Deskripsi
- Conduct end-to-end security testing on web applications, mobile apps (iOS/Android), APIs, network infrastructure, and internal systems.
- Simulate advanced real-world attack scenarios to evaluate the effectiveness of our detection and response capabilities.
- Actively monitor global cyber threat intelligence, zero-day vulnerabilities, and new CVEs.
- Perform rapid impact analysis to determine if new threats affect BFI's IT environment.
- Produce clear CVE Impact Reports & Advisories with actionable mitigation/remediation steps for technical teams.
- Work closely with Developers, DevOps, and IT Infrastructure teams to guide and verify security flaw fixes.
- Translate complex technical vulnerabilities into executive-ready risk reports highlighting business impacts.
- Minimum 5 years of hands-on experience in Cybersecurity, specifically as a Penetration Tester, Red Team Operator, or Vulnerability Assessor.
Mandatory Certification (Must hold at least ONE)
- OSCP (Offensive Security Certified Professional)
- OSWE (Offensive Security Web Expert)
OSEP (Offensive Security Experienced Penetration Tester)(Other certifications like GPEN, GWAPT, GXPN, HTB CPT/CWEE, eCPPT, eWPTX, or CPENT are strong advantages).
Bug Bounty Experience (Huge Plus)
- Proven track record of discovering vulnerabilities via official platforms (HackerOne, Bugcrowd, Intigriti) or corporate VDPs.
- Evidence required: Profile links, Hall of Fame (HoF) mentions, or official acknowledgment certificates.