Lead Penetration Tester
On-siteHo Chi Minh City, Ho Chi Minh City (HCMC), Vietnam
Ho Chi Minh City, Ho Chi Minh City (HCMC), VietnamOn-siteFull TimeSenior LevelLarge
Full TimeSenior LevelLarge
Job Summary
Lead Penetration Tester responsible for leading security assessments across web, mobile, API, cloud, and banking platforms; identify vulnerabilities, guide remediation, and validate fixes; produce penetration testing reports with risk ratings and remediation recommendations; mentor junior testers; collaborate with security, engineering, DevOps, and business stakeholders; role requires client-facing capabilities and flexibility to work onsite when required; strong expertise in banking systems, OWASP guidelines, cloud security, and security tooling is required.
Required Qualifications
- Hands-on experience in penetration testing, ethical hacking, and vulnerability assessments across web, mobile, API, network, and cloud environments.
- Experience leading a penetration testing team or security practice.
- Strong understanding of banking systems, digital banking, payments, AML/KYC, fraud management, and transaction workflows.
- Deep knowledge of web and API security, including OWASP Top 10, API security, IDOR, injection, broken access control, authentication, authorization, and business logic vulnerabilities.
- Experience testing iOS and Android applications, including authentication, session management, local storage, certificate pinning, and secure communications.
- Experience assessing networks, servers, operating systems, infrastructure security, and common vulnerabilities.
- Knowledge of cloud security principles across AWS, Azure, or GCP.
- Proficiency with Burp Suite, OWASP ZAP, Nmap, Nessus, Metasploit, Wireshark, Postman, MobSF, or similar tools.
- Ability to produce clear security reports and communicate findings to technical and business stakeholders.
- Experience working with engineering teams to validate vulnerabilities, support remediation, and perform retesting.
- Understanding of secure coding, encryption, IAM, data privacy, and common security frameworks.
- Familiarity with security requirements in regulated industries, particularly banking and financial services.
- Excellent English communication skills.
Desired Qualifications
- Experience delivering penetration testing for banks, fintechs, payment platforms, or financial institutions.
- Experience with secure code reviews and SAST tools.
- Experience integrating security into CI/CD pipelines using SAST, DAST, SCA, container scanning, or secrets detection.
- Knowledge of container, Kubernetes, Docker, cloud, and Infrastructure-as-Code (IaC) security.
- Experience with red teaming, attack simulation, or adversary emulation.
- Scripting skills in Python, Bash, or PowerShell for automation.
- Security certifications such as CEH, eJPT, PNPT, OSCP, GPEN, GWAPT, CISSP, CISM, or equivalent.
- (Note: Due to the high volume of applications we receive, we are unable to respond to every candidate individually. If you have not received a response from GFT regarding your application within 10 workdays, please consider that we have decided to proceed with other candidates. We truly appreciate …
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.