Senior Security Engineer, Red Team
7 days ago
**Job Description**:
**Life at Grab**
At Grab, every Grabber is guided by The Grab Way, which spells out our mission, how we believe we can achieve it, and our operating principles - the 4Hs: Heart, Hunger, Honour and Humility. These principles guide and help us make decisions as we work to create economic empowerment for the people of Southeast Asia.
**Get to know the Team**:
You’ll be part of an exciting team that is responsible for the Grab Cyber Defence function. The Cyber Defence team is responsible for threat detection, incident response, threat intelligence, threat hunting, red teaming, insider abuse and insider fraud detection.
Unlike traditional enterprise environments, Grab's multi-cloud, microservices and container infrastructure makes it an attractive environment for the attacker. Our job as Red Teamers is to prepare Grab for these attacks via adversary attack simulation and atomic testing.
**Get to know the Role**:
**The Day-to-Day Activities**:
- Support the full scope red team engagements through planning, organizing, executing, and reporting.
- Perform penetration tests in one or more of the following: Cloud, API, Network, Web, Mobile and social engineering engagement.
- Perform targeted, covert red team operation in various technology landscapes with custom tooling to aid infiltration, exploitation and post-exploitation activities.
- Develop payloads, scripts and tools that weaponize new concepts for execution, evasion, lateral movement and persistence.
- Set up infrastructure needed for the engagements
- Research new TTPs that are relevant to Grab threat profile and tech stack.
- Take part in joint Purple-Teaming efforts.
- Communicate effectively with other red team operators, defenders, stakeholders and senior management.
- Develop comprehensive and accurate reports and presentations for both technical and executive audiences.
**The Must-Haves**:
- At least 3 years of offensive security working experience.
- Experience in Modern Infrastructure Penetration Testing with a firm understanding of cloud architecture, CI/CD, microservices architecture and Kubernetes/container security.
- Experience in Application Penetration testing with a firm understanding of modern web exploitation, modern authentication frameworks and exploit chaining techniques.
- Experience in Windows, OSX and *NIX internal security to develop covert persistence mechanisms, modern EDR/EPP evasion techniques and privilege escalation techniques.
- Experience in utilizing and customizing post-exploitation frameworks such as Mythic, Cobalt strike, Metasploit, Empire, Covenant, etc.
- Past involvement in Red Team Operations, ability to think like an adversary, good situational awareness, generating creative adversarial scenarios and having a knack for operational security (OPSEC).
- Programming experience in one or more interpreted or compiled languages: Python, Go, C/C++, C#, PowerShell, Rust.
- Good interpersonal, organizational, communication and time management skills.
**The Nice-to-Haves**:
- Offensive Security (OSCP, OSCE, OSWE, OSEP, OSED, OSMR), eLearnSecurity (eCPPT, eCPTX, eWPTX, eCMAP), CREST (CRT, CCSAS), CRTO, CRTE, or equivalent.
- Past achievements in CTF, Bug bounty or CVEs.
- Published offensive/defensive related research.
- Experience in Purple Teaming projects and working closely with the Blue Team.
**Our Commitment**
We recognize that with these individual attributes come different workplace challenges, and we will work with Grabbers to address them in our journey towards creating inclusion at Grab for all Grabbers.
-
Security Engineer
3 days ago
Jakarta, Indonesia FinAccel Full timeSecurity Engineer - Red Team is part of our Information Security Department who is responsible for cyber attacks. On a daily basis, our Red Team will continuously detect, analyze, and find security gaps in Finaccel's systems (Infrastructure & Application). Security Engineer - Red Team must have extensive knowledge in vulnerability assessment and penetration...
-
Security Engineer
3 weeks ago
Jakarta, Indonesia amIT Global Solution Full timeAt least 2 years experience in Vulnerable Assessment, Penetrating Testing and Red Teaming - Having Cyber Security certifications like CEH (Certified Ethical Hacker) or similiar is a plus - Willing to work onsite at Sunter, North Jakarta Jenis Pekerjaan: Kontrak Panjang kontrak: 12 bulan Pengalaman: - Penetration Testing: 1 tahun (Diwajibkan) -...
-
IT Security Specialist
1 month ago
Jakarta, Indonesia Techtiera Services Indonesia Full timeWe are dedicated to safeguarding our digital landscape and ensuring the security of our data and systems. We are seeking a highly skilled IT Security Specialist with both Red Team and Blue Team experience to join our dynamic team. As an IT Security Specialist, you will play a critical role in protecting our organization from cyber threats by simulating...
-
Senior Technical Account Manager- Openshift
5 days ago
Jakarta, Indonesia Red Hat Software Full timeAbout the job: The Red Hat Telco, Media, and Entertainment Support team is looking for an experienced, enterprise-level engineer to join us as an OpenShift focused Senior Technical Account Manager in Jakarta, Indonesia. In this role, you will work with a small set of telecommunications customers to provide architectural guidance and implementation advice for...
-
Senior Specialist Solutions Architect
1 week ago
Jakarta, Indonesia Red Hat Software Full timeAbout the job: The Red Hat Sales team is looking for a Senior Specialist Solutions Architect to join us. In this role, you will support the South East Asia TME (Telco, Media & Entertainment) Sales team and provide presales technical support to customers. You will work with key customers on site or remotely to build a relationship of trust and confidence...
-
Security Engineer
3 hours ago
Jakarta, Indonesia FinAccel Full timeWe are looking for Security Engineer - Red Team to be part of our Information Security Department who is responsible for cyber attacks. On a daily basis, our Red Team will continuously detect, analyze, and find security gaps in our systems (Infrastructure & Application). Security Engineer - Red Team must have extensive knowledge in vulnerability assessment...
-
Senior Technical Account Manager
2 months ago
Jakarta, Indonesia Red Hat, Inc. Full timeRed Hat South East Asia TAM team is looking for an experienced, enterprise-level engineer to join us as a Senior Technical Account Manager in Jakarta, Indonesia. In this role, you will serve as a trusted advisor who will work with a small set of key strategic customers to provide practical technical and architectural guidance for the Red Hat Enterprise Linux...
-
Senior Technical Account Manager
2 months ago
Jakarta, Indonesia Red Hat, Inc. Full timeAbout The Job The Red Hat South East Asia Technical Account Management (TAM) team is looking for an experienced, enterprise-level engineer to join us as a Senior Technical Account Manager based in either Indonesia/Philippines/Malaysia. In this role, you will serve as a trusted advisor who will work with a small set of key strategic customers to provide...
-
Senior Technical Account Manager
4 months ago
Jakarta, Indonesia Red Hat, Inc. Full timeAbout The Job The Red Hat South East Asia Technical Account Management (TAM) team is looking for an experienced, enterprise-level engineer to join us as a Senior Technical Account Manager based in either Indonesia/Thailand/Malaysia. In this role, you will serve as a trusted advisor who will work with a small set of key strategic customers to provide...
-
Red Teamer Manager-goto Financial
1 week ago
Jakarta, Indonesia GO-JEK Full timeAbout the Role If you’re looking to be a part of a dynamic, highly-analytical team and an opportunity to dive deep into projects surrounding information security, look no further. As our Red Team Specialist for GoTo Financial, you’ll take the wheel in ensure product security for Gojek. Along with Perform a thorough documentation on how vulnerabilities...
-
Security Engineer
3 days ago
Jakarta, Indonesia Amartha Full time**About the Role** The Associate Software Security Engineer plays an essential role in protecting Amartha from evolving cyber threats. You will be part of our dynamic security team, focusing on identifying and mitigating security risks across our technology stack. **About the Team** Our Information Security team consists of dedicated security...
-
Security Engineer
7 days ago
Jakarta, Indonesia WeNetwork Asia Full timeSecurity Engineer - Offensive Team - Security Infrastructure **About the Company**: Our client is a well-known leading PayLater platform that has been recognized as one of the unicorn companies in Indonesia **Responsibilities**: - Able to conduct security reviews from the perspective of external attackers (hackers). - Generate reports on the results of...
-
Red Teamer-goto Financial
1 week ago
Jakarta, Indonesia GO-JEK Full time**About the Role** If you’re looking to be a part of a dynamic, highly-analytical team and an opportunity to dive deep into projects surrounding information security, look no further. As our Red Teamer (Offensive Security) for GoTo Financial, you’ll take the wheel in ensure product security for Gojek. Along with Perform a thorough documentation on how...
-
Senior Technical Account Manager Platform and
7 months ago
Jakarta, Indonesia Red Hat, Inc. Full timeRed Hat South East Asia TAM team is looking for an experienced, enterprise-level engineer to join us as a Technical Account Manager in Jakarta, Indonesia. In this role, you will serve as a trusted advisor who will work with a small set of key strategic customers to provide practical technical and architectural guidance for the Red Hat RHEL / OpenShift...
-
IT Security Engineer
7 months ago
Jakarta, Indonesia PT GTECH DIGITAL ASIA Full timeGTech is a global digital technology enabler, we provide integrated digital solutions for multiple industries. Our platforms cover omnichannel commerce digitalization, DTC commerce transformation, FinTech, Customer Relationship Management and supply chain digitalization. Design, plan, develop, deploy, and continuously improve Security Policies,...
-
Senior Technical Account Manager Platform and
7 months ago
Jakarta, Indonesia Red Hat Software Full timeAbout the job: Red Hat South East Asia TAM team is looking for an experienced, enterprise-level engineer to join us as a Technical Account Manager in Jakarta, Indonesia. In this role, you will serve as a trusted advisor who will work with a small set of key strategic customers to provide practical technical and architectural guidance for the Red Hat RHEL /...
-
Security Engineer
2 months ago
Jakarta, Indonesia PT. Amalura Multi Dimensi Full timeJob Description: - Participate in Red Team and Blue Team exercises. - Validate reports for Bug Bounty Programs. - Support incident investigations and provide mitigation recommendations - Document finding and collaborates with technical teams - Stay update on the latest attack methods and emerging threats Requirement: - Minimum graduated from reputable...
-
Red Teamer-team6 Specialist
6 days ago
Jakarta, Indonesia GO-JEK Full time**About the Role** If you’re looking to be a part of a dynamic, highly-analytical team and an opportunity to dive deep into projects surrounding information security, look no further. As our Team6 Specialist (Offensive Security) for GoTo Financial, you’ll take the wheel in ensure product security for Gojek. Along with Perform a thorough documentation on...
-
Security Engineer
7 months ago
Jakarta, Indonesia Autobahn Security Full time**About Autobahn Security** Autobahn Security is a technology start-up with a vision to make cybersecurity and vulnerability management accessible to all businesses. Our SaaS product has been developed by some of the world's finest cybersecurity researchers and experts. Our SaaS tool allows both cybersecurity experts and non-experts to embark on a journey...
-
Information Security Engineer
1 week ago
Jakarta, Indonesia Alodokter Full timeLead, manage, and review all penetration test projects in the company (internal and external) Generate summary and detailed report for penetration test activity Responsible for handling the vulnerability management of company's products and services Review, validate, and manage bug bounty program Responsible to manage and review the vulnerability found...