Penetration Tester

Lancesoft Indonesia

Jakarta Pusat

On-site

IDR 400,000,000 - 700,000,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Lancesoft Indonesia is seeking a Senior Penetration Tester to lead end-to-end security engagements across web apps, APIs, mobile, networks, and cloud. You will perform hands-on testing, validate findings, and provide actionable remediation guidance while mentoring junior assessors.

Candidates should have 5+ years in offensive security (or 7+ years cybersecurity with pentesting focus) and strong OWASP/WSTG knowledge, plus OSCP or equivalent practical certifications.

Qualifications

  • Minimum 5 years of offensive security experience, OR 7 years in cybersecurity with at least 4 years focused on pentesting.
  • Proven experience managing critical engagements in high-risk sectors (Finance, Telecom, E‑commerce, government).
  • Web & API: strong knowledge of OWASP Top 10 and WSTG; testing authentication/authorization, IDOR, SSRF and API vulnerabilities.
  • Mobile Security: familiarity with OWASP MASTG; hands-on analysis on Android/iOS and bypass techniques.
  • Certifications (Practical): OSCP preferred, with OSWE/OSEP/GWAPT/GPEN/CREST CRT as additions.

Responsibilities

  • Lead technical scoping, RoE setup with stakeholders, and execute end-to-end assessments.
  • Perform deep-dive testing on Web, Mobile, API, Network, Active Directory, and Cloud environments with manual validation.
  • Produce executives’ summary and technical reports with prioritized remediation steps.
  • Lead debriefs and communicate findings to both business leadership and engineers.
  • Conduct retests to verify fixes and mentor junior team members; contribute to internal playbooks.

Skills

Penetration testing
Leadership
Reporting
Mentoring
Scripting & tooling

Tools

Python
Bash
PowerShell
Go/C# (plus)

Job description

The Senior Penetration Tester will lead end-to-end security engagements across web applications, APIs, mobile platforms, internal networks, and cloud infrastructure. This role is responsible for executing technical scoping, hands-on penetration testing, manual exploit validation, and retesting. Beyond identifying vulnerabilities, you will deliver actionable, prioritized remediation guidance for engineering teams while mentoring junior security assessors through report reviews, internal playbook development, and continuous knowledge sharing.

Key Responsibilities

  • Leadership: Lead technical scoping, establish Rules of Engagement (RoE) with stakeholders, and execute end-to-end assessments independently
  • Hands-on Penetration Testing: Perform deep-dive assessments on Web, Mobile (Android/iOS), API (REST/GraphQL), Network, Active Directory, and Cloud/Container environments with manual validation to eliminate false positives
  • Reporting & Deliverables: Produce clear, two-tiered reports consisting of an Executive Summary for leadership and reproducible technical details with prioritized remediation steps for developers
  • Debriefs & Stakeholder Communication: Lead debrief sessions, presenting complex technical findings effectively to both non-technical business leaders and technical engineering teams
  • Remediation & Retesting: Conduct retests to verify fix effectiveness and ensure long-term risk mitigation
  • Capability Development & Mentoring: Drive continuous improvement by building internal tooling, refining checklists/playbooks, and mentoring junior team members

Person Specifications

  • Minimum 5 years of experience in offensive security, OR 7 years in general cybersecurity with at least 4 years exclusively focused on penetration testing
  • Proven experience independently managing critical engagements within high-risk sectors (Financial Services, Telecommunications, E-Commerce, or Government)
  • Web & API: In-depth knowledge of OWASP Top 10 and WSTG. Expertise in testing authentication/authorization flaws, IDOR, SSRF, insecure deserialization, business logic bugs, and API vulnerabilities (REST & GraphQL batching/introspection abuse)
  • Mobile Security: Deep knowledge of OWASP MASTG. Hands-on experience with static/dynamic analysis on Android & iOS, including client-side security bypasses
  • Scripting & Tooling: Proficient in Python, Bash, or PowerShell (Go or C# is a plus). Ability to modify PoCs and build custom scripts rather than relying solely on automated scanners
  • Standards & Compliance: Familiarity with PTES, OSSTMM, NIST SP 800-115, MITRE ATT&CK, CVSS v3.1/v4.0, PCI DSS, ISO 27001, as well as Indonesian regulations (POJK/SEOJK and UU PDP)
  • Preferred Certification (Practical/Hands-on): OSCP (Primary), paired with OSEP, OSWE, GPEN, GWAPT, CRTO, or CREST CRT
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Penetration Tester
Senior Penetration Tester

Asiatek Solusi Indonesia • Jakarta Pusat

On-site
IDR 600,000,000 - 900,000,000
Penetration Tester
Penetration Tester

VLink Inc • Jakarta Pusat

On-site
IDR 300,000,000 - 600,000,000
Penetration Tester
Penetration Tester

Telkom Indonesia • Indonesia

On-site
IDR 300,000,000 - 600,000,000
Senior Penetration Tester: Lead Engagements & Security
Senior Penetration Tester: Lead Engagements & Security

Telkom Indonesia • Indonesia

On-site
IDR 300,000,000 - 600,000,000
Senior Penetration Tester - Ra
Senior Penetration Tester - Ra

Axonect • Jakarta Pusat

On-site
IDR 350,000,000 - 700,000,000
Lead Penetration Tester: Web, API & Cloud Security
Lead Penetration Tester: Web, API & Cloud Security

Lancesoft Indonesia • Jakarta Pusat

On-site
IDR 400,000,000 - 700,000,000
Senior Penetration Tester: Lead End-to-End Security Testing
Senior Penetration Tester: Lead End-to-End Security Testing

Asiatek Solusi Indonesia • Jakarta Pusat

On-site
IDR 600,000,000 - 900,000,000
Penetration Testing (Offensive) Sentrabyte Digital Solusi
Penetration Testing (Offensive) Sentrabyte Digital Solusi

Sentrabyte Digital Solusi • Daerah Khusus Ibukota Jakarta

On-site
IDR 136,869,000 - 256,630,000
Competitive salary
Supportive environment
Continuous learning opportunities
Offensive Security Manager
Offensive Security Manager

INDODAX - Indonesia Digital Asset Exchange • Jakarta Pusat

On-site
IDR 900,000,000 - 1,500,000,000
Offensive Security Manager
Offensive Security Manager

INDODAX • Jakarta Selatan

On-site