Middle/Senior Pen-Test Engineer

Location: Ha Noi / Ho Chi Minh

Middle/Senior Pen-Test Engineer

RESPONSIBILITIES

  • Plan and execute penetration tests across our web applications, mobile apps, APIs, backend services, cloud infrastructure and internal networks
  • Test authentication, authorisation and session management flows, including digital onboarding, eKYC, transaction authorisation and multi-factor journeys
  • Assess business logic vulnerabilities specific to banking products: account opening, deposits, lending, card issuance, limits, fees and rewards
  • Write clear, reproducible reports with proof of concept, realistic risk ratings and practical remediation guidance
  • Work directly with engineering teams to validate fixes and help them understand the root cause, not just the symptom
  • Contribute to threat modelling and secure design reviews for new features and integrations
  • Perform secure code reviews and help improve SAST, DAST, SCA and secret scanning coverage in our CI/CD pipelines
  • Support client-led and third-party penetration tests, respond to findings, and prepare evidence for client security assessments and regulatory reviews
  • Build internal tooling, test harnesses and attack playbooks to make testing repeatable
  • Track emerging threats relevant to digital banking and translate them into new test cases
  • Contribute to red team exercises and purple team collaboration with the detection and response side

REQUIREMENTS

  • 3+ years of hands-on penetration testing or offensive security experience
  • Strong track record testing web applications and APIs (REST, GraphQL, gRPC) against OWASP Top 10 and beyond
  • Mobile application security testing experience on iOS and Android, including reverse engineering, runtime manipulation and bypassing client-side controls
  • Cloud security testing experience (AWS, Azure or GCP): IAM misconfiguration, privilege escalation paths, exposed services, container and Kubernetes security
  • Solid understanding of network protocols, TLS, and internal network attack techniques
  • Proficiency with tools such as Burp Suite, Nmap, Metasploit, Frida, Objection, MobSF, BloodHound, Nuclei and similar
  • Scripting ability in Python, Go, Bash or similar to build custom exploits and automation
  • Ability to read code and identify vulnerabilities at the source level (Java, Kotlin, Go, TypeScript, Swift or similar)
  • Excellent report writing and the ability to explain risk to both engineers and non-technical stakeholders
  • Strong ethics, discretion and judgement when handling sensitive findings and production systems

Nice to have

  • Experience testing banking, payments or fintech systems
  • Familiarity with OWASP ASVS, MASVS, SAMM, MITRE ATT&CK and PTES
  • Knowledge of regulatory and compliance frameworks such as MAS TRM Guidelines, PCI DSS, ISO 27001, SOC 2, or central bank security requirements in APAC and the Middle East
  • Experience with payment and card security: HSMs, key management, 3-D Secure, tokenisation, card processor integrations
  • Red team, adversary simulation or social engineering experience
  • Detection engineering or DFIR exposure
  • Published CVEs, bug bounty track record, CTF results, security research or conference talks
  • Certifications such as OSCP, OSWE, OSEP, OSCE, CREST CRT or CCT, GPEN, GWAPT, GMOB, or CISSP

BENEFITS

  • Salary: Negotiable
  • Probation salary is 100% of official salary
  • 13th-month salary and performance review twice a year
  • Bonus for special occasions each year (Labor Day, National Day, Solar New year, Lunar New Year)
  • Project Bonus
  • IT Certificate allowance
  • Health Care Insurance
  • Social, health and unemployment Insurance following Government policy
  • Enjoy company summer trips and other team building activities held  monthly and quarterly
  • Work five days per week with flexible check-in time
  • Professional, creative and dynamic working environment

CONTACT