAX • Jakarta Selatan

On-site
Cyber Security Specialist
Cyber Security Specialist

Indivara Group • Indonesia

On-site
IDR 180,000,000 - 280,000,000
Offensive Security Manager
Offensive Security Manager

INDODAX - Indonesia Digital Asset Exchange • Jakarta Pusat

On-site
IDR 900,000,000 - 1,500,000,000
Lead Penetration Tester: Web, API & Cloud Security
Lead Penetration Tester: Web, API & Cloud Security

Lancesoft Indonesia • Jakarta Pusat

On-site
IDR 400,000,000 - 700,000,000