About the job
About Amartha
At Amartha, we are dedicated to empowering micro-businesses across Indonesia, fostering growth and financial equality. We have proudly supported over 3.6 million entrepreneurs, primarily women, by disbursing IDR 37 trillion in funding. As we approach 2026, Amartha is transforming into a technology-driven financial ecosystem, broadening our services in lending, funding, and payments. Through innovative digital solutions, we strive to improve accessibility, streamline processes, and deliver a seamless user experience.
About the Role
The Security Engineering Lead is a pivotal role within Amartha, acting as a guardian to spearhead various Information Security initiatives that protect our organization from both internal and external threats.
About the Team
The Information Security team at Amartha consists of dynamic, highly analytical professionals who prioritize security and privacy by design throughout all product lifecycle and engineering processes. We are passionate about being the security enablers for Amartha’s systems.
Responsibilities
- Lead, mentor, and develop a high-performing team of offensive security engineers, cultivating a culture of innovation and continuous learning.
- Design and implement sophisticated offensive security operations and adversary simulations against critical financial systems and data, utilizing frameworks such as MITRE ATT&CK.
- Ensure all offensive activities and remediation efforts comply with Indonesia's financial sector regulations and the Personal Data Protection Law (UU PDP).
- Conduct comprehensive vulnerability research and penetration testing across web, mobile, API, cloud (GCP), and corporate infrastructure.
- Enhance efficiency and scalability of offensive security operations through the development of custom scripts and automation.
- Identify current and emerging technology challenges, including security trends and vulnerabilities, via diverse security assessments.
- Manage and address complex technical issues in a fast-paced business environment.
- Conduct proactive investigations to analyze security weaknesses and recommend strategies.
- Engage in threat intelligence activities.
- Collaborate closely with internal and external teams to implement security solutions.
- Research and integrate new technological solutions to bolster organizational security posture.
- Define and document system security requirements and recommend solutions.
- Monitor systems for anomalous behavior and establish preventive measures.
- Oversee bug bounty program initiatives.
- Improve the effectiveness of security-related processes through automation.
