368,611open jobs
9,439companies
50,719added this week
Browse all
Location
In office (Jakarta)
Seniority
Staff · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Founded in 2018 and headquartered in West Jakarta City, Indonesia, Ajaib is an investing platform to buy and sell stocks, ETFs, and mutual funds.

As the Offensive Security Engineer/Lead, you will spearhead our adversarial simulation, penetration testing, and vulnerability research programs to proactively identify and neutralize security weaknesses. Reporting directly to the Head of Security, you will design and execute sophisticated Red Team campaigns, simulate real-world cyber adversary behaviors, and validate our detection capabilities. You will be responsible for operationalizing threat intelligence by mapping all simulation activities directly to the MITRE ATT&CK framework and the Lockheed Martin Cyber Kill Chain.

Key Responsibilities

  • Offensive Security Program Leadership: Define the strategy, scope, and execution roadmap for enterprise-wide penetration testing, red teaming, and adversary simulation exercises.
  • Adversary Simulation & MITRE Mapping: Design and execute complex, multi-stage red team operations that emulate real-world Threat Actors and Advanced Persistent Threats (APTs), meticulously mapping techniques to the MITRE ATT&CK Framework.
  • Cyber Kill Chain Validation: Evaluate the efficacy of our security posture across every phase of the Lockheed Martin Cyber Kill Chain (Reconnaissance to Actions on Objectives), identifying gaps in boundary defenses and internal monitoring.
  • Purple Teaming Collaboration: Partner closely with the Blue Team (SOC and Incident Response) to conduct Purple Team exercises, using simulation data to refine detection engineering, SIEM alerts, and response playbooks.
  • Vulnerability Exploitation & Reporting: Safely exploit vulnerabilities across network infrastructure, cloud environments, and applications. Translate complex technical proof-of-concepts into actionable, risk-prioritized remediation reports for engineering teams.
  • Tooling Innovation: Oversee the development, deployment, and safe operation of proprietary offensive security tools, scripts, and command-and-control (C2) frameworks.

Requirements

  • Experience: 8+ years of dedicated technical experience in offensive security, ethical hacking, or penetration testing, with at least 2+ years leading a red team or offensive security function.
  • Framework Expert: Mastery of the MITRE ATT&CK matrix (Enterprise, Cloud, and Mobile) and deep conceptual understanding of the Lockheed Martin Cyber Kill Chain methodology.
  • Technical Environment: Proficient with commercial and open-source offensive tools (e.g., Cobalt Strike, Burp Suite, Metasploit) and deep familiarity with cloud-native security landscapes (AWS, GCP, or Azure).
  • Scripting & Exploitation: Strong scripting/programming skills (e.g., Python, Go, PowerShell, Bash) to automate attacks, bypass security controls, and develop custom exploits.
  • Certifications: Possession of advanced offensive security certifications such as OSCE, OSEP, OSWE, GXPN, or CRTO (Certified Red Team Operator) is highly preferred.
  • Communication: Exceptional communication skills with a proven track record of explaining complex attack vectors and business impacts to both deeply technical engineers and non-technical business executives.

Benefits

Join us as we make magic happen to increase Indonesia’s financial inclusion!

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Jakarta
$70k – $126k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Shiloh
DevOps
AWS
Azure
GCP
Cybersecurity
Cyber Kill Chain
Defense in Depth
MITRE ATT&CK
Apply
$87k – $157k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Ashburn
Bash
PowerShell
Python
Visual Basic
Cybersecurity
Cyber Kill Chain
MITRE ATT&CK
Apply
$150k – $200k per year • Remote • Full-Time • 11+ years exp
YARA
Databases
Apache Kafka
ElasticSearch
OpenSearch
AI/ML
AI Agents
Embeddings
RAG
Semantic Search
GraphRAG
Knowledge Graph
Semantic Search
DevOps
Kubernetes
Vector
Cybersecurity
MITRE ATT&CK
STIX
TAXII
YARA
Apply
$20k – $51k per year (Estimated) • In office • Omsk
PowerShell
Python
Cybersecurity
MITRE ATT&CK
Apply
$24k – $58k per year (Estimated) • Remote/Hybrid • Contractor • Moscow
Bash
PowerShell
Python
DevOps
Kali Linux
SLI/SLO/SLA
Cybersecurity
BloodHound
GoPhish
MITRE ATT&CK
Nessus
OpenVAS
OWASP ZAP
Wazuh
Apply
In office • 5+ years exp • Jakarta
Python
SQL
Databases
Amazon Redshift
Apache Kafka
Google BigQuery
Google Cloud Spanner
Snowflake
AI/ML
Dagster
dbt
Flink
DevOps
CI/CD
Git
GitHub Actions
GitHub
Analytics
Tableau
Marketing
Amplitude
Mixpanel
Apply
In office • Full-Time • 4+ years exp • Bachelor's Degree • Jakarta
Java
Node JS
Python
JavaScript
DevOps
Bitbucket
CI/CD
Docker
GitHub Actions
GitLab CI
Jenkins
Kubernetes
Terraform
GitHub
GitLab
Cybersecurity
Burp Suite
Checkmarx
Semgrep
Snyk
SonarQube
Apply
In office • Full-Time • 8+ years exp • Bachelor's Degree • Jakarta
Go
Java
Node JS
Python
JavaScript
DevOps
AWS
Bitbucket
CI/CD
Docker
GCP
Kubernetes
GitHub
GitLab
Cybersecurity
Burp Suite
OWASP ASVS
OWASP SAMM
OWASP Top 10
Semgrep
Snyk
SonarQube
STRIDE
Threat Modeling
Apply
In office • Full-Time • 4+ years exp • Bachelor's Degree • Jakarta
DevOps
Incident Management
Cybersecurity
ISO 27001
Apply
In office • 7+ years exp • Jakarta
Apply
In office • Full-Time • Jakarta
Apply
SAP BASIS 1 day ago
In office • Full-Time • Bachelor's Degree • Jakarta • Semarang
Databases
SAP HANA
DevOps
AWS
Azure
GCP
Incident Management
Apply
In office • Full-Time • 7+ years exp • Jakarta
Go
Python
DevOps
AWS
CI/CD
Datadog
GitLab CI
Grafana
Kibana
GitLab
Apply
In office • Full-Time • 2+ years exp • Bachelor's Degree • Jakarta
Python
SQL
Analytics
Power BI
Tableau
Apply
In office • Full-Time • 4+ years exp • Bachelor's Degree • Jakarta
Python
SQL
JavaScript
Frontend
D3.js
Analytics
Power BI
A/B Testing
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.