Penetration Tester (Web Application)

ABOUT CLIENT

Our client is using new technology to develop products for the banking industry

JOB DESCRIPTION

Be skilled in conducting advanced manual application penetration tests.
Capable of developing tools and internal applications for discovering, assessing, and mitigating security vulnerabilities in both development and production stages.
Engage in design, source code review, and testing of new application security features and controls across various products.
Automate security penetration testing cases and ensure deployment in a production environment.
Advocate for secure development practices for software engineers.
Research and provide recommendations to the development team regarding security standards.
Continuously upgrade personal knowledge of information security to remain at the forefront of the field.

JOB REQUIREMENT

A bachelor's degree in Computer Science, Computer Engineering, Information Systems, or a related field, or 3+ years of equivalent work experience is required.
Familiarity with methods, processes, and procedures for conducting penetration testing.
Strong understanding of web application development.
Experience in reviewing source code (Java, Python) and mobile applications (Native, KMM).
Proficiency in cloud security (AWS).
Knowledge of web and mobile application security principles, including understanding of application security topics such as OWASP Top 10 and authentication infrastructure (SAML, OAUTH).
Experience in planning, coordinating, executing, and reporting security tasks.
Strong communication skills with the ability to explain complex technical issues to non-technical business users.
Possession of security-related certifications like GWAPT/ OSWE, etc. will be an advantage.

WHAT'S ON OFFER

Company offers meal and parking benefits.
Full benefits and probationary salary provided.
Insurance coverage as per Vietnamese labor law and premium health care for employees and their families.
Work environment is values-driven, international, and agile in nature.
Opportunities for overseas travel related to training and work.
Participation in internal Hackathons and company events such as team building, coffee runs, and blue card activities.
Additional benefits include a 13th-month salary and performance bonuses.
Employees receive 15 days of annual leave and 3 days of sick leave per year.
Work-life balance with a 40-hour workweek from Monday to Friday.

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

Product

Technical Skills:

Security, AWS

Location:

Ho Chi Minh - Viet Nam

Working Policy:

Hybrid

Job ID:

J00142

Status:

Close

Related Job:

Product Engineer (Web)

Ho Chi Minh - Viet Nam


Product

  • Angular
  • Typescript
  • NodeJS

Conceptualize and develop products and features, aligning them with strategic goals and shipping them to production. Provide ongoing support and enhancements for product success by iterating based on user feedback. Develop and document feature and project scopes, as well as technical design documents. Implement technical improvements to enhance application performance, stability, and scalability. Actively contribute to refining development processes, code quality, and engineering best practices. Collaborate with designers to ensure a seamless UX/UI and support the Customer Success team in understanding product usage. Take ownership of product quality and actively engage in testing as an integral part of the development process.

Negotiation

View details

Lead Penetration Tester

Ho Chi Minh, Ha Noi - Viet Nam


Outsource

  • Security

Conduct authorized penetration testing for various digital platforms, including web applications, mobile applications, APIs, infrastructure, and cloud environments. Identify and document security vulnerabilities, validate and exploit when necessary, covering areas such as authentication, authorization, session management, input validation, encryption, access control, and business logic issues. Perform security assessments according to industry standards (e.g. OWASP Top 10, OWASP API Security Top 10, OWASP Mobile Security Testing Guide) and relevant security practices. Analyze application flows, user journeys, transaction processes, access controls, and data handling mechanisms to uncover potential security risks. Conduct vulnerability assessment and manual verification to reduce false positives, confirming actual exploitability in authorized environments. Retest to validate remediation effectiveness and ensure vulnerabilities are properly resolved. Support security testing activities within the software development life cycle (SDLC), including security requirement review, threat analysis, test planning, and release security validation. Stay updated with emerging cyber threats, attack techniques, security risks, and security testing best practices. Lead the planning, scoping, and execution of penetration testing activities across assigned projects. Define the penetration testing approach, test strategy, testing scope, priorities, timelines, and required evidence based on project and client requirements. Guide and mentor penetration testers or security engineers in testing methodology, vulnerability validation, reporting quality, and remediation discussions. Review vulnerability findings, risk ratings, evidence, and remediation recommendations to ensure accuracy, consistency, and practical value. Serve as the main technical point of contact for penetration testing activities, working with client stakeholders, security teams, development teams, DevOps, infrastructure teams, and compliance teams. Facilitate vulnerability walkthroughs, risk clarification sessions, remediation discussions, and retesting alignment with relevant stakeholders. Support estimation, planning, status tracking, issue escalation, and delivery reporting for security testing activities. Contribute to improving security testing processes, reporting templates, testing checklists, knowledge sharing, and reusable testing practices. Support regulatory, audit, and compliance requirements by providing security testing evidence, reports, remediation status, and technical clarification when needed.

Negotiation

View details

Software Engineer (Node.js) - Platform Security

Ho Chi Minh - Viet Nam


Product

  • NodeJS

Create system architectures and coding standards for cloud-native solutions. Write high-quality Node.js code, enhance system security and reliability, and solve complex software integration problems. Develop platform security controls for web applications, APIs, and cloud services, covering authentication, authorization, session management, secrets management, encryption, and audit logging. Identify and address security risks through threat modeling, secure code reviews, automated security testing, dependency scanning, and investigation of security-related issues. Manage the testing, deployment, and documentation of integrated systems. Guide junior engineers, collaborate with cross-functional teams, and ensure solutions align with business needs and international standards. Actively participate in Agile software development phases, including creating user stories and sprint planning. Collaborate with multinational organizations, and be flexible to occasionally adapt to US and EU time zones.

Negotiation

View details