← All jobs

Security Engineer, Junior Penetration Tester

StraitsX · Jakarta, Jakarta, Indonesia

onsitefull-timejunior level

About this role

About The Role

We are seeking a motivated Junior Security Engineer to join our Security team in Jakarta, Indonesia. This is an entry-level role designed for a budding security professional who is passionate about offensive security. You will support the team in identifying vulnerabilities across our infrastructure and applications, learning to provide clear remediation advice, and helping to build a more resilient organization. 

What You Will Do

  • Conduct vulnerability assessments and penetration tests across web, mobile (iOS/Android), and network environments.
  • Drafting penetration test reports that detail findings, risk levels, and step-by-step reproduction instructions.
  • Collaborate with developers to help them understand security findings and verify that fixes have been correctly implemented.
  • Keep up with the latest CVEs, OWASP updates, and security research to bring fresh perspectives to the team.

What Are We Looking For

  • Bachelor’s degree in Computer Science, Information Security, or a related field (Recent graduates are welcome).
  • A strong understanding of networking (TCP/IP), web technologies (HTTP/HTTPS), and basic OS security (Linux/Windows).
  • Familiarity with the OWASP Top 10 and common vulnerability classes (SQLi, XSS, Broken Auth).
  • OSCP is highly preferred, but we will consider candidates with eJPT, PNPT, or CEHP, provided they show a strong desire to obtain their OSCP within the first year.
  • Basic experience with tools like Burp Suite (Community/Pro), Nmap, and SQLmap.
  • Ability to follow a testing methodology and document technical steps clearly.
  • Preferred but not required: have experience or be interested in smart contract audit.

About StraitsX

StraitsX is a leading digital payment infrastructure provider that is powering trusted, programmable finance across borders and blockchains globally. As a Major Payment Institution licensed by the Monetary Authority of Singapore and one of the first stablecoin issuers under the Stablecoin Issuance Framework (SCS), StraitsX sets new standards for regulatory clarity and operational integrity. Through its issuance of XSGD and XUSD stablecoins, StraitsX enables institutions, fintechs, and Web3 platforms to move value seamlessly across currencies, networks, and jurisdictions. Its modular infrastructure, including APIs, liquidity rails, and tokenised settlement systems, supports real-world adoption of stablecoins at scale while abstracting technical complexity. Operating in a highly regulated environment, StraitsX partners with global businesses and developers to deliver interoperable, reliable, and future-ready payment solutions—bridging the gap between traditional finance and the digital economy.

Jobb.ai is an independent skill benchmarking platform. Applications are submitted on the employer's official website.