Seclab Indonesia
2022 - Present
Penetration Tester Team Leader
Seclab Indonesia is a Cyber Security research, education & advisory service company in Indonesia.
Lead a team of Penetration Testing projects.
Lead a team of Penetration Testing projects.
- Led and managed 10+ penetration testing engagements per quarter across web applications, mobile apps, and network infrastructures, ensuring on-time and high-quality delivery
- Supervised and mentored a team of 3–9 penetration testers, improving team efficiency and consistency in vulnerability identification and reporting
- Performed pre-engagement validation (“positive testing”), ensuring test coverage alignment and reducing false positives during exploitation phase
- Conducted end-to-end security assessments (black-box & gray-box), identifying critical vulnerabilities (SQLi, RCE, Auth Bypass, Business Logic Flaws related to fraudulent transactions, etc) across 100+ client assets
- Delivered detailed technical reports and executive summaries, enabling clients to prioritize remediation and reduce security risks in production environments
- Reverse-engineered custom client-side encryption mechanisms (AES-CBC-based) to enable request tampering and uncover hidden attack surfaces
- Developed custom Burp Suite extensions to automate decryption, modification, and re-encryption of protected API traffic, improving testing efficiency by ~60%
- Designed and delivered hands-on OSCP training sessions for clients and internal teams, increasing technical capability
- Collaborated with project managers and stakeholders to streamline reporting workflows
- Full Time - Hybrid