SecurityNow Hiring
Penetration Tester
Find the real gaps before an attacker finds them first.
Full-timeHybridDepok, West JavaMin. 2 years
Apply for This RoleAbout This Role
You will test client web apps, mobile apps, APIs, networks, and cloud environments — then write findings up in reports their engineers can genuinely act on. We value methodical testing and solid exploitation evidence far more than scanner output.
What You Will Do
- Perform penetration tests across web, mobile, API, internal/external network, and cloud targets.
- Write full technical reports with proof of concept, CVSS scoring, and remediation guidance.
- Run retests to verify that findings are genuinely closed.
- Present results to both client engineering teams and management.
- Contribute to our methodology, internal tooling, and team knowledge base.
What We Are Looking For
- At least 2 years of professional penetration testing or security assessment work.
- Strong command of OWASP Top 10, OWASP ASVS/MASVS, PTES, and MITRE ATT&CK.
- Fluency with Burp Suite, Nmap, Metasploit, and other offensive tooling.
- Scripting ability (Python, Bash, or Go) for automation and PoC development.
- Strict ethical and scope discipline — you work only within written authorization.
Nice to Have
- OSCP, OSWE, CRTO, GPEN, or equivalent certification.
- A verifiable bug bounty, CVE, or CTF track record.
- Experience with red team exercises, Active Directory attacks, or cloud pentesting (AWS/Azure/GCP).
Application Form
Apply for This Role
Fill in the details below and attach your CV. Your application goes straight to our recruitment team at [email protected].
Applying for
Penetration Tester
Other Open Positions
Security
GRC Analyst / Consultant
Guide Indonesian organizations to earn — and keep — their ISO 27001 certification.
View & ApplySecuritySecurity Engineer
Build and run security controls that actually hold up in production.
View & ApplyTechnologyFull Stack Developer
Build the Sphere Suite platform GRC teams rely on every day.
View & Apply