Lead Pen Tester

JOB DESCRIPTION

We are seeking motivated Lead Pen Tester (Group Security) to be part of a team that evaluates a wide range of Our client's products and services - to identify security weaknesses and exposures that pose a risk to the enterprise, and work with teams to understand their risk and path to remediation.
Technical
Execute penetration tests, either in a team or individually, to identify vulnerabilitiesand weaknesses that could impact bank systems;
Including testing of web applications, mobile applications, web APIs, Infrastructure, Cloud technologies, and hardware.
Triage vulnerabilities and justify risk in alignment with common vulnerability scoringsystems, considering the environment and context;
Report testing results to key project stakeholders in varying formats (i.e. traditionalreport, bug tickets), including verbal communication;
Work with larger technical programs across the bank to understand and constructtesting requirements;
Where required, work as an embedded penetration tester on large programs;
Assist with other offensive security activities within the team
Self-manage security testing projects from end-to-end;
Participate in 'run the business' activities, such as maintenance and uplift of thepenetration testing environment.
Leadership
Maintains and increases motivation within team by regularly checking in onmotivation levels, and making adjustments quickly where needed (e.g. QCI, teammeeting, team engagement activity).
Creates and maintains an equally safe environment for all members of team to 'test and learn', share learning, challenge thinking, team development and explore new ideas.
Sets effective and meaningful goals and timelines for each team member that supports them to achieve beyond what is expected (e.g. align with Peak performance framework).
Provides input to Engineering Manager in making decision of Prioritising and ensuringresources for the right work and making trade-offs between current and futureperformance to balance immediate goals with longer-term growth for the team.
Supports the team to cut through complexity and create clarity by simplifyingpractices and processes.
Be responsible for team engagement & relations.

JOB REQUIREMENT

Must-have
8+ years of experience in IT/Security industry, and at least 3 years as a penetration tester;
Experience testing various technologies and platforms, including but not limited to; Web applications, web APIs, mobile applications (iOS, Android), network and server technologies, cloud services (AWS, Azure), and hardware;
Experience writing and conveying complex security findings through reports;
A comprehensive understanding of Penetration Testing frameworks and methodologies (OWASP, OSSTMM, WAHH);
Methodical, analytical approach with outstanding attention to detail. The ability to construct and execute testing within a controlled environment that complies with methodologies, policies, and best practice;
A clear understanding of both manual and automated penetration testing techniques, including knowledge of common penetration testing tools and the impacts they have on systems;
A good understanding of risk mitigation strategies when working in highly sensitiveenvironment;
Proven ability to work both individually and within a team environment (at times with little guidance), build strong relationships and maintain rapport with internal Our Client's stakeholders and 3rd party service providers;
Strong team working skills are essential;
Excellent verbal and written communication skills;
Ability to attend to the detail on multiple concurrent tasks while meeting variousdeadlines;
Ability to work semi-autonomously and organise/prioritise own work schedule on a short-term basis;
Proven ability to develop scripts and tools to enhance manual processes and existing tooling.
Nice to have:
Experience working with large corporations.
Training on self-development platforms (i.e. HackTheBox, Pentesterlabs, wechall, etc.);
Participation in Bug Bounty programs;
Undergraduate (minimum) in technical degree (Computer Science, Software Engineer, Cyber Security);
Standard Industry certifications such as OSCP, CREST (CRT, CCT) or equivalent.

WHAT'S ON OFFER

Generous compensation and benefit package
Attractive salary and benefits
20-day annual leave and 7-day sick leave, etc.
13th month salary and Annual Performance Bonus
Premium healthcare for yourself and family members
Monthly allowance for team activities
Premium welcome kit and frequent appreciation gifts
Extra benefits for long-term employees
Exciting career and development opportunities
Large scale products with modern technologies in banking domain
Clear roadmap for career advancement in both technical and leadership pathways
Well-structured learning and development programs (technical and soft skills)
Sponsored certificates in both IT and banking/finance
Premium accounts on Udemy
English learning with native teachers
Opportunity for traveling & training in Australia
Professional and engaging working environment
Hybrid working model and excellent work-life balance
Well-equipped & modern Agile office with fully-stocked pantry
Special programs to improve your physical and mental health
Annual company trip and events
A solid talented team behind you - great people who love what they do

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

Product

Technical Skills:

Security

Location:

Ho Chi Minh - Viet Nam

Working Policy:

Salary:

Negotiation

Job ID:

J01402

Status:

Close

Related Job:

Technical Lead (Java)

Ho Chi Minh, Ha Noi - Viet Nam


Outsource

  • Java

#Technical Leadership Lead and mentor a team of backend engineers across multiple functional domains. Provide technical direction and ensure alignment with architecture standards and engineering best practices. Review solution designs, code quality, and implementation approaches - promoting clean architecture, resilient microservices, and AI-enhanced development patterns. Guide the team in diagnosing complex technical challenges, using both traditional analysis and AI-powered debugging or observability tools. Support planning, estimation, and technical decision-making within the engineering team. Backend Architecture & Development Design and develop backend services using Java and modern backend frameworks (e.g., Spring Boot). Define and implement microservices-based architecture and API-driven systems. Ensure backend services are scalable, secure, resilient, and maintainable. Drive best practices in backend development, including maintainable system design, automated testing, code quality, API governance, performance optimization and documentation. Work closely with DevOps teams to support CI/CD pipelines, incorporate intelligent automation, and ensure stable, secure deployment environments. Integrate AI-assisted development practices into coding, testing, documentation, code reviews, and defect prevention workflows. #Banking & Payment Domain Design backend systems supporting banking products and financial transaction processing. Build and maintain services related to payments, card processing, financial operations, and core banking functions. Ensure backend implementations comply with financial industry standards and security requirements. Collaborate with business and product teams to translate banking and financial requirements into technical solutions. #Client Collaboration & Delivery Work directly with client stakeholders, architects, and product owners to understand business processes, requirements and define technical solutions. Challenge and clarify requirements with curiosity dig deep into the "why" behind business needs. Participate in architecture discussions and technical workshops with client teams. Communicate technical designs, trade-offs, and solutions clearly to both engineering teams and non-technical stakeholders. Support project delivery by ensuring technical risks are identified and mitigated early.

Negotiation

View details

Lead Data Engineer

Ho Chi Minh, Ha Noi - Viet Nam


Outsource

  • Data Engineering
  • Management

Architect, develop, and maintain scalable data infrastructure, including data lakes, pipelines, and metadata repositories, ensuring the timely and accurate delivery of data to stakeholders. Work closely with data scientists to build and support data models, integrate data sources, and support machine learning workflows and experimentation environments. Develop and optimize large-scale, batch, and real-time data processing systems to enhance operational efficiency and meet business objectives. Leverage Python, Apache Airflow, and AWS services to automate data workflows and processes, ensuring efficient scheduling and monitoring. Utilize AWS services such as S3, Glue, EC2, and Lambda to manage data storage and compute resources, ensuring high performance, scalability, and cost-efficiency. Implement robust testing and validation procedures to ensure the reliability, accuracy, and security of data processing workflows. Stay informed of industry best practices and emerging technologies in both data engineering and data science to propose optimizations and innovative solutions.

Negotiation

View details

Full-stack Lead (Android, Java)

Ho Chi Minh, Ha Noi - Viet Nam


Outsource

  • Android

#Role Summary Lead the design and development of high-quality Android applications for banking projects in an Agile/Scrum environment Own the technical architecture and provide hands-on leadership across the full development lifecycle, from solution design to production deployment Drive scalable, secure, and high-performance mobile solutions aligned with modern Android best practices and enterprise standards Act as the technical authority for the Android domain, guiding the team on architecture, coding standards, and engineering excellence Contribute to backend/service integration and support end-to-end solution delivery as a full-stack Android technical leader when required Actively leverage AI tools to improve team productivity, code quality, testing coverage, and technical documentation Collaborate closely with cross-functional stakeholders, Solution Architects, and Delivery Leadership while mentoring and growing the Android engineering team#Key Activities Define and own the mobile architecture, technical roadmap, and engineering standards for Android applications Lead the design and development of complex, enterprise-grade Android solutions using Kotlin and Java Provide hands-on contribution to critical features, technical spikes, performance optimization, and integration layers Drive the adoption of Clean Architecture, MVVM, Jetpack Compose, and modularization strategies Review and approve technical designs, pull requests, and implementation approaches Ensure seamless integration with backend services, APIs, and external enterprise platforms Contribute to API design discussions and support backend collaboration for end-to-end delivery Establish and enforce best practices for code quality, testing strategy, CI/CD, and release management Identify technical risks, propose mitigation plans, and support delivery planning and estimations Coach and mentor Android developers, conduct technical training, and support career development Work closely with Product Owners, Scrum Masters, QA, DevOps, and Architects to ensure successful delivery

Negotiation

View details