
Offensive Security Lead
Posted Jul 29

Posted Jul 29
This is a fully remote position, open to applicants in Indonesia.
• Establish and oversee Ajaib’s offensive security strategy, roadmap, and testing program.
• Perform hands-on penetration testing on mobile applications, web applications, APIs, backend services, cloud environments, and internal systems.
• Organize and carry out red-team exercises and adversary simulations based on realistic threat scenarios.
• Detect intricate attack paths across applications, infrastructure, identity systems, and third-party integrations.
• Evaluate authentication, authorization, session management, account recovery, transaction flows, and customer protection controls.
• Conduct security assessments for new products, features, architectures, and high-risk integrations.
• Assess the effectiveness of security controls, monitoring, detection, and incident response capabilities.
• Collaborate with engineering and security teams to verify remediation and ensure that vulnerabilities are thoroughly resolved.
• Offer clear, actionable remediation guidance that aids teams in minimizing risk without hindering delivery.
• Create custom testing tools, scripts, payloads, and automation to enhance offensive security coverage.
• Manage external penetration tests, specialized assessments, and independent security reviews.
• Assist in responsible disclosure and bug bounty activities, including triage, validation, and remediation tracking.
• Produce high-quality reports that detail technical findings, business impact, attack scenarios, and recommended actions.
• Establish offensive security metrics, testing standards, and risk prioritization methods.
• Mentor offensive security engineers and contribute to enhancing the team’s technical expertise.
• Communicate attack trends, lessons learned, and defensive recommendations with security and engineering teams.
• Remain updated on emerging vulnerabilities, attacker techniques, exploitation methods, and threats impacting financial platforms.
• Extensive experience in penetration testing, red teaming, offensive security, or security research.
• Proven experience leading offensive security engagements or mentoring security professionals.
• In-depth technical understanding of web, mobile, API, cloud, infrastructure, and identity security.
• Practical experience in identifying and exploiting complex vulnerabilities and chained attack paths.
• Strong familiarity with common application and infrastructure weaknesses, including the OWASP Top 10 and OWASP API Security Top 10.
• Experience in testing authentication, authorization, access control, cryptography, transaction flows, and business logic.
• Comprehensive knowledge of network protocols, operating systems, cloud environments, containers, and modern application architectures.
• Experience with manual testing techniques as well as offensive security tools and frameworks.
• Proficiency in writing scripts or tools in languages such as Python, Go, JavaScript, or Bash.
• Experience in generating clear technical reports and presenting risk to engineering leaders and senior stakeholders.
• Strong understanding of responsible testing practices, rules of engagement, and safe exploitation.
• Ability to balance technical depth with business context and risk prioritization.
• Excellent written and spoken English skills.
• High-impact ownership: shape and lead offensive security for a growing financial platform.
• Hands-on technical work: test real-world systems across mobile, APIs, cloud, identity, and infrastructure.
• Meaningful mission: help protect customers, investments, personal data, and financial transactions.
• Real influence: work directly with engineering and security teams to drive measurable improvements.
• Challenging attack surface: assess complex products spanning stocks, crypto, and U.S. investment services.
• Leadership opportunity: build offensive security standards, mentor the team, and strengthen Ajaib’s security culture.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.