GFT Technologies logo
GFT TechnologiesPosted 1 month ago

Lead Penetration Tester

On-siteHo Chi Minh City, Ho Chi Minh City (HCMC), Vietnam

Full TimeSenior LevelLarge

Job Summary

Lead Penetration Tester responsible for leading security assessments across web, mobile, API, cloud, and banking platforms; identify vulnerabilities, guide remediation, and validate fixes; produce penetration testing reports with risk ratings and remediation recommendations; mentor junior testers; collaborate with security, engineering, DevOps, and business stakeholders; role requires client-facing capabilities and flexibility to work onsite when required; strong expertise in banking systems, OWASP guidelines, cloud security, and security tooling is required.

Required Qualifications

  • Hands-on experience in penetration testing, ethical hacking, and vulnerability assessments across web, mobile, API, network, and cloud environments.
  • Experience leading a penetration testing team or security practice.
  • Strong understanding of banking systems, digital banking, payments, AML/KYC, fraud management, and transaction workflows.
  • Deep knowledge of web and API security, including OWASP Top 10, API security, IDOR, injection, broken access control, authentication, authorization, and business logic vulnerabilities.
  • Experience testing iOS and Android applications, including authentication, session management, local storage, certificate pinning, and secure communications.
  • Experience assessing networks, servers, operating systems, infrastructure security, and common vulnerabilities.
  • Knowledge of cloud security principles across AWS, Azure, or GCP.
  • Proficiency with Burp Suite, OWASP ZAP, Nmap, Nessus, Metasploit, Wireshark, Postman, MobSF, or similar tools.
  • Ability to produce clear security reports and communicate findings to technical and business stakeholders.
  • Experience working with engineering teams to validate vulnerabilities, support remediation, and perform retesting.
  • Understanding of secure coding, encryption, IAM, data privacy, and common security frameworks.
  • Familiarity with security requirements in regulated industries, particularly banking and financial services.
  • Excellent English communication skills.

Desired Qualifications

  • Experience delivering penetration testing for banks, fintechs, payment platforms, or financial institutions.
  • Experience with secure code reviews and SAST tools.
  • Experience integrating security into CI/CD pipelines using SAST, DAST, SCA, container scanning, or secrets detection.
  • Knowledge of container, Kubernetes, Docker, cloud, and Infrastructure-as-Code (IaC) security.
  • Experience with red teaming, attack simulation, or adversary emulation.
  • Scripting skills in Python, Bash, or PowerShell for automation.
  • Security certifications such as CEH, eJPT, PNPT, OSCP, GPEN, GWAPT, CISSP, CISM, or equivalent.
  • (Note: Due to the high volume of applications we receive, we are unable to respond to every candidate individually. If you have not received a response from GFT regarding your application within 10 workdays, please consider that we have decided to proceed with other candidates. We truly appreciate …

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce