Baru Red Teamer

Date Posted: Posted6 hari yang lalu
Salary:
Jakarta

Job Description

Location Jakarta Work Type Permanent Application Posted March 2, 2022

About the Role


If you’re looking to be a part of a dynamic, highly-analytical team and an opportunity to dive deep into projects surrounding information security, look no further. As our Red Teamer (Offensive Security) for GoTo Financial, you’ll take the wheel in ensure product security for Gojek. Along with Perform a thorough documentation on how vulnerabilities were exploited, you will be in charge of assist in identifying, tracing and neutralizing the active threats. Working closely with Blue Team, you will get to manage unique security incidents.



What Will You Do

  • Actively involved as an individual contributor and subject matter experts from the beginning to the end such as: (1) upon request, during an active incident response of a real attack, (2) data/system breaches, (3) catastrophic system failures due to cyberattack, and (4) involved early in any important projects that required higher degree of security assessments from the adversaries’ attack point of view
  • Dedicatedly assist in identifying, tracing and neutralizing the active threats
  • Perform a thorough documentation on how vulnerabilities were exploited and what changes should be made to prevent that from being exploited again
  • Assist/participate in presenting the findings to multiple stakeholders involved in the study and/or incidents
  • Proactively identify (and attempt to exploit) multiple vulnerabilities that are affecting the system and data security of our business
  • Obtain a realistic understanding of the risks that our business can face including training used to prepare employees for cyber incidents
  • Ensure that you upkeep required training regimens within Offensive Security Team across the rest of the Red Team members
  • Participate in regular purple teaming exercises together with the Blue Team

What Will You Need

  • At least 2 years of experience in ethical hacking (active exploitation), manual penetration testing and/or red teamer operations covering at least two of the following domains: infrastructure, operating systems, web app, mobile app, software bug testing
  • A decent level of code/programming experience (e.g.: write/modify exploit codes, trace and debugging traditional/OOP/API style programming)A strong hacker mindset including social engineering, logical and creative thinking (outside of the box) and unconventional thought processes when playing the devil advocates
  • Strong dedication and desire to understand how things work, on a very deep level
  • Experience with the red teaming aspect of technical writing documentation of the findings to multiple levels of stakeholders (from engineering to senior managers)
  • Hands-on experience in at least three of the following domains: Physical Security, Social Engineering, Infrastructure (Cloud & On-Premise), Offensive Mindset, Computer Network & Systems, Detection Evasion, Penetration Testing, Vulnerability Research, Technical Writing, DevSecOps (incld. CI/CD), Threat Intels, OSINT
  • Having professional certification(s) related to red-teaming such as GIAC (GPEN, GCPN, GWAPT, GMOB, GXPN) or Offensive Security (OSCP, OSEP, OSWA/E, OSED/OSMR) is bonus point

About the Team

Offensive Security Team is a sub-pod of the GoTo Financial Security. The Offensive Security Charter: To help hedge against surprise, particularly catastrophic surprises - by not only playing the adversary, but also devil's advocate and related roles. The team challenge complacency or unthoughtfulness in security-by-design principles and discover weaknesses before real adversaries do.

Related Jobs

Job Detail

  • Job Id
    3dd94d35ed0091f8
  • Location
    Jakarta
  • Company
  • Type
    Private
  • Employment Status
    Permanent
  • Positions
    Available
  • Career Level
    Experience
  • Gender
    Male/Female

Contact GO-JEK

Sponsored by

https://www.halokerja.id connects jobseekers and recruiters by accurately matching candidate profiles to the relevant job openings through an advanced 2-way matching technology. While most job portals only focus on getting candidates the next job, Shine focuses on the entire career growth of candidates.

Latest Job