Penetration Tester

ABOUT CLIENT

Our client is a leading cyber security company in Vietnam

JOB DESCRIPTION

Tham gia triển khai dịch vụ pentest cho khách hàng: tiếp nhận yêu cầu, xác định phạm vi và điều kiện đảm bảo của các dự án pentest được giao.
Phân chia công việc theo quy trình pentest và giao cho các thành viên thực hiện dự án.
Hướng dẫn các pentester thực hiện kiểm tra đánh giá ATTT cho ứng dụng.
Kiểm soát chất lượng dịch vụ, tuân thủ quy trình, nguồn lực và thời gian triển khai cho các dự án được giao.
Là đầu mối kỹ thuật, làm việc với các bộ phận nội bộ và Khách hàng để phối hợp giải quyết các vấn đề trong phạm vi cung cấp dịch vụ.
Nghiên cứu cải tiến quy trình, checklist và các kỹ thuật mới nhằm nâng cao chất lượng dịch vụ và năng suất lao động, giảm tỉ lệ sót lỗi.
Đảm bảo SLA theo hợp đồng đã ký với Khách hàng.

JOB REQUIREMENT

Trình độ học vấn
Tốt nghiệp đại học chuyên ngành: An toàn thông tin, Công nghệ thông tin, Khoa học máy tính, Toán - Tin hoặc các ngành liên quan.
Trình độ tiếng Anh tương đương TOEIC 650 trở lên.
Yêu cầu chuyên môn & năng lực kỹ thuật
Hiểu rõ các lỗ hổng bảo mật ứng dụng và kỹ thuật khai thác tương ứng.
Nắm vững các hướng dẫn lập trình an toàn; có khả năng lập trình thành thạo và bảo mật với một hoặc nhiều framework phổ biến.
Có kiến thức về các cơ chế bảo vệ, phòng chống tấn công; am hiểu phân tích và xây dựng payload dạng 1-day.
Thành thạo quy trình kiểm thử xâm nhập (pentest) ứng dụng và các phương pháp đánh giá bảo mật như Blackbox, Greybox, Whitebox.
Nắm rõ checklist đánh giá bảo mật ứng dụng Web và Mobile theo chuẩn OWASP quốc tế.
Có ít nhất 3 năm kinh nghiệm trong lĩnh vực đánh giá an toàn thông tin ứng dụng.
Ưu tiên ứng viên sở hữu các chứng chỉ chuyên ngành như OSCP, OSWE, CPENT, Security+...
Kỹ năng mềm
Kỹ năng làm việc nhóm tốt, khả năng chịu áp lực cao.
Tư duy chủ động trong việc tìm kiếm và khai thác thông tin.
Tinh thần kỷ luật, đúng giờ và cam kết cao trong công việc.

WHAT'S ON OFFER

Mức thu nhập hàng năm cạnh tranh
Cơ hội làm việc với khách hàng đa dạng trong và ngoài nước
Đánh giá và điều chỉnh lương hàng năm vào tháng 3
Bảo hiểm sức khỏe và tai nạn cá nhân với Hạn mức chi trả lên đến 600 triệu/năm
Kiểm tra sức khỏe hàng năm
Giải thưởng cho năng lực và đóng góp xuất sắc
Hỗ trợ chi phí 100% cho các chứng chỉ chuyên môn quốc tế, khen thưởng đặc biệt cho nhân viên đạt chứng chỉ chuyên môn quốc tế
Đầu tư liên tục vào học liệu mới nhất về lĩnh vực ATTT từ các nhà cung cấp uy tín hàng đầu thế giới
Cung cấp tài khoản Elearning từ Udemy cho mọi nhân viên
Miễn phí tham gia các chương trình chia sẻ kiến thức chuyên ngành và hội thảo chuyên môn
Văn phòng tiêu chuẩn hạng A tại tòa nhà Landmark 72 với không gian xanh và khu vực giải trí, gym
Thời gian thư giãn hàng ngày với hoạt động Happy hours
Các hoạt động thể thao và giải trí như câu lạc bộ bóng đá, bi-a, pocker, pes, v.v.
12 ngày phép năm theo quy định Luật Lao Động, và thêm 3 ngày nghỉ mát cùng các ngày lễ truyền thống
Tổ chức sinh nhật cá nhân với quà tặng và bánh sinh nhật từ công ty
Tham gia các sự kiện và hoạt động như Teambuilding, Sinh nhật hàng tháng, Year End Party, nghỉ mát, ngày lễ 08/03, 20/10 và ngày sinh nhật tập đoàn

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

Product

Technical Skills:

Pentest

Location:

Ha Noi - Viet Nam

Working Policy:

Onsite

Job ID:

J01961

Status:

Close

Related Job:

Lead Penetration Tester

Ho Chi Minh, Ha Noi - Viet Nam


Outsource

  • Security

Conduct authorized penetration testing for various digital platforms, including web applications, mobile applications, APIs, infrastructure, and cloud environments. Identify and document security vulnerabilities, validate and exploit when necessary, covering areas such as authentication, authorization, session management, input validation, encryption, access control, and business logic issues. Perform security assessments according to industry standards (e.g. OWASP Top 10, OWASP API Security Top 10, OWASP Mobile Security Testing Guide) and relevant security practices. Analyze application flows, user journeys, transaction processes, access controls, and data handling mechanisms to uncover potential security risks. Conduct vulnerability assessment and manual verification to reduce false positives, confirming actual exploitability in authorized environments. Retest to validate remediation effectiveness and ensure vulnerabilities are properly resolved. Support security testing activities within the software development life cycle (SDLC), including security requirement review, threat analysis, test planning, and release security validation. Stay updated with emerging cyber threats, attack techniques, security risks, and security testing best practices. Lead the planning, scoping, and execution of penetration testing activities across assigned projects. Define the penetration testing approach, test strategy, testing scope, priorities, timelines, and required evidence based on project and client requirements. Guide and mentor penetration testers or security engineers in testing methodology, vulnerability validation, reporting quality, and remediation discussions. Review vulnerability findings, risk ratings, evidence, and remediation recommendations to ensure accuracy, consistency, and practical value. Serve as the main technical point of contact for penetration testing activities, working with client stakeholders, security teams, development teams, DevOps, infrastructure teams, and compliance teams. Facilitate vulnerability walkthroughs, risk clarification sessions, remediation discussions, and retesting alignment with relevant stakeholders. Support estimation, planning, status tracking, issue escalation, and delivery reporting for security testing activities. Contribute to improving security testing processes, reporting templates, testing checklists, knowledge sharing, and reusable testing practices. Support regulatory, audit, and compliance requirements by providing security testing evidence, reports, remediation status, and technical clarification when needed.

Negotiation

View details

Automation Tester (Karate, Cucumber, Java)

Ho Chi Minh - Viet Nam


Outsource

  • Automation Test
  • Java

Perform testing activities to enhance product quality and collaborate with the team including developers, business analysts, customer service, and operations for successful product delivery Address test automation requirements with strong attention to detail, analytical skills, and problem-solving abilities Automate functional, regression, and performance acceptance tests Take full responsibility for improving automated test coverage across the board Take part in sprint planning and partner with the Scrum team to analyze requirements and offer relevant test suggestions

Negotiation

View details

Manual QA Tester

Ho Chi Minh - Viet Nam


Product

  • Manual Test

Create, document and implement comprehensive manual test cases for web and mobile (iOS/Android) user processes. Ensure new features align with functional requirements, UI/UX specifications and cover edge cases. Record defects with detailed reproduction steps, screenshots/video capture and assess severity. Validate bug fixes, regressions and rollback scenarios across different environments (dev, QA, staging). Test mobile builds on real devices and emulators. Work closely with developers to clarify requirements, address unclear acceptance criteria and refine user stories. Update and maintain test plans, checklists and traceability matrices. Provide stakeholders with daily QA status and release-readiness risk reports.

Negotiation

View details