Lead Pen Tester

JOB DESCRIPTION

We are seeking motivated Lead Pen Tester (Group Security) to be part of a team that evaluates a wide range of Our client's products and services - to identify security weaknesses and exposures that pose a risk to the enterprise, and work with teams to understand their risk and path to remediation.
Technical
Execute penetration tests, either in a team or individually, to identify vulnerabilitiesand weaknesses that could impact bank systems;
Including testing of web applications, mobile applications, web APIs, Infrastructure, Cloud technologies, and hardware.
Triage vulnerabilities and justify risk in alignment with common vulnerability scoringsystems, considering the environment and context;
Report testing results to key project stakeholders in varying formats (i.e. traditionalreport, bug tickets), including verbal communication;
Work with larger technical programs across the bank to understand and constructtesting requirements;
Where required, work as an embedded penetration tester on large programs;
Assist with other offensive security activities within the team
Self-manage security testing projects from end-to-end;
Participate in 'run the business' activities, such as maintenance and uplift of thepenetration testing environment.
Leadership
Maintains and increases motivation within team by regularly checking in onmotivation levels, and making adjustments quickly where needed (e.g. QCI, teammeeting, team engagement activity).
Creates and maintains an equally safe environment for all members of team to 'test and learn', share learning, challenge thinking, team development and explore new ideas.
Sets effective and meaningful goals and timelines for each team member that supports them to achieve beyond what is expected (e.g. align with Peak performance framework).
Provides input to Engineering Manager in making decision of Prioritising and ensuringresources for the right work and making trade-offs between current and futureperformance to balance immediate goals with longer-term growth for the team.
Supports the team to cut through complexity and create clarity by simplifyingpractices and processes.
Be responsible for team engagement & relations.

JOB REQUIREMENT

Must-have
8+ years of experience in IT/Security industry, and at least 3 years as a penetration tester;
Experience testing various technologies and platforms, including but not limited to; Web applications, web APIs, mobile applications (iOS, Android), network and server technologies, cloud services (AWS, Azure), and hardware;
Experience writing and conveying complex security findings through reports;
A comprehensive understanding of Penetration Testing frameworks and methodologies (OWASP, OSSTMM, WAHH);
Methodical, analytical approach with outstanding attention to detail. The ability to construct and execute testing within a controlled environment that complies with methodologies, policies, and best practice;
A clear understanding of both manual and automated penetration testing techniques, including knowledge of common penetration testing tools and the impacts they have on systems;
A good understanding of risk mitigation strategies when working in highly sensitiveenvironment;
Proven ability to work both individually and within a team environment (at times with little guidance), build strong relationships and maintain rapport with internal Our Client's stakeholders and 3rd party service providers;
Strong team working skills are essential;
Excellent verbal and written communication skills;
Ability to attend to the detail on multiple concurrent tasks while meeting variousdeadlines;
Ability to work semi-autonomously and organise/prioritise own work schedule on a short-term basis;
Proven ability to develop scripts and tools to enhance manual processes and existing tooling.
Nice to have:
Experience working with large corporations.
Training on self-development platforms (i.e. HackTheBox, Pentesterlabs, wechall, etc.);
Participation in Bug Bounty programs;
Undergraduate (minimum) in technical degree (Computer Science, Software Engineer, Cyber Security);
Standard Industry certifications such as OSCP, CREST (CRT, CCT) or equivalent.

WHAT'S ON OFFER

Generous compensation and benefit package
Attractive salary and benefits
20-day annual leave and 7-day sick leave, etc.
13th month salary and Annual Performance Bonus
Premium healthcare for yourself and family members
Monthly allowance for team activities
Premium welcome kit and frequent appreciation gifts
Extra benefits for long-term employees
Exciting career and development opportunities
Large scale products with modern technologies in banking domain
Clear roadmap for career advancement in both technical and leadership pathways
Well-structured learning and development programs (technical and soft skills)
Sponsored certificates in both IT and banking/finance
Premium accounts on Udemy
English learning with native teachers
Opportunity for traveling & training in Australia
Professional and engaging working environment
Hybrid working model and excellent work-life balance
Well-equipped & modern Agile office with fully-stocked pantry
Special programs to improve your physical and mental health
Annual company trip and events
A solid talented team behind you - great people who love what they do

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

Product

Technical Skills:

Security

Location:

Ho Chi Minh - Viet Nam

Working Policy:

Salary:

Negotiation

Job ID:

J01402

Status:

Close

Related Job:

AI-Native Software Engineering Lead

Ho Chi Minh - Viet Nam


Outsource

  • Backend
  • AI

Responsible for developing and evolving the AI-native SDLC operating model, including agent workflow designs, verification gates, context management standards, and evaluation frameworks Build and lead multi-agent systems using orchestration layers such as Claude Code, GitHub Copilot Workspace, Cursor, LangGraph, CrewAI, or equivalent, from prototype to production Collaborate with the Director of Engineering to contribute to and maintain the company's AI toolchain selection criteria and evaluate tools with engineering rigor, providing internal guidance on when AI is beneficial and when it is not Establish engineering standards, agent evaluation loops, and AI output quality gates across the delivery organization Previous experience in a lead, principal, or staff engineer role with demonstrated cross-team influence Experience in outsourcing, consulting, or multi-client delivery environments Track record of building or leading an internal community of practice, guild, or AI adoption program Develop and continuously evolve the company's AI-native SDLC playbook, including standards, workflow templates, case studies, and guardrails that delivery teams can adopt immediately Design and lead internal upskilling programs that transition engineers from AI-assisted to AI-native working patterns Keep track of the AI capability frontier, model improvements, new agent frameworks, and emerging risks, translating signals into timely updates to client practices Work closely alongside Delivery Teams as an AI transformation advisor and execution partner, identifying the highest-value automation opportunities across the SDLC and coordinating with the team to implement them Design and deploy agent-orchestrated workflows tailored to each client's stack, team maturity, and delivery context, with measurable ROI Build business cases for AI-native adoption with clients and account managers, framing the value in terms of velocity, quality, and cost Represent the company's AI-native engineering capabilities in client conversations, QBRs, and RFP responses as a credible technical authority

Negotiation

View details

Platform Lead

Others - Singapore


Product

  • Backend
  • Devops
  • Data Engineering

Develop and expand distributed systems to handle large volumes of sensory, telemetry, and control data across cloud and edge environments, facilitating real-time connections for fleets of robots. Create the API Platform with a focus on high reliability, exceptional developer experience, and robust multimodal AI capabilities accessible through user-friendly APIs and SDKs. Establish extensive training and inference platforms for foundation models used in robot autonomy, teleoperation, and developer integrations. Devise data ingestion and streaming pipelines for real-time connectivity of robot fleets to the cloud, covering various data inputs such as video, LiDAR, joint states, and audio. Oversee and advance a modern cloud native infrastructure stack employing Kubernetes, Docker, and infrastructure as code tools. Ensure platform reliability through telemetry, monitoring, alerting, autoscaling, failover, and disaster recovery measures. Make infrastructure decisions pertaining to distributed storage, consensus protocols, GPU orchestration, network reliability, and API security. Foster collaboration across ML, robotics, and product teams to facilitate hardware in the loop simulation, policy rollout, continuous learning, and CI/CD workflows. Implement secure APIs featuring fine-grained access control, usage metering, rate limiting, and billing integration to accommodate a growing user base.

Negotiation

View details

(Senior) Embedded Security Engineer – Linux / Android Platforms

Ho Chi Minh, Ha Noi - Viet Nam


Outsource

  • Security
  • Embedded

Security Architecture & Engineering: Design and implement security features for embedded platforms, contribute to security architecture definition, and perform security architecture reviews and threat modeling. Security Implementation & Hardening: Implement security hardening for Linux / Android / QNX systems, conduct secure code reviews, and support integration of access control and system hardening mechanisms (e.g. SELinux, AppArmor). Threat Modeling & Reviews: Identify risks, define mitigation strategies, and drive security improvements early in the development lifecycle. Testing & Validation: Perform security testing and validation, and ensure compliance with relevant security standards and best practices.

Negotiation

View details