Application Security & Penetration Testing Engineer
On-siteHo Chi Minh City, Ho Chi Minh City (HCMC), Vietnam
Job Summary
Execute in-depth penetration testing on networks, web applications, mobile apps, and cloud environments using tools like Metasploit, Burp Suite, and custom scripts to simulate sophisticated attacks. Conduct dynamic and static testing against OWASP Top 10 and ASVS standards, while performing manual and automated source code reviews to detect vulnerabilities such as SQL injection and insecure dependencies. Evaluate security architectures, including firewalls and encryption schemes, to identify design flaws and recommend improvements aligned with NIST and ISO 27001 frameworks. Deliver comprehensive reports with actionable recommendations and collaborate with development and DevOps teams to embed security into the SDLC. Report to the security function in Ho Chi Minh City, Vietnam, with a focus on offensive and defensive application security work.
Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent experience)
- 3+ years in penetration testing, red teaming, or application security roles (Senior: 5+)
- Demonstrated experience reviewing security protocol designs and conducting source code audits
- Mastery of pentest tools: Metasploit, Burp Suite, Kali Linux
- Proficiency with AppSec tools: OWASP ZAP, Postman, Checkmarx, or similar
- Strong knowledge of programming languages (Python, Java, JavaScript) for code review and automation
- Expertise in OWASP Top 10, OWASP ASVS, and security design principles (zero trust, defense-in-depth)
- Experience with cloud platforms (AWS, Azure) and modern web frameworks
- Comfortable working across regions and functions in a global environment (Vietnam, US, Australia)
Desired Qualifications
- Certifications: OSCP, OSCE, CRTP, GWAPT, CEH, or equivalent
- Experience with red-team operations, APT simulations, or social engineering exercises
- Exposure to IoT, embedded, or access-control product security
- Experience developing proof-of-concept exploits for systems, code, or protocols
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.