Offensive Security Manager
- Gaji
- Gaji tidak dicantumkan
- Jenis pekerjaan
- Kontrak
- Diposting
- Sumber
- Dealls Indonesia (sitemap + page JSON)
Kami akan mengarahkan Anda ke situs tempat lowongan diposting untuk menyelesaikan lamaran.
Deskripsi pekerjaan
Tanggung jawab
1. Product Security (AppSec)
Secure SDLC: Manage the Product Security Engineers who work alongside developers. Ensure security reviews, threat models, and code scanning (SAST/DAST) happen before deployment.
Bug Bounty Management: Oversee the public or private Bug Bounty Program (e.g., HackerOne, Bugcrowd). Triage incoming reports, validate severity, and pay out researchers.
Developer Education: Move beyond "gatekeeping." Create a "Security Champions" program to train developers on how to write secure code (e.g., OWASP Top 10 prevention).
2. Red Teaming & Adversary Simulation
Campaign Management: Design and approve Red Team campaigns (e.g., "Simulate a ransomware attack starting from a phishing email to Finance"). Define the "Rules of Engagement" to ensure production systems aren't crashed.
Purple Teaming: Facilitate "Purple Team" exercises where your Red Team attacks and sits with the Blue Team (Defenders) to see if they can detect the attack in real-time.
Physical & Social Engineering: Authorize physical security tests (badge cloning, tailgating) and advanced spear-phishing campaigns to test human resilience.
3. Vulnerability Management
Prioritization Strategy: Stop the "patch everything" noise. Guide the Vulnerability Management Engineer to prioritize fixes based on exploitability (e.g., "Is there a public exploit available?" "Is this server internet-facing?").
SLA Enforcement: Act as the "bad guy" with IT and Engineering leadership when critical vulnerabilities are not patched within the agreed Service Level Agreement (SLA).
Asset Coverage: Ensure that scanners (Qualys/Tenable) are actually seeing 100% of the environment, including shadow IT and new cloud deployments.
Persyaratan
- Min. S1 Teknik Informatika/System Komputer/atau yang sejenis
- 7+ years in Information Security, with 3–4+ years as a Penetration Tester, Red Teamer, or AppSec Engineer; hands-on ability to perform attacks like SQL injection or compromise Active Directory.
- Application Security Fluency: Deep understanding of modern application stacks, including API security, micro services, and CI/CD pipelines.
- Scripting & Automation: Proficient in Python, Go, or Bash for automating testing and security tools.
- Leadership & Risk Communication: Ability to explain technical risks (e.g., XSS) in business terms to Product Managers or stakeholders.
- Legal & Ethics Knowledge: Understanding of legal boundaries for ethical hacking (e.g., CFAA, safe harbor clauses).
- Preferred Certifications: OSCP / OSCE (technical credibility), GWAPT / GPEN / GXPN (penetration testing), CISSP (management-focused).
Referensi: 33579 · Berlaku sampai 12 Oktober 2026