Penetration Tester (Web Application)

ABOUT CLIENT

Our client is using new technology to develop products for the banking industry

JOB DESCRIPTION

Be skilled in conducting advanced manual application penetration tests.
Capable of developing tools and internal applications for discovering, assessing, and mitigating security vulnerabilities in both development and production stages.
Engage in design, source code review, and testing of new application security features and controls across various products.
Automate security penetration testing cases and ensure deployment in a production environment.
Advocate for secure development practices for software engineers.
Research and provide recommendations to the development team regarding security standards.
Continuously upgrade personal knowledge of information security to remain at the forefront of the field.

JOB REQUIREMENT

A bachelor's degree in Computer Science, Computer Engineering, Information Systems, or a related field, or 3+ years of equivalent work experience is required.
Familiarity with methods, processes, and procedures for conducting penetration testing.
Strong understanding of web application development.
Experience in reviewing source code (Java, Python) and mobile applications (Native, KMM).
Proficiency in cloud security (AWS).
Knowledge of web and mobile application security principles, including understanding of application security topics such as OWASP Top 10 and authentication infrastructure (SAML, OAUTH).
Experience in planning, coordinating, executing, and reporting security tasks.
Strong communication skills with the ability to explain complex technical issues to non-technical business users.
Possession of security-related certifications like GWAPT/ OSWE, etc. will be an advantage.

WHAT'S ON OFFER

Company offers meal and parking benefits.
Full benefits and probationary salary provided.
Insurance coverage as per Vietnamese labor law and premium health care for employees and their families.
Work environment is values-driven, international, and agile in nature.
Opportunities for overseas travel related to training and work.
Participation in internal Hackathons and company events such as team building, coffee runs, and blue card activities.
Additional benefits include a 13th-month salary and performance bonuses.
Employees receive 15 days of annual leave and 3 days of sick leave per year.
Work-life balance with a 40-hour workweek from Monday to Friday.

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

Product

Technical Skills:

Security, AWS

Location:

Ho Chi Minh - Viet Nam

Working Policy:

Hybrid

Job ID:

J00142

Status:

Close

Related Job:

Senior AI DevSecOps Engineer

Ho Chi Minh - Viet Nam


Product

  • Devops
  • AWS
  • Azure
  • Security

Management of CI/CD Pipeline: Ensure automation, security, and scalability across all stages of the development lifecycle. Infrastructure & Security: Design and implement secure multi-cloud infrastructure solutions leveraging cloud services, containerization, and orchestration tools. Policy as Code: Define and enforce security and compliance policies across Kubernetes clusters using OPA or Kyverno, ensuring guardrails are automated and auditable. AI & Platform Automation: Drive the adoption of AI-powered tools and workflows to automate infrastructure operations, optimize CI/CD pipelines, accelerate root cause analysis, improve security posture, and enhance engineering productivity. Observability & Alerting: Build and maintain a comprehensive observability stack with proactive alerting, dashboards, and runbooks for critical business flows and security events. Secret & Credential Management: Design and enforce secrets management practices across all environments ensuring zero hardcoded credentials in codebases and pipelines. Incident Response & On-Call: Own and continuously improve incident response processes, define runbooks, lead post-mortems, track MTTR, and participate in on-call rotation to maintain platform reliability and SLO adherence. Threat Modelling & Penetration Testing: Conduct regular threat modelling sessions with engineering teams and coordinate or perform penetration testing activities to proactively identify attack surfaces before they reach production. Code Security: Conduct regular code reviews and static/dynamic analysis to identify and remediate security vulnerabilities. Compliance and Best Practices: Ensure compliance with industry standards and best practices. Collaboration: Collaborate with development, operations, and security teams to foster a culture of automation and security-first thinking. Mentorship: Mentor junior engineers and other team members on security best practices. Documentation: Maintain thorough and up-to-date documentation of security policies, procedures, and incident reports. Trend Scouting: Stay updated with the latest trends in technology and AI to integrate innovative solutions into our processes.

Negotiation

View details

Application Engineer

Ho Chi Minh - Viet Nam


Product

  • Frontend
  • ReactJS
  • NodeJS

Develop and support the Jan desktop application on multiple operating systems using Tauri. Engage in full stack development, utilizing React and Node.js for the application layer and Rust for native components. Take responsibility for packaging, building, and distributing the application, including installers, auto-updates, release pipelines, and code signing. Prioritize strong support for Linux by ensuring packaging and distribution across various distributions. Seamlessly integrate local model runtimes and application features throughout the development process. Embrace an agent-native approach and run agents in parallel, maintaining a strong focus on review and guardrail discipline.

Negotiation

View details

Product Engineer (Web)

Ho Chi Minh - Viet Nam


Product

  • Angular
  • Typescript
  • NodeJS

Conceptualize and develop products and features, aligning them with strategic goals and shipping them to production. Provide ongoing support and enhancements for product success by iterating based on user feedback. Develop and document feature and project scopes, as well as technical design documents. Implement technical improvements to enhance application performance, stability, and scalability. Actively contribute to refining development processes, code quality, and engineering best practices. Collaborate with designers to ensure a seamless UX/UI and support the Customer Success team in understanding product usage. Take ownership of product quality and actively engage in testing as an integral part of the development process.

Negotiation

View details