Back to search
FLOQ Linkedin · Posted yesterday

Penetration Tester

Jakarta

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Role summary

We operate a regulated cryptocurrency exchange and a B2B platform that routes sizeable crypto flows on behalf of our partners. In this environment, the interval between an unpremeditated authorization flaw and an actual loss of funds is short, and offensive security functions as a direct financial control rather than a compliance formality.

The Lead Penetration Tester owns the offensive security function end to end. This is a senior, hands-on role: the successful candidate performs testing directly while also setting strategy, developing tooling, and representing offensive security to engineering and leadership. Findings from this role directly inform release decisions.


Core responsibilities:

Bug-bounty program

Serve as the accountable owner of the bug-bounty program, responsible for its scope, operational quality, and researcher relationships.

  • Define and maintain program scope, rules of engagement, and reward tiers appropriate to a platform that handles material financial value.
  • Triage inbound submissions: reproduce reported issues, assign severity using CVSS together with business-impact context, and de-duplicate findings.
  • Manage the researcher relationship through timely, accurate, and technically credible responses in order to retain high-quality participants.
  • Drive remediation to closure with engineering teams, track resolution against defined SLAs, and report program health and trends to leadership.
  • Translate recurring vulnerability classes into secure-development guidance to prevent recurrence.

Randomized penetration testing of new features

Establish and operate a continuous, randomized penetration-testing cadence against new and modified features. This activity is a direct loss-prevention measure.

  • Maintain a rotating testing schedule so that new features receive adversarial assessment before and shortly after release, prioritized by proximity to fund movement.
  • Concentrate testing on the highest-impact loss scenarios, including account takeover, authorization bypass, unauthorized fund transfer, API and business-logic abuse, and the integrity of B2B crypto flows.
  • Document findings with reproducible steps, a clear assessment of exploitability, and a realistic estimate of financial exposure, together with concrete remediation guidance.
  • Develop and maintain reusable tooling and automation so that testing coverage scales with engineering velocity.

Additional responsibilities

  • Define the offensive security strategy and roadmap, and mentor other members of the security team.
  • Scope and coordinate third-party penetration tests where independent assurance is required for regulatory or partner purposes.
  • Contribute an offensive security perspective to the threat modelling of major new features.
  • Support the security compliance obligations of a regulated exchange, translating technical findings into terms suitable for auditors and regulators.


Required qualifications:

  • A minimum of five years' experience in offensive security or penetration testing, including experience leading engagements or a small team.
  • Demonstrable, hands-on expertise across web, API, cloud (AWS preferred), and authentication and identity attack surfaces.
  • A strong command of business-logic and authorization vulnerabilities, beyond automated scanning.
  • Proven experience operating or substantially contributing to a bug-bounty program, including triage, severity assessment, and researcher management.
  • Proficiency in scripting and automation (Python, Bash, or equivalent) sufficient to build repeatable tooling.
  • Excellent written and verbal communication, with the ability to convey a critical finding clearly to both engineering and executive audiences.

Preferred qualifications

  • Experience in fintech, payments, or cryptocurrency and blockchain security, including familiarity with custody, wallet, on- and off-ramp, and transaction-integrity attack surfaces.
  • Relevant certifications such as OSCP, OSEP, OSWE, or GXPN.
  • Experience operating within regulated environments and applicable security compliance frameworks; familiarity with Indonesian financial-sector regulation (for example, OJK requirements) is a strong advantage.
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search