Offensive Security Engineer

3 Months ago • 3 Years + • Cyber Security

Job Summary

Job Description

Job Details

About the Role

As a member of the Offensive Security Team you'll help secure GoTo from threats and improve its cyber resilience. Utilizing your expertise you'll uncover security vulnerabilities and weaknesses in People, Process and Technology within the GoTo's environment by working on various Offensive Security Assessments. You'll be closely working with Engineering Teams which will help you gain a comprehensive understanding of how things are built, which you can leverage to find out security weaknesses. Moreover you would also be collaborating with other Information Security Teams on initiatives to help improve the security posture of GoTo.

What You Will Do

    • Conduct regular Web Application, Mobile Application, and Network penetration tests independently or as part of the team.
    • Participate in Red Team and Blue Team exercises to enhance the organization’s detection and response capabilities.
    • Validate submissions as part of the Bug Bounty Program.
    • Provide support during Security Incidents to uncover root causes and provide recommendations for detection and prevention.
    • Perform thorough, clear, and concise documentation of assessment findings and remediation recommendations.
    • Communicate and collaborate effectively with Engineering and other Security Teams to share findings and help prioritize remediation.
    • Keep current with the latest Attack methodologies, Vulnerabilities, Tools, and Security Threats.

What You Will Need

    • 3+ years of experience performing Offensive Security Assessments - covering at least two of the following domains: web application security, mobile application security, web/mobile application development and infrastructure security.
    • Proven penetration testing capabilities in an enterprise environment and a strong understanding of OWASP Web and Mobile Security Standards.
    • Possess an adversary mindset with a good understanding of the Objective, behavior, and TTPs of threat actors. 
    • Experience reporting assessment findings and providing pragmatic recommendations for remediation.
    • Experience reading and writing code in at least one programming language - Golang, Java, Swift and Objective C
    • Ability to write/modify Offensive Security tools, exploit codes, and develop capabilities to support adversarial emulation.
    • Experience with evading enterprise-grade defenses such as EDR, Email Security, and Network Controls.
    • Experience with cloud platforms such as AWS, GCP, or Azure.
    • Good verbal communication skills to interact with the team and stakeholders effectively, and good written skills to write clear and concise reports.
    • Having professional certification(s) related to Offensive Security such as GIAC (GPEN, GCPN, GWAPT, GMOB, GXPN) or OffSec (OSCP, OSEP, OSWA, OSWE, OSED, OSMR ) or CREST (CCSAS, CCT-INF) or Zero-Point Security (CRTO, CRTL) is a bonus.
About the Team

The Offensive Security Team performs various assessments to proactively identify vulnerabilities and weaknesses in GoTo’s Applications, Systems, and Networks before adversaries. The Team works on initiatives to enhance the Threat Prevention, Threat Detection, and Incident Response capabilities of GoTo.

About GoTo Group
GoTo Group is the largest digital ecosystem in Indonesia with its mission to “Empower Progress’ by offering technological infrastructure and solutions for everyone to access and thrive in the digital economy. The GoTo ecosystem consists of on-demand transportation services, food and grocery delivery, logistics and fulfillment, as well as financial and payment services through the Gojek and GoTo Financial platforms.It is the first platform in Southeast Asia that hosts these crucial cases in a single ecosystem, capturing the majority of Indonesia’s vast consumer household.

About Gojek 
Gojek is Southeast Asia’s leading on-demand platform and pioneer of the multi-service ecosystem with over 2.5 million driver partners across the regions offering a wide range of services such as transportation, food delivery, logistics and more. With its mission to create impact at scale, Gojek is committed to resolving consumer problems and raising standards of living by connecting consumers to the best providers of goods and services in the market.

About GoTo Financial
GoTo Financial accelerates financial inclusion through its leading financial services and merchants solutions. Its consumer services include GoPay and GoPayLater and serve businesses of all sizes through Midtrans, Moka, GoBiz Plus, GoBiz, and Selly. With its trusted and inclusive ecosystem of products, GoTo Financial is open to new growth opportunities and aims to empower everyone to Make It Happen, Make It Together, Make It Last.

GoTo and its business units, including Gojek and GoToFinancial ("GoTo") only post job opportunities on our official channels on our respective company websites and on LinkedIn. GoTo is not liable for any job postings or job offers that did not originate from us. You should conduct your own due diligence to prevent being victims of any fake job scams, if they did not originate from GoTo's official recruitment channels.

Similar Jobs

Eloelo - DevOps Engineer

Eloelo

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Barbaricum - Intelligence Operations Integrator

Barbaricum

Panama City, Florida, United States (On-Site)
3 Months ago
Luxoft - Senior Java Developer

Luxoft

Wrocław, Lower Silesian Voivodeship, Poland (On-Site)
2 Months ago
PwC - AES-Oracle APEX_VBCS_JCS- Senior Associate - Consult

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Luxoft - Security FW (PSP) / Memory Firmware (ABL FW) Developer

Luxoft

Bengaluru, Karnataka, India (On-Site)
2 Months ago
HP - Cybersecurity Project Manager

HP

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Varonis  - Product Security GRC

Varonis

Miami, Florida, United States (On-Site)
2 Months ago
Saviynt - Senior Engineer II, Software Engineering

Saviynt

Bengaluru, Karnataka, India (Hybrid)
3 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

TV2Z - iOS Developer (4-6 years)

TV2Z

Hyderabad, Telangana, India (On-Site)
6 Months ago
Krafton  - [Publishing Platform Div.] Game Platform Backend Engineer (2년 ~ 10년)

Krafton

Seoul, South Korea (On-Site)
3 Months ago
ByteDance - Backend Software Engineer, Authorization - 2025 Start

ByteDance

Singapore (On-Site)
3 Months ago
Google - Software Engineer III, Zamm

Google

(On-Site)
2 Months ago
Google - Software Engineer, Google Cloud Computing, Cloud Learning Services

Google

Cambridge, Massachusetts, United States (On-Site)
3 Months ago
eBay - Senior Staff Engineer

eBay

Toronto, Ontario, Canada (Hybrid)
4 Months ago
Logifuture - Java Software Developer

Logifuture

Kragujevac, Serbia (Hybrid)
3 Months ago
ION - Technical Support Analyst, Jersey City - 9781

ION

Jersey City, New Jersey, United States (On-Site)
4 Months ago
ByteDance - Software Engineer — Data Security

ByteDance

San Jose, California, United States (On-Site)
3 Months ago
Extreme Network - Senior Linux Software Development Engineer (9521)

Extreme Network

Toronto, Ontario, Canada (Hybrid)
4 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

Omnissa - Staff Engineer - .Net Engineer

Omnissa

Bengaluru, Karnataka, India (Hybrid)
3 Months ago
PwC - AES SAP PTP-STO Senior Manager - Operate

PwC

Hyderabad, Telangana, India (On-Site)
4 Months ago
Google - Databases Site Reliability Engineer

Google

Bengaluru, Karnataka, India (On-Site)
3 Months ago
PwC - IN_Senior Associate_MDM Consultant_Data & Analytics_Advisory_PAN  India

PwC

Kolkata, West Bengal, India (On-Site)
3 Months ago
Logitech - Global Product Planner/Analyst

Logitech

Chennai, Tamil Nadu, India (Hybrid)
4 Months ago
PwC - TAX_Canada BCS_Senior Associate _Kol/Bang/Hyd

PwC

Kolkata, West Bengal, India (On-Site)
4 Months ago
Oil and Gas Job Search  - Designer to Lead Designer - Civil 3D - Bangalore

Oil and Gas Job Search

Samudrapur, Maharashtra, India (On-Site)
5 Months ago
Crunchyroll - Senior Manager, Partnership Marketing - APAC

Crunchyroll

Mumbai, Maharashtra, India (On-Site)
2 Months ago
Haleon - Talent Acquisition Partner

Haleon

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
Nielsen Holdings - Senior/Lead Devops Engineer - AM-TECH-DA-04

Nielsen Holdings

Gurugram, Haryana, India (Hybrid)
3 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

ZeroFox - Physical Security Analyst

ZeroFox

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Deliveroo - Security Software Engineer

Deliveroo

Hyderabad, Telangana, India (On-Site)
3 Months ago
PwC - IN_Manager_GIS_Citizen Services_Advisory_BANGALORE

PwC

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Google - Security Engineer, Waze

Google

(On-Site)
2 Months ago
ION - Senior Security Architect

ION

London, England, United Kingdom (On-Site)
4 Months ago
Barracuda Networks  Inc  - Cybersecurity Analyst

Barracuda Networks Inc

Chelmsford, England, United Kingdom (Hybrid)
2 Months ago
Codeninja - Information Security Engineer

Codeninja

Lahore, Punjab, Pakistan (On-Site)
3 Months ago
PwC - IN_Associate_Internal Audit Services_Internal  Audit_Advisory_Gurgaon

PwC

Gurugram, Haryana, India (On-Site)
4 Months ago
Fortra - Professional Services Consultant - Cybersecurity

Fortra

Saudi Arabia (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

About The Company

GoTo is the largest technology group in Indonesia, combining on-demand and financial services through the Gojek and GoTo Financial brands. It is the first platform in Southeast Asia to host these two essential use cases in one ecosystem, capturing a majority of Indonesian consumer household expenditure.


GoTo’s mission is to “Empower Progress” by offering an unparalleled selection of goods and services through a comprehensive merchant and partner network and promoting financial inclusion through its leading payments and financial services business.

Jakarta, Jakarta, Indonesia (On-Site)

Jakarta, Jakarta, Indonesia (On-Site)

Jakarta, Jakarta, Indonesia (On-Site)

Bengaluru, Karnataka, India (Hybrid)

Surabaya, East Java, Indonesia (On-Site)

Surabaya, East Java, Indonesia (On-Site)

Bengaluru, Karnataka, India (Hybrid)

Jakarta, Jakarta, Indonesia (On-Site)

Bengaluru, Karnataka, India (On-Site)

Jakarta, Jakarta, Indonesia (On-Site)

View All Jobs

Get notified when new jobs are added by GoTo Group

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug