FULL_TIME
As the Offensive Security Engineer/Lead, you will lead adversarial simulation, penetration testing, and vulnerability research initiatives to proactively detect and eliminate security risks. Reporting to the Head of Security, you will plan and run advanced Red Team campaigns, mimic real-world cyber adversary tactics, and assess our detection capabilities. You will be tasked with operationalizing threat intelligence by mapping all simulation activities directly to the MITRE ATT&CK framework and the Lockheed Martin Cyber Kill Chain.
Key Responsibilities
Offensive Security Program Leadership: Establish the strategy, scope, and execution roadmap for organization-wide penetration testing, red teaming, and adversary simulation exercises.
Adversary Simulation & MITRE Mapping: Plan and run complex, multi-stage red team operations that replicate real-world Threat Actors and Advanced Persistent Threats (APTs), carefully mapping techniques to the MITRE ATT&CK Framework.
Cyber Kill Chain Validation: Assess the effectiveness of our security posture across every phase of the Lockheed Martin Cyber Kill Chain (Reconnaissance to Actions on Objectives), pinpointing gaps in perimeter defenses and internal monitoring.
Purple Teaming Collaboration: Work closely with the Blue Team (SOC and Incident Response) to conduct Purple Team exercises, leveraging simulation data to improve detection engineering, SIEM alerts, and response playbooks.
Vulnerability Exploitation & Reporting: Safely exploit vulnerabilities across network infrastructure, cloud environments, and applications. Convert complex technical proof-of-concepts into actionable, risk-prioritized remediation reports for engineering teams.
Tooling Innovation: Oversee the development, deployment, and safe operation of proprietary offensive security tools, scripts, and command-and-control (C2) frameworks.
Requirements
Experience: 8+ years of dedicated technical experience in offensive security, ethical hacking, or penetration testing, with at least 2+ years leading a red team or offensive security function.
Framework Expert: Mastery of the MITRE ATT&CK matrix (Enterprise, Cloud, and Mobile) and deep conceptual understanding of the Lockheed Martin Cyber Kill Chain methodology.
Technical Environment: Proficient with commercial and open-source offensive tools (e.g., Cobalt Strike, Burp Suite, Metasploit) and deep familiarity with cloud-native security landscapes (AWS, GCP, or Azure).
Scripting & Exploitation: Strong scripting/programming skills (e.g., Python, Go, PowerShell, Bash) to automate attacks, bypass security controls, and develop custom exploits.
Certifications: Possession of advanced offensive security certifications such as OSCE, OSEP, OSWE, GXPN, or CRTO (Certified Red Team Operator) is highly preferred.
Communication: Exceptional communication skills with a proven track record of explaining complex attack vectors and business impacts to both deeply technical engineers and non-technical business executives.
Benefits
Join us as we make magic happen to increase Indonesia's financial inclusion!
Offensive Security Engineer/Lead
Ajaib • Jakarta • Gaji tidak dicantumkan
Deskripsi Pekerjaan
Ringkasan
- Perusahaan
- Ajaib
- Lokasi
- Jakarta
- Tipe kerja
- FULL_TIME
- Gaji
- Gaji tidak dicantumkan
- Tanggal tayang
- 15 Jun 2026
- Terlihat sejak
- 30 Sep 2026
Sumber & keterlacakan data
Workable ATS (first-party) — https://apply.workable.com/j/08ADBD012C
Siap melamar? Langsung di sumber asli.Buka Halaman Lamaran
Lowongan Terkait Lainnya
FULL_TIME3bln
DevSecOps Engineer/Lead
Ajaib • Jakarta
Gaji tidak dicantumkanLihat Detail →
FULL_TIME4blnIT Support & Project Manager
Ajaib • Jakarta
Gaji tidak dicantumkanLihat Detail →
FULL_TIME4blnApplication Security Engineer/Lead
Ajaib • Jakarta
Gaji tidak dicantumkanLihat Detail →
FULL_TIME5blnSecurity Platform Engineer
Ajaib • Jakarta
Gaji tidak dicantumkanLihat Detail →