Security Engineer - Offensive Security

Traveloka.wd3.traveloka

Apply to this job
Indonesia - Jakarta, Green Office Park 1 Until 8/22/2026 First posted June 23, 2025 Last posted June 23, 2025
Job description

It's fun to work in a company where people truly BELIEVE in what they're doing!

‎ 

‎ 

Job Description

Securing an organization and its information systems requires a holistic approach that includes continuous security verification, extending beyond standard testing and assessment methods. By assuming the role of a threat actor, the Offensive Security Team delivers valuable findings and insights with practical impact, which must be prioritized. Utilizing an offensive or attacker’s mindset, the team continuously reviews everything within the organization—including applications, infrastructure, and business processes—to identify potential loopholes that could be exploited by a real attacker to compromise the organization.
 
As an Offensive Security team member at Traveloka, your daily tasks encompass penetration testing, adversarial emulation exercises, threat intelligence, maintaining offensive threat models, developing offensive security tools, reviewing bug bounty reports, and hunting vulnerabilities based on commonalities, internal trends, and latest threats. Your coverage area is comprehensive, assessing the organization from an attacker's perspective. We are seeking a candidate with robust cybersecurity technical expertise and solid understanding about cyber intrusion in an organization. This role is crucial for ensuring we stay abreast of the latest threats and are capable of identifying unique and complex challenges specific to Traveloka.

‎ 

Requirements

Proven track record of highly technical cybersecurity expertise such as CTF (Capture the Flag), bug bounty, publication, blog, open source security tool contribution, speaking engagement, or Offensive Security certification.

Fluent in programming with any language and shell scripting.

Experience in Windows security, Unix security, network security, and web application security is a must.

Experienced in cloud computing like AWS and GCP is a plus.

Experienced in red or purple team exercise is a plus.

Able to practically demonstrate various security vulnerabilities, exploits, and attacks in web applications, computer infrastructure, and personal computers.

Understand about cybersecurity threats related to travel and tech industries.

Excellent written and verbal communication skills

Dedication to cybersecurity alongside a strong commitment to continuous learning about new technologies

‎ 

If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!

About this role

Summary

Conduct penetration testing and threat intelligence to secure the organization.

Job title

Security Engineer - Offensive Security

Experience level

3+ years

Industry

travel

Location requirements

Jakarta, Indonesia; remote work not allowed

Salary

Not specified

Management role

No

Skills & keywords

Required skills

cybersecurityCTFbug bountyprogrammingshell scriptingwindows securityunix securitynetwork securityweb application security

Preferred skills

cloud computingAWSGCPred teampurple team

Specializations

penetration testingthreat intelligencevulnerability huntingcloud computingoffensive security
Locations

Structured locations inferred from the posting.

Unknown location

On-site