Security Engineer (Red Team) - Mid/Senior

Amartha
Daerah Khusus Ibukota Jakarta
IDR 300,000,000 - 400,000,000
Job description

Security Engineer (Red Team) - Mid/Senior

The Associate Software Security Engineer plays an essential role in protecting Amartha from evolving cyber threats. You will be part of our dynamic security team, focusing on identifying and mitigating security risks across our technology stack.

About the Team

Our Information Security team consists of dedicated security professionals who prioritize security and privacy by design. We work closely with development teams to enable secure product development while maintaining operational efficiency.

Primary Responsibilities

  1. Execute vulnerability assessments and penetration tests across web applications, APIs, and mobile platforms
  2. Implement and maintain security controls in cloud environments (GCP, AWS)
  3. Develop automation scripts and tools to enhance security processes
  4. Perform security code reviews and threat modeling
  5. Support our bug bounty program through triage and validation
  6. Monitor systems for security anomalies and investigate potential incidents
  7. Collaborate with development teams to remediate security findings

Growth & Development

  1. Mentorship from experienced security engineers
  2. Certification and training support
  3. Hands-on experience with modern security tools and challenges
  4. Clear career advancement path within the security team

Requirements

Required Skills

  1. 2+ years of hands-on security testing or software development experience
  2. Strong understanding of web security fundamentals and OWASP Top 10
  3. Proficiency in at least one scripting/programming language (Python, Bash, or Go)
  4. Experience with security testing tools (Burp Suite, OWASP ZAP)
  5. Basic understanding of cloud security concepts
  6. Ability to clearly communicate technical findings to various stakeholders
  7. Fast learner with passion for cybersecurity
  8. Self-motivated to stay updated with security trends and threats

Preferred Qualifications

  1. Security certifications (eJPT, OSCP, CEH)
  2. Experience with cloud platforms (AWS, GCP)
  3. Knowledge of CI/CD pipelines and DevSecOps practices
  4. Mobile application security testing experience
  5. Familiarity with infrastructure as code (Terraform, Ansible)

Technical Environment

Security Tools: Burp Suite, Metasploit, Nmap, MobSF, Frida
Development Tools: Git, GitHub, Jenkins
Programming Languages: Python, Bash, Go

Get a free, confidential resume review.
Select file or drag and drop it
Avatar
Free online coaching
Improve your chances of getting that interview invitation!
Be the first to explore new Security Engineer (Red Team) - Mid/Senior jobs in Daerah Khusus Ibukota Jakarta