S

Security Engineer, Junior Penetration Tester

StraitsX Special capital Region of Jakarta, Java, Indonesia

onsite
Posted Feb 10, 2026

About The Role We are seeking a motivated Junior Security Engineer to join our Security team in Jakarta, Indonesia. This is an entry-level role designed for a budding security professional who is passionate about offensive security. You will support the team in identifying vulner

Full Description

About The Role We are seeking a motivated Junior Security Engineer to join our Security team in Jakarta, Indonesia. This is an entry-level role designed for a budding security professional who is passionate about offensive security. You will support the team in identifying vulnerabilities across our infrastructure and applications, learning to provide clear remediation advice, and helping to build a more resilient organization. What You Will Do Conduct vulnerability assessments and penetration tests across web, mobile (iOS/Android), and network environments. Drafting penetration test reports that detail findings, risk levels, and step-by-step reproduction instructions. Collaborate with developers to help them understand security findings and verify that fixes have been correctly implemented. Keep up with the latest CVEs, OWASP updates, and security research to bring fresh perspectives to the team. What Are We Looking For Bachelor’s degree in Computer Science, Information Security, or a related field (Recent graduates are welcome). A strong understanding of networking (TCP/IP), web technologies (HTTP/HTTPS), and basic OS security (Linux/Windows). Familiarity with the OWASP Top 10 and common vulnerability classes (SQLi, XSS, Broken Auth). OSCP is highly preferred, but we will consider candidates with eJPT, PNPT, or CEHP, provided they show a strong desire to obtain their OSCP within the first year. Basic experience with tools like Burp Suite (Community/Pro), Nmap, and SQLmap. Ability to follow a testing methodology and document technical steps clearly.

Preferred but not required: have experience or be interested in smart contract audit.

Vulnerability AssessmentsPenetration TestingNetworkingWeb TechnologiesOS SecurityOWASP Top 10SQL InjectionCross-Site ScriptingBurp SuiteNmapSQLmapTesting MethodologyTechnical DocumentationSmart Contract Auditmulti-location

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.