Security Consultant
Indexed description
About softScheck APAC
softScheck is a fast-growing IT security consultancy firm in APAC. We provide cybersecurity consultancy services across multiple government agencies, Banks, MNCs, and large corporations.
We're growing our team and looking for talented security professionals to join us. We have two open offensive security consultant roles whether you specialize in penetration testing or red team operations, we want to hear from you. This position is remote-based and requires you to be located in Indonesia, with on-site work required based on certain conditions.
Security Consultant, Penetration Tester
As a member of the penetration testing division, your daily job will include but is not limited to:
- Performing penetration tests across Infra/Networks, Web and Mobile applications, APIs, GenAI/LLM applications, and other relevant attack surfaces.
- Performing secure code review (static and dynamic).
- Performing vulnerability assessment and host configuration review for Windows and Linux systems, databases, network equipment, and product appliances.
- Write a comprehensive penetration testing report and support the customer on the finding remediation through email and conference calls.
- Collaborate with the rest of the teams on improvement and problem solving.
- Lead/facilitate internal meetings as well as client meetings in support of project delivery.
- Provide support for sales by providing project scoping to potential clients.
Requirements:
- Independent with contributor mindset and committed with a high-performance culture.
- Minimum of 2-3 years’ experience in performing penetration testing.
- Good English communication to articulate, explain and support the client on the finding remediation.
- Responsive, humble, responsible, and open-minded.
- Strong problem-solving and prioritization skills, with the ability to manage multiple tasks and meet tight deadlines.
- At least one relevant web penetration testing certification such as BSCP, CWEE, eWPTX, OSWA, or OSWE
Good to have:
- Relevant certifications such as OSCP, CRT, CPTS, PNPT, or eMAPT
- CTF and bug bounty experience
Security Consultant, Red Team
As a member of the red team division, your daily job will include but is not limited to:
- Execute hands-on red team operations simulating real-world threat actors (external/assumed breach) and adversary emulation across enterprise environments including endpoints, servers, identity platforms, applications, and cloud infrastructure.
- Contribute to the design and execution of end-to-end attack campaigns under the guidance of the red team manager.
- Identify, validate, exploit, and chain vulnerabilities to demonstrate realistic attack paths and business risks
- Conduct research into emerging threat actor tactics, techniques and procedures (TTPs), offensive security tooling and adversary simulation approaches
- Write comprehensive red team reports and deliver findings presentations to both technical and non-technical stakeholders
Requirements:
- 4–5+ years of relevant experience in Red Teaming, Offensive Security Operations, Penetration Testing, Security Research, or similar roles
- Proven hands-on experience with EDR evasion and bypassing security controls and detections
- Proficient with two or more programming languages such as C, C++, C#, or Python
- Experience with command-and-control frameworks, data obfuscation/encryption, and Active Directory exploitation
- Strong understanding of adversary tactics, techniques, and procedures (TTPs)
- Hands-on experience with manual exploitation, attack chaining, writing custom scripts, tooling, or payloads
- Preferred Certifications: OSCP, OSEP, CRTE, CRTO, CRTL, or CAPE similar red team certifications
Join softScheck!
softScheck is committed to building our team with high performing culture that emphasizes servant leadership and continuous improvement which constantly spur one another towards bringing the best version of oneself.
Your personal data will be processed for the purpose of managing softScheck's recruitment related activities, which includes setting up and conducting interviews and tests for applicants, evaluating, and assessing the results and as is otherwise needed in the recruitment and hiring process. Please consult our Privacy Notice (https://www.softscheck-apac.com/sg/privacy-policy/), to know more about how we collect, use, and transfer the personal data of our candidates.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search