Skip to content

Open nowPosted 111 days ago

Offensive Security Engineer/Lead

Workable (global search)108,016 open roles

Where
Jakarta, Indonesia
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowOffensive Security Engineer/LeadWorkable (global search) · Jakarta, Indonesia
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 111 days ago

Workable (global search) median: 7 days open

The posting

As the Offensive Security Engineer/Lead, you will spearhead our adversarial simulation, penetration testing, and vulnerability research programs to proactively identify and neutralize security weaknesses. Reporting directly to the Head of Security, you will design and execute sophisticated Red Team campaigns, simulate real-world cyber adversary behaviors, and validate our detection capabilities. You will be responsible for operationalizing threat intelligence by mapping all simulation activities directly to the MITRE ATT&CK framework and the Lockheed Martin Cyber Kill Chain.

Key Responsibilities

  • Offensive Security Program Leadership: Define the strategy, scope, and execution roadmap for enterprise-wide penetration testing, red teaming, and adversary simulation exercises.
  • Adversary Simulation & MITRE Mapping: Design and execute complex, multi-stage red team operations that emulate real-world Threat Actors and Advanced Persistent Threats (APTs), meticulously mapping techniques to the MITRE ATT&CK Framework.
  • Cyber Kill Chain Validation: Evaluate the efficacy of our security posture across every phase of the Lockheed Martin Cyber Kill Chain (Reconnaissance to Actions on Objectives), identifying gaps in boundary defenses and internal monitoring.
  • Purple Teaming Collaboration: Partner closely with the Blue Team (SOC and Incident Response) to conduct Purple Team exercises, using simulation data to refine detection engineering, SIEM alerts, and response playbooks.
  • Vulnerability Exploitation & Reporting: Safely exploit vulnerabilities across network infrastructure, cloud environments, and applications. Translate complex technical proof-of-concepts into actionable, risk-prioritized remediation reports for engineering teams.
  • Tooling Innovation: Oversee the development, deployment, and safe operation of proprietary offensive security tools, scripts, and command-and-control (C2) frameworks.

Requirements

  • Experience: 8+ years of dedicated technical experience in offensive security, ethical hacking, or penetration testing, with at least 2+ years leading a red team or offensive security function.
  • Framework Expert: Mastery of the MITRE ATT&CK matrix (Enterprise, Cloud, and Mobile) and deep conceptual understanding of the Lockheed Martin Cyber Kill Chain methodology.
  • Technical Environment: Proficient with commercial and open-source offensive tools (e.g., Cobalt Strike, Burp Suite, Metasploit) and deep familiarity with cloud-native security landscapes (AWS, GCP, or Azure).
  • Scripting & Exploitation: Strong scripting/programming skills (e.g., Python, Go, PowerShell, Bash) to automate attacks, bypass security controls, and develop custom exploits.
  • Certifications: Possession of advanced offensive security certifications such as OSCE, OSEP, OSWE, GXPN, or CRTO (Certified Red Team Operator) is highly preferred.
  • Communication: Exceptional communication skills with a proven track record of explaining complex attack vectors and business impacts to both deeply technical engineers and non-technical business executives.

Benefits

Join us as we make magic happen to increase Indonesia’s financial inclusion!

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.