Offensive Security Specialist

Offensive Security

3 years experience breaking systems to make them stronger. Specialized in penetration testing, vulnerability research, and building open-source security tools.

๐Ÿ›ก๏ธ 3 Years Exp
๐Ÿ” 14 CVEs
๐Ÿ› ๏ธ 31+ Tools
joel.config.js
// Offensive Security Professional
const joel = {
  name: 'Joel Indra',
  role: 'Offensive Security',
  experience: 3 // years,
  cves: 14,
  tools: 30 // open-source+,
  status: 'Securing the Digital Universe'
};
hack(joel);
Scroll
01

About Me

๐Ÿ”
0
CVEs Discovered
๐Ÿ› ๏ธ
0
Open-Source Tools
๐Ÿ“…
0
Years Experience
๐Ÿ†
0
Bug Bounty Awards
Education

Institute of Technology and Business Stikom Bali

Computer System โ€” Major: Cyber Security

Best Thesis Award, 32nd Graduation Ceremony

Thesis: Information System Security Analysis Using VAPT Methods [Zero Hacking]

Career Highlights
14
CVEs Published
31+
Tools Built
3
Years Active
10+
Bug Bounties

Secured bug bounty awards from SAP, IBM, Cambridge University, Bukalapak, and more. Led penetration testing for PT Bank Central Asia, Bank Indonesia, PT Telkom Indonesia.

Offensive Security Engineer specializing in exploit development, CVE research, and scalable offensive tooling. Proven track record in discovering high-impact vulnerabilities, building production-grade security tools, and executing advanced penetration testing across banking, government, and enterprise environments.

Offensive Security
Web API Mobile (Android/iOS) Desktop Network Cloud IoT Red Teaming Adversarial Emulation Social Engineering
Application Security
API Security WordPress vulnerability research SAST, DAST, IAST methodologies
Exploit Development & Tooling
Custom offensive tools (Python ecosystem) C2 frameworks (AES-GCM) XSS engines OAST systems
Threat Intelligence & Reconnaissance
OSINT Google Dorking attack surface discovery Exposure analysis and vulnerability mapping
Reporting & Communication
Risk-based reporting with business impact translation Stakeholder-focused remediation strategies
02

Hacking Projects

Live from GitHub ยท Updated 3m ago โ†ป
OR Python โ˜… 1

originx

Shodan origin ip recon, single and mass recon, best tools!

Python
โ˜… 1
View on GitHub โ†’
WA Python

waffex

Check all kind of waff on website target

Python
View on GitHub โ†’
CP Python

cpexploiter

Open-source security tool

Python
View on GitHub โ†’
MO Shell

morphtext

Morpthext for prompt injection

Shell
View on GitHub โ†’
WI PowerShell

wincheck

W1ncheck running for do information gathering on your windows system

PowerShell
View on GitHub โ†’
XS Shell

xstinject

XST Injection, this tools for automate check xst injection on your single or mulitple target

Shell
View on GitHub โ†’
TH PowerShell โ˜… 1

thickcheck

This PowerShell script allows you to check the security features (NX Compatibility, DEP, ASLR, CFG) โ€ฆ

PowerShell
โ˜… 1
View on GitHub โ†’
Showing 25โ€“31 of 31 projects

Explore more on GitHub

Dive into detailed documentation, source code, and security researchers' collaborations.

Follow @joelindra
03

Publications

04

Professional Experience

Corporate & Contract

PR
PT. Protergo Siber Security
Offensive Security Engineer Full-time April 2024 โ€“ Present

Executed end-to-end penetration testing across web, API, mobile, cloud, and infrastructure. Identified critical vulnerabilities across application, network, and wireless layers. Conducted Active Directory exploitation and adversarial simulations. Delivered risk-based reports improving client security posture.

SI
PT Sinergi Informatika Semen Indonesia
Penetration Tester Contract August 2023 - April 2024

Conducted penetration testing on Android apps (Akses Toko, Forca HR), iOS apps, web apps (Firms, Forca ERP, SISI ID, SMART Firms), and MRT firewall systems.

XN
PT Xynexis International
Penetration Tester Contract August 2022 - July 2023

Conducted penetration testing for PT Bank Central Asia, Bank Indonesia, PT Telkom Indonesia Tbk, PT SeaBank Indonesia, Prodia, and other high-profile organizations.

DP
Dinas Penanaman Modal dan Pelayanan Terpadu Satu Pintu
Penetration Tester Contract September 2021 - August 2022

Conducted penetration testing to assess and fortify security of Badung Regency Investment Office main website.

PL
Kepolisian Negara Republik Indonesia (Polda Bali)
Penetration Tester & Software Developer Contract July 2021 - August 2022

Developed web application using CodeIgniter 4 for cybercrime case monitoring. Conducted penetration testing for cybercrime monitoring web applications.

Freelance Projects

HF
Hugging Face
Vulnerability Researcher Freelance June 2025 - Present

Uncovering hidden zero-day vulnerabilities. Notable CVE discoveries: CVE-2025-6921, CVE-2025-11231.

OS
OffSec
Dork Researcher Freelance May 2024 - Present

Conducting targeted reconnaissance using advanced search operators. GHDB entries: ghdb/8437, ghdb/8446.

WP
WordPress
Vulnerability Researcher Freelance January 2024 - Present

Uncovering zero-day vulnerabilities. Discovered 12 CVEs including CVE-2024-27996, CVE-2024-30549, CVE-2024-31928, CVE-2024-32534, and more.

??
Confidential
Offensive Consultant Freelance December 2023 - Present

Expert cybersecurity assessments. Specialized in desktop, mobile, web, network, wireless, physical security, and social engineering assessments.

MB
Maybank
Penetration Tester Freelance April 2024 - March 2025

Conducted WiFi penetration testing, desktop penetration testing, network penetration testing, web penetration testing, and mobile app penetration testing on corporate environment. Documented findings and provided remediation recommendations.

Source Code Reviewer Freelance December 2025 - December 2025

Performed secure source code review on critical applications to identify vulnerabilities, insecure coding patterns, and logic flaws. Provided detailed remediation guidance to development teams.

KS
Kiwoom Securities Indonesia
Penetration Tester Freelance May 2024 - August 2024

Conducted desktop penetration testing on endpoint systems to assess security vulnerabilities and enhance desktop security frameworks.

JH
Jadi Hacker
Instructor - Android Penetration Testing Freelance December 2023 - March 2024

Providing comprehensive training on Android Penetration Testing with hands-on approach covering latest techniques and tools.

05

Awards & Speaking

๐Ÿ† Awards & Honors
๐Ÿ›๏ธ
Hall of Fame - SAP Software Company
๐Ÿ›๏ธ
Hall of Fame - IBM Corporation
๐Ÿ›๏ธ
Hall of Fame - Bukalapak E-Commerce
๐Ÿ“œ
Appreciation Letter - Cambridge University
๐ŸŽค Speaking Engagements
Why Ethical Hacking is Necessary
Light Security
Bug Bounty Introduction
linuxhacking.id
Web Hacking
linuxhacking.id
Mobile Hacking
KamarKamsib
06

Certifications

Junior Penetration Tester [PT1]

#68c4116a42043e4019936393 - 2025

Verified

Certified Red Team CredOps Infiltrator [CRT-COI]

#9056AC07 - 2025

Verified

Certified Red Team Analyst [ CRTA ]

#2011532 - 2025

Verified

Certified Process Injection Analyst [ CPIA ]

#d9a2a18b - 2025

Verified

Certified Appsec Practitioner [ CAP ]

#7897347 - 2023

Verified

Certified Blockchain Practitioner [ CBP ]

#7895993 - 2023

Verified

Certified Network Security Practitioner [ CNSP ]

#7896092 - 2023

Verified

Certified Ethical Hacker [ CEH Master ]

#ECC2734851069 โ€“ 2023-2026

Verified

Certified Ethical Hacker [ CEH Practical ]

#ECC1069437825 โ€“ 2023-2026

Verified

Certified Ethical Hacker [ CEH Ansi ]

#ECC7489521630 โ€“ 2021-2024

Verified

Certified Secure Computer User [ CSCUv2 ]

#ECC2467981350 โ€“ 2021

Verified

MikroTik Certified Network Associate [ MTCNA ]

#2104NA4168 - 2021

Verified