Enable job alerts via email!

Security Engineer - Penetration Tester

DKatalis

Daerah Khusus Ibukota Jakarta

On-site

IDR 300.000.000 - 400.000.000

Full time

30+ days ago

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Start fresh or import an existing resume

Job summary

An innovative financial technology firm is seeking a Security Engineer to enhance their software security practices. In this role, you will be a key player in integrating security into the software development lifecycle, ensuring that best practices are followed to protect sensitive information. You will collaborate with development teams, evaluate security tools, and provide expertise on secure coding practices. This position offers a unique opportunity to work in a dynamic environment while driving security innovation and best practices. If you are passionate about cybersecurity and want to make a significant impact, this role is perfect for you.

Qualifications

  • 5+ years of experience in web applications and services.
  • Knowledge of secure architecture and design patterns.
  • Experience in Red Team operations and threat modeling.

Responsibilities

  • Integrate security into the Software development lifecycle.
  • Evaluate and operationalize application security tools.
  • Lead security innovation and best practices in product development.

Skills

Node JS
Java
React-Native
Android / Flutter
Secure coding practices
Red Team operations
Threat modeling
Social engineering

Education

Information security certifications (GPEN, OSCP, OSCE, OSWE)

Tools

Sonar
Fortify
Checkmarx
Burp
Nmap
Nessus
Wireshark

Job description

DKatalis is a financial technology company with multiple offices in the APAC region. In our quest to build a better financial world, one of our key goals is to create an ecosystem linked financial services business.

DKatalis is built and backed by experienced and successful entrepreneurs, bankers, and investors in Singapore and Indonesia who have more than 30 years of financial domain experience and are from top-tier schools like Stanford, Cambridge London Business School, JNU with more than 30 years of building financial services/banking experience from Bank BTPN, Danamon, Citibank, McKinsey & Co, Northstar, Farallon Capital, and HSBC.

Responsibility

To drive integrating security seamlessly into the Software development lifecycle, the Security Engineer will serve as a technical subject matter expert working with development teams. This individual will collaborate with teams and vendors to determine security requirements and support all phases of integration, operations, and maintenance to ensure a secure software environment. They will be able to work independently or in a team environment.

  • Provide subject matter expertise on secure coding practices and security design based on current knowledge of security threats and vulnerabilities that could impact the technology stack.
  • Support definition of Secure SDLC standard to include security architecture, design, and coding requirements for infrastructure, application, and data to align with application security maturity model and adopt a shift-left approach for security.
  • Evaluate various application security tools, including SAST, DAST, SCA, IAST, and Penetration Testing, and operationalize security tools for integration with CI/CD.
  • Explain and interpret the vulnerability report items to development staff.
  • Perform application testing and review security test results from scans and penetration testing to identify possible vulnerabilities that may be exploited and propose remediation solutions or mitigation controls.
  • Develop security controls and processes for products and services developed and deployed for both cloud environments, preferably GCP.
  • Perform threat modeling, conduct security architecture reviews, and provide training to architects and developers to enhance the adoption of secure coding practice within the product development lifecycle.
  • Provide security-related coaching and expertise to drive and elevate security expertise within the development teams.
  • Lead security innovation and best practices in product development through collaboration and learning from industry professionals and consortiums.
  • This position is also subject to being "on-call" for emergencies requiring immediate resolution.
Requirements
  • Minimum 5 years of experience building production web applications and services in at least two of the following languages: Node JS, Java, React-Native, Android / Flutter.
  • Experience performing Red Team operations in enterprise environments.
  • Experience in software coding/development including scripting languages.
  • Building, deploying, and managing Red Team operational infrastructure.
  • Knowledge of adversarial TTPs.
  • Experience with compromise and lateral movement in Mac, Linux, and Windows environments.
  • Open-source intelligence gathering and social engineering.
  • Web and mobile application assessments.
  • Wireless and network assessments.
  • Experience with custom payloads and exploit use in a production environment.
Desired skills & credentials
  • Knowledge of secure architecture and design patterns for Web, Mobile, and Microservices.
  • CI/CD and Appsec Tools: Sonar, Fortify, Checkmarx.
  • Reverse Engineering and Fuzzing to identify potential vulnerabilities.
  • Security / Forensics Tools: Burp, Nmap, Nessus, NetStumbler, Cain & Abel, THC Hydra, W3af, GFI LANguard, Wireshark (Tshark), WinDump (TCPDump), Web inspect, tcpreplay, Access Data FTK, Encase, Helix, etc.
  • Information security certifications: GPEN, OSCP, OSCE, OSWE.
Apply for this job

* indicates a required field

First Name *

Last Name *

Email *

Phone *

Location (City) *

Resume/CV *

Enter manually

Accepted file types: pdf, doc, docx, txt, rtf

How do you know about us?

Instagram

LinkedIn

Telegram / WAG

Online Event (Webinar)

Referral

Others

(If you are referred by one of our employee please write your friend's full name)

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.