job description
Join Avensys Consulting as a Senior Penetration Tester in the vibrant tech hubs of Bali, Indonesia. This contract role offers a unique opportunity to work with cutting-edge cybersecurity tools and methodologies while enjoying the islandâs dynamic work-life balance.
As a Senior Penetration Tester, you will lead security assessments, identify vulnerabilities, and provide actionable insights to fortify our clientsâ digital infrastructures. Your expertise will be critical in safeguarding sensitive data and ensuring compliance with global security standards.
This position is ideal for seasoned professionals passionate about ethical hacking, threat modeling, and security architecture. Whether youâre based in Canggu, Ubud, or any of Baliâs tech-friendly locales, youâll collaborate with a global team while contributing to high-impact projects.
Note: Remote work options may be available for candidates based in Bali.
Responsibility
- Conduct comprehensive penetration tests on web applications, networks, and systems to identify security flaws.
- Develop and execute test plans, including vulnerability scans, exploit simulations, and social engineering assessments.
- Document findings in detailed reports with prioritized remediation recommendations for stakeholders.
- Collaborate with development and IT teams to implement security best practices and mitigate risks.
- Stay updated on emerging threats, zero-day vulnerabilities, and advanced attack techniques.
- Perform security architecture reviews and provide guidance on secure coding practices.
- Assist in compliance audits (e.g., ISO 27001, PCI DSS, GDPR) and ensure adherence to industry standards.
- Mentor junior team members and share knowledge through workshops or training sessions.
Qualifications
- Bachelorâs degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
- 5+ years of hands-on experience in penetration testing, ethical hacking, or red teaming.
- Proficiency with tools like Burp Suite, Metasploit, Nessus, Wireshark, and OWASP ZAP.
- Strong understanding of networking protocols, encryption, and secure SDLC practices.
- Certifications such as OSCP, CEH, CISSP, or GIAC (highly preferred).
- Experience with scripting languages (Python, Bash, PowerShell) for automation and custom exploit development.
- Excellent analytical, problem-solving, and communication skills.
- Ability to work independently in a fast-paced, contract-based environment.