Position Overview:
- Lead the penetration testing (Offensive Security) capabilities for all Web applications, APIs, Mobile backends, and AI/LLM-integrated applications of the Company/Subsidiaries.
- Build and operate a continuous testing model (CTEM/PTaaS): combining in-depth manual testing with automation and integration into CI/CD under the DevSecOps model.
- Perform and coordinate penetration testing across Web/API application environments, cloud-native infrastructure (Container, Kubernetes, Serverless), and the software supply chain.
- Translate testing results into risk mitigation recommendations for the Blue Team/SOC and development teams; lead Purple Team activities.
- Standardize methodologies (OWASP WSTG/ASVS, PTES, NIST SP 800-115), processes, and ensure compliance with ISO/IEC 27001:2022, PCI DSS 4.x, Cybersecurity Law, and Personal Data Protection Law No. 91/2025/QH15.
- Manage resources, develop the team, and report application risk exposure levels to senior management.
Key Responsibilities:
1. Build and Operate Continuous – Automated Testing Capabilities
- Deploy and operate testing platforms and toolsets (Burp Suite Professional/Enterprise, ZAP, Nuclei, SAST/DAST/SCA/IAST).
- Integrate security testing into the CI/CD pipeline (shift-left), manage SBOM and software supply chain risks.
- Research new CVEs, write PoCs/exploit code, develop internal tools (Python/Go), and automate testing processes.
- Apply AI/LLM to accelerate analysis and report preparation, while controlling data leakage risks when using AI.
- Advise senior management on new application security technologies and solutions for entities within the ecosystem.
2. Penetration Testing of Web, API, and AI-Integrated Applications
- Perform in-depth manual testing according to OWASP WSTG/ASVS: business logic flaws, IDOR/BOLA, race conditions, SSRF, deserialization, HTTP request smuggling, client-side attacks.
- Test APIs (REST/GraphQL/gRPC/Webhook) according to the OWASP API Security Top 10; test authorization, OAuth 2.0/OIDC, SAML, JWT, SSO, and passwordless authentication (passkey) flows.
- Test AI/LLM-integrated and Agentic AI applications: prompt injection, data leakage through RAG, abuse of agent/tool privileges, and MCP connection controls.
- Provide exploitation evidence (PoC), rank risks according to CVSS 4.0 linked to business impact; perform retesting to verify remediation (Remediation Verification).
- Coordinate with relevant departments to develop remediation and reassessment plans.
3. Support Blue Team/SOC in Enhancing Defensive Capabilities (Purple Team)
- Convert attack scenarios into detection use cases based on MITRE ATT&CK; measure detection and response capabilities.
- Advise on application defense architecture: WAF/WAAP, API Gateway, bot and API abuse protection, and Zero Trust principles.
- Monitor the vulnerability remediation lifecycle (MTTR), and provide early warnings of exposure risks on the Internet attack surface (EASM).
4. Standardize Processes, Methodologies, and Compliance
- Develop and periodically review processes, regulations, checklists, and bilingual Vietnamese–English penetration testing report templates.
- Ensure testing activities comply with ISO/IEC 27001:2022, PCI DSS 4.0.1, NIST CSF 2.0, Cybersecurity Law, Personal Data Protection Law No. 91/2025/QH15, and industry-specific regulations.
- Manage, back up, and upgrade the testing lab infrastructure; strictly protect sensitive data generated during testing.
5. Team Management, Resource Coordination, and Reporting
- Assign tasks, monitor quality, and review all reports before release.
- Develop capability development roadmaps, training programs, and performance evaluations for the team.
- Manage independent penetration testing vendors, Bug Bounty/VDP programs, and tool budgets.
- Periodically report application risk and exposure dashboards to senior management.
Job Requirements:
Mandatory Requirements:
- Bachelor’s degree or higher in Information Technology/Information Security. Candidates from other majors are accepted if they can demonstrate equivalent hands-on capabilities (certifications, CVEs, Bug Bounty, CTF).
- Professional English: ability to read technical documentation and write reports.
- Cloud & AI: AWS/Azure/GCP security certifications, CCSP; training courses/certifications in AI Security – AI Red Teaming (e.g., SANS SEC535).
- (Acceptable alternative evidence of capabilities: HTB CPTS/CBBH/CWEE, PNPT; rankings on HackerOne/Bugcrowd/Intigriti; published CVEs; national/international CTF achievements.)
- More than 6 years of experience in IT/Information Security.
- More than 4 years of direct experience in Web/API application penetration testing (excluding time spent purely on system operations).
- More than 2 years of experience managing a technical team of 3 or more members, or serving as Technical Lead for a Group-scale penetration testing project.
- Have led or directly performed at least 20 Web/API application penetration testing projects.
Preferred:
- Strong preference (Web/API application penetration testing): OSCP/OSCP+, OSWE, OSWA, Burp Suite Certified Practitioner (BSCP), GWAPT (SANS SEC542).
- Additional specialization: SANS SEC522 (Application Security), SEC540 (Cloud Native Security & DevSecOps), SEC588 (Cloud Penetration Testing), SEC560, OSEP, CRTO, CREST CPSA/CRT/CCT.
- Management certifications: CISSP, CISM, CISA, or ISO/IEC 27001 Lead Auditor/Lead Implementer are an advantage.
- Experience in highly regulated environments: finance – banking, aviation, real estate, commerce, and services; familiarity with the Group’s ecosystem is an advantage.
- Experience testing cloud-native applications, large-scale APIs, and AI/LLM-integrated applications is a significant advantage.
- Preference for candidates who have worked at penetration testing/Red Team service companies or participated in Bug Bounty programs.
- Knowledge of the Group’s organizational structure, business areas, and culture is an advantage.
Knowledge:
- OWASP standards: Top 10 (latest version), WSTG, ASVS, API Security Top 10, Top 10 for LLM Applications, and Agentic AI risks.
- Testing methodologies: PTES, NIST SP 800-115, MITRE ATT&CK, threat modeling (STRIDE), and CVSS 4.0 risk rating.
- Modern application architecture: SPA/JavaScript frameworks, microservices, API Gateway, GraphQL, WebSocket, and mobile application backends.
- Cloud and container security: AWS/Azure/GCP, Kubernetes, Docker, Serverless, Infrastructure-as-Code, CNAPP/CSPM.
- Identity and access: OAuth 2.0/OIDC, SAML, JWT, MFA/passkey, and Zero Trust architecture.
- DevSecOps and software supply chain: CI/CD, SAST/DAST/SCA, SBOM, secret management, and pipeline attacks.
- AI security: LLM/RAG/Agentic AI risks, prompt injection, AI red teaming, with reference to NIST AI RMF.
- Programming and automation: Python, Go, Bash, JavaScript; ability to read and understand source code (Java, .NET, Node.js, PHP) for white-box testing.
- Standards and regulations: ISO/IEC 27001:2022, PCI DSS 4.0.1, NIST CSF 2.0, Cybersecurity Law, Personal Data Protection Law No. 91/2025/QH15, and regulations on ensuring system security by level.
Skills:
- Business-oriented risk mindset: translate technical vulnerabilities into business impact.
- Write reports and present findings bilingually in Vietnamese–English to both technical teams and senior management.
- Plan, organize, and manage projects using the Agile model.
- Analytical, problem-solving, and decision-making skills under time pressure.
- Team management, task assignment, and mentoring skills for developing successors.
- Communication, cross-functional coordination, and effective teamwork.
Other Requirements:
- Professional ethics and strict compliance with the testing scope (Rules of Engagement), NDA, and data protection regulations.
- Ability to work independently, proactively research, and continuously learn at the pace of change in the field.
- Willingness to perform testing outside regular working hours within approved testing windows.
- Team spirit, strong commitment, and honesty in reporting results.
- Clear criminal record/background check (mandatory for positions with access to critical systems).
Benefits:
- Competitive salary package (Base salary and performance bonuses).
- Probation period salary is 100% of the official salary.
- Comprehensive health and accident insurance.
- 15 days of annual leave, 3 remote work days per month.
- Provision of work equipment (Macbook/ Laptop, mouse, monitor, etc.).
- A creative and modern working environment.
Working location: Galaxy Innovation Hub – D1 Hi Tech Park, Tang Nhon Phu Ward, HCMC
Kindly send your CV to: [email protected]