Lead Penetration Tester

ABOUT CLIENT

Our client is a global technology company that specializes in providing innovative IT solutions for the financial services industry

JOB DESCRIPTION

Conduct authorized penetration testing for various digital platforms, including web applications, mobile applications, APIs, infrastructure, and cloud environments.
Identify and document security vulnerabilities, validate and exploit when necessary, covering areas such as authentication, authorization, session management, input validation, encryption, access control, and business logic issues.
Perform security assessments according to industry standards (e.g. OWASP Top 10, OWASP API Security Top 10, OWASP Mobile Security Testing Guide) and relevant security practices.
Analyze application flows, user journeys, transaction processes, access controls, and data handling mechanisms to uncover potential security risks.
Conduct vulnerability assessment and manual verification to reduce false positives, confirming actual exploitability in authorized environments.
Retest to validate remediation effectiveness and ensure vulnerabilities are properly resolved.
Support security testing activities within the software development life cycle (SDLC), including security requirement review, threat analysis, test planning, and release security validation.
Stay updated with emerging cyber threats, attack techniques, security risks, and security testing best practices.
Lead the planning, scoping, and execution of penetration testing activities across assigned projects.
Define the penetration testing approach, test strategy, testing scope, priorities, timelines, and required evidence based on project and client requirements.
Guide and mentor penetration testers or security engineers in testing methodology, vulnerability validation, reporting quality, and remediation discussions.
Review vulnerability findings, risk ratings, evidence, and remediation recommendations to ensure accuracy, consistency, and practical value.
Serve as the main technical point of contact for penetration testing activities, working with client stakeholders, security teams, development teams, DevOps, infrastructure teams, and compliance teams.
Facilitate vulnerability walkthroughs, risk clarification sessions, remediation discussions, and retesting alignment with relevant stakeholders.
Support estimation, planning, status tracking, issue escalation, and delivery reporting for security testing activities.
Contribute to improving security testing processes, reporting templates, testing checklists, knowledge sharing, and reusable testing practices.
Support regulatory, audit, and compliance requirements by providing security testing evidence, reports, remediation status, and technical clarification when needed.

JOB REQUIREMENT

Proficient in penetration testing, vulnerability assessment, ethical hacking, and security testing across various environments including application, API, mobile, network, and cloud.
Demonstrated ability to lead or coordinate penetration testing activities, including test planning, execution tracking, finding review, stakeholder communication, and retesting coordination.
Strong knowledge of web and API security vulnerabilities, including OWASP Top 10, API authentication, authorization, token handling, insecure direct object references, injection, broken access control, and business logic flaws.
Experience testing iOS and Android applications, including mobile application security controls, local storage, certificate pinning, authentication, session handling, and secure communication.
Experience in assessing network services, servers, operating systems, misconfigurations, access controls, and common infrastructure vulnerabilities.
Familiarity with cloud security concepts and security testing considerations for AWS, Azure, or GCP environments.
Proficient in using tools such as Burp Suite, OWASP ZAP, Nmap, Nessus, Metasploit, Wireshark, Postman, MobSF, or equivalent security testing tools.
Able to independently validate vulnerabilities, assess exploitability, determine business impact, and provide clear remediation recommendations.
Capable of writing and reviewing clear security reports, including vulnerability details, risk ratings, technical evidence, business impact, and remediation guidance.
Able to explain technical findings to both technical and non-technical stakeholders in a clear, structured, and practical manner.
Proficient in working with engineering teams to clarify root causes, support fix implementation, and perform retesting.
Good understanding of secure coding principles, data privacy, encryption, identity and access management, and common security frameworks.
Understanding of security requirements in regulated, audit, or compliance-driven environments.
Strong problem-solving skills, ownership mindset, attention to detail, and ability to manage multiple testing activities in parallel.
Excellent English communication skills required, with the ability to communicate fluently and confidently with client stakeholders, security teams, business users, and technical teams.
Previous experience working on penetration testing or security assessment projects for banks, fintechs, payment platforms, card systems, or financial institutions.
Good understanding of banking systems, digital banking, payments, cards, customer onboarding, AML/KYC, fraud management, account services, and transaction flows.
Familiarity with banking security practices and financial industry security requirements.
Familiarity with PCI DSS, ISO 27001, SOC 2, SWIFT Customer Security Controls Framework, local banking regulations, or other financial industry security requirements.
Experience conducting secure code review or working with SAST tools to identify security issues in application code.
Experience integrating security testing into CI/CD pipelines and working with tools such as SAST, DAST, SCA, container scanning, or secrets detection.
Familiarity with cloud misconfiguration assessment, container security, Kubernetes security, Docker security, and infrastructure-as-code security checks.
Experience with controlled red team exercises, attack simulation, phishing simulation, or adversary emulation in authorized environments.
Proficient in using Python, Bash, PowerShell, or similar scripting languages to automate testing, validation, or reporting tasks.
Experience in building security testing methodology, playbooks, checklists, report templates, or quality review practices.
Experience mentoring junior or mid-level penetration testers and supporting capability development within a security testing team.
Relevant certifications such as CEH, eJPT, PNPT, OSCP, GWAPT, GPEN, CISSP, CISM, or equivalent are preferred.

WHAT'S ON OFFER

Attractive salary package
Guaranteed 13th-month salary
Performance-based bonus
Access to professional English course
Comprehensive health insurance
Generous annual leave allowance

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

Outsource

Technical Skills:

Security

Location:

Ho Chi Minh, Ha Noi - Viet Nam

Working Policy:

Hybrid

Job ID:

J02215

Status:

Active

Related Job:

AI Transformation Lead

Ho Chi Minh - Viet Nam


Outsource

  • AI

Develop a 3-year AI transformation roadmap aligned with business goals in IT outsourcing, product development, and ODC services. Prioritize highest-impact AI use cases in the organization using a build-vs-buy-vs-partner framework. Establish AI governance for model selection, cost management, data privacy, IP protection, and ethical AI guidelines. Implement AI-assisted development workflows for 1,000+ engineers, including AI code generation, review, automated testing, and AI-powered debugging. Drive adoption of AI orchestration platforms to automate repetitive engineering tasks. Create internal AI skills/training programs and a culture of continuous AI experimentation. Measure and report on productivity gains, quality improvements, and time-to-market acceleration from AI adoption. Collaborate with product teams to define AI features for various products. Lead the development of AI Copilots, intelligent assistants, and autonomous agents embedded within products. Guide the architecture of an Ontology-Based AI ERP/MES Platform, including Knowledge Graphs, GraphRAG, and Multi-Agent Systems. Identify new AI-powered product opportunities in logistics, manufacturing, and supply chain to create new revenue streams. Advocate for AI internally, communicate the vision, celebrate wins, and address concerns across all levels. Partner with HR to define new AI-focused roles and refine hiring criteria. Collaborate with ODC/Client Delivery teams to package and sell AI capabilities to existing and new clients. Represent the company externally in conferences, thought leadership, and talent branding to position the company as an AI leader in the IT services industry.

Negotiation

View details

Senior Tech Lead (Shop 6.0)

Ho Chi Minh - Viet Nam


Outsource

  • Backend
  • Frontend
  • Azure

Take on overall technical and organizational responsibility for delivering Shop 6.0 across frontend, backend, and infrastructure Plan delivery scope, milestones, and releases, and coordinate the work of parallel workstreams (frontend, backend, DevOps, QA) Make and facilitate key architectural decisions together with the senior engineers, particularly around microservices, APIs, and cloud-native implementation on Azure Identify and manage risks related to integration (especially the ERP Cloud connection), scalability, and technical dependencies Serve as the central point of contact for stakeholders on scope, prioritization, and timelines Ensure code quality through reviews, mentoring, and clear standards, including a pull request process with mandatory checks and senior/lead review Ensure transparency on progress, risks, and decisions towards the team and management

Negotiation

View details

Tech Lead (ERP)

Ho Chi Minh - Viet Nam


Outsource

  • .NET
  • ReactJS
  • Azure

Leading, mentoring, and developing a cross-functional team of backend and frontend developers, and promoting technical ownership and continuous learning. Ensuring that technical direction and architecture across the stack follows the JTL guidelines and addressing any technical debts & challenges. Active involvement in designing and reviewing backend services, REST and GraphQL APIs in .NET, as well as React/TypeScript frontend components. Establishing and upholding engineering standards for code quality, maintainability, automated testing, and sustainable development practices. Leading technical discussions and design decisions, while balancing trade-offs in a complex, large-scale system. Advocating for AI-assisted development across the team and supporting engineers in utilizing AI tools effectively. Aligning backend and frontend teams and fostering close collaboration with quality engineers, architects, and product managers. Identifying technical risks, challenging assumptions, and driving continuous improvement.

Negotiation

View details