KPMG logo

Penetration Tester (Red Team)

KPMG • Tangerang, Banten, Indonesia

onsitefull-time
Posted Oct 2, 2026Apply by Nov 1, 2026

**Role & seniority: ** Cyber Defense & Incident Response professional (level not explicitly stated); role focused on hands-on offensive security, forensics, and IR within Digital Trust & Cyber.

**Stack/tools: ** Penetration testing and security testing across web apps, networks, mobile, wireless, social engineering, cloud; digital forensics and incident response; uses tools typical to red teaming/forensics (specific tools not listed).

  • Certifications (preferred): OSCP, OSWE, OSCE/ OSEE/ OSWP, CEH, CRRP.

  • Top 3 responsibilities:

    1. Advise and deliver engagements in penetration testing, red teaming, digital forensics, and incident response.

    2. Support delivery/engagement management: scoping, deliverables, financial/risk management.

    3. Client/team collaboration: develop relationships, support leadership, embed effective working practices, and contribute to business development.

  • Must-have skills:

    • Proven experience in cyber defense and incident response, including pen testing/red team/forensics/IR (professional services or in-house).

    • Ability to mimic adversary TTPs and perform exploitation leading to access/privilege escalation.

    • Experience producing detailed reports (attack narratives, evidence, recommendations).

    • Strong English communication, project management, and attention to detail; manage multiple cases and adapt to varying environments/engagement types.

  • Nice-to-haves:

    • Re

Full Description

KPMG Digital Trust & Cyber helps organizations with tailored solutions for cyber security and data protection. Our professionals assist clients to address their concerns around Confidentiality, Integrity, Availability and Privacy of their technology, business systems, and information assets to build enterprise-wide security strategies to help move the organizations from reacting in crisis mode to having proactive, value-added business solutions, we help them carry security throughout their entire organization.

We are seeking for someone who have proven track record in cyber defense and incident response area with experience on penetration testing, red team, digital forensics, and incident response for professional working experience, within professional services or an in-house information security function.

What you will do

  • Advising and delivering projects on penetration testing, red teaming, digital forensics, and incident response.
  • Support project and engagement management teams to deliver high quality work in a timely manner to include: scoping activities, production of deliverables, financial management & engagement and risk management.
  • Developing constructive relationships, both internal and external, and support the business development activity of senior members of the team.
  • Supporting leadership of the team in the embedding effective working practices.
  • Recognize the importance of continuous self-development and actively strive to achieve this.

Desired Skills & Experience Excellent academic background in fields related to Computer Science, Cyber, Information Security, IT or relevant STEM subjects. Experienced in performing Web Application Security testing, Network Penetration Testing, Mobile Application Testing, Wireless Security Testing, Social Engineering, and Cloud Security Testing. Experienced in mimicking real-world adversary tactics, techniques, and procedures (TTPs) to evaluate organizational security postures Experience in identifying and exploiting weaknesses in a system’s architecture to gain access and escalate privileges across environments. Experience in delivering detailed reports, including attack narratives, evidence collection, and recommendations for improving security. Ability to build strong and lasting internal and client relationships. Good English communication skills (both written and oral) and project management skills. Strong attention for detail and the ability to manage multiple simultaneous cases and flexibility to adapt to a variety of different engagement types, working hours and work environments and locations.

Preferably hold one of the following certifications: OSCP, OSWE, OSCE, OSEE, OSWP, CEH & CRRP.

Only shortlisted candidates will be contacted by KPMG Siddharta Advisory Recruitment team. All applicants' information and personal data will be treated as strictly confidential and used for recruitment purposes only.

Web Application Security TestingNetwork Penetration TestingMobile Application TestingWireless Security TestingSocial EngineeringCloud Security TestingRed TeamingDigital ForensicsIncident ResponseAdversary Tactics, Techniques, And ProceduresPrivilege EscalationSecurity ReportingProject ManagementClient Relationship ManagementRisk ManagementEnglish Communicationmulti-location

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.