Remote Security Testing Engineer

at PT. Devantara Media Factory

Posted 1 week ago 1 applied

Description:

  • The position is for a Security Testing Engineer at Devantara Media Factory, with a salary range of $4,200 - $8,200 per month.
  • The role involves executing security testing activities, including penetration testing and vulnerability assessments, on web applications, infrastructure, and network environments to proactively identify and remediate security weaknesses.
  • Responsibilities include designing and maintaining automated and manual security testing strategies to ensure robust test coverage across critical systems, applications, and services.
  • The engineer will configure and manage security testing tools and environments, including vulnerability scanners, SIEMs, firewalls, IDS/IPS, and other relevant security monitoring technologies.
  • Developing detailed technical reports and risk assessments is essential, clearly articulating discovered vulnerabilities, their potential impact, and actionable remediation steps aligned with industry best practices.
  • Collaboration with DevOps, development, and infrastructure teams is required to embed secure coding practices throughout the software development lifecycle (SDLC) and support compliance with standards such as OWASP, ISO 27001, and NIST.
  • The engineer will continuously monitor for security anomalies and conduct post-exploitation analysis to simulate real-world attack scenarios and validate defensive mechanisms.
  • Staying current with emerging threat landscapes, tools, and techniques is necessary to strengthen internal testing methodologies and security postures.

Requirements:

  • Proven experience in security testing, including penetration testing and vulnerability assessment for web applications, networks, or cloud infrastructure environments is required.
  • In-depth knowledge of information security standards and frameworks such as OWASP Top 10, NIST, and ISO 27001, with practical application in securing systems and applications is essential.
  • The ability to perform secure code reviews and identify vulnerabilities, particularly in widely used Content Management Systems (CMS) such as WordPress, Joomla, and Drupal is necessary.
  • Proficiency in operating and analyzing results from industry-standard security testing tools such as Burp Suite, Nmap, Metasploit, Wireshark, and other relevant frameworks is required.
  • A strong grasp of network protocols, system architecture, and infrastructure security best practices across diverse environments is essential.
  • Hands-on experience with scripting and programming languages (e.g., Python, PHP, Java, or Shell scripting) to automate security tasks and develop custom test scripts is required.
  • Security certifications such as OSCP, CEH, CISSP, or equivalent are highly desirable and considered a significant advantage.

Benefits:

  • The position offers a competitive salary along with performance bonuses.