Senior Web & API Penetration Tester

Position Overview:

  • Directly perform in-depth penetration testing (black-box/gray-box/white-box) on the Company’s/Subsidiaries’ Web applications, APIs, mobile backends, and AI/LLM-integrated applications.
  • Exploit and demonstrate vulnerabilities through controlled PoCs; rank risks based on technical severity in conjunction with business impact; perform retesting to verify remediation.
  • Research new vulnerabilities and CVEs, write exploits, develop tools and automation scripts to support continuous testing and CI/CD integration.
  • Provide technical consultation to development teams on root causes, remediation approaches, and secure coding; support Blue Team/SOC in developing detection scenarios (Purple Team).
  • Comply with and contribute to improving methodologies, checklists, and report templates; provide technical guidance and mentoring to junior-level specialists.

Key Responsibilities:

1. In-depth Penetration Testing of Web Applications and APIs

  • Perform manual testing in accordance with OWASP WSTG/ASVS: business logic flaws, IDOR/BOLA, privilege escalation, race conditions, SSRF, deserialization, HTTP request smuggling, client-side attacks (XSS, prototype pollution, DOM clobbering).
  • Test REST/GraphQL/gRPC/Webhook APIs in accordance with the OWASP API Security Top 10; test authentication and authorization flows including OAuth 2.0/OIDC, SAML, JWT, SSO, MFA, and passkeys.
  • Perform white-box testing: review source code (Java, .NET, Node.js, PHP, Python) to identify vulnerabilities that dynamic testing may not detect.
  • Strictly control the testing scope (Rules of Engagement), minimizing impact on production systems and real data.

2. Testing Cloud-Native Applications and AI/LLM-Integrated Applications

  • Test applications deployed on container/Kubernetes/Serverless platforms: misconfigurations, container escape, service account abuse, secret exposure, and Infrastructure-as-Code risks.
  • Test AI/LLM-integrated and Agentic AI applications: direct and indirect prompt injection, data leakage through RAG, abuse of agent/tool privileges, MCP connection controls, and trust boundaries.
  • Assess software supply chain risks: third-party libraries, SBOM, compromised dependencies, and credential leakage in CI/CD pipelines.

3. Vulnerability Research, Tool Development, and Automation

  • Monitor and analyze CVEs and new attack techniques; assess their impact on the Group’s systems and propose response actions.
  • Write PoCs/exploit code for publicly disclosed vulnerabilities and self-discovered vulnerabilities; research vulnerabilities in open-source frameworks currently in use.
  • Develop internal scripts and tools (Python/Go/Bash), write Nuclei templates, and extend Burp Suite to shorten testing time.
  • Participate in integrating SAST/DAST/SCA into CI/CD and fine-tune rules to reduce false positives.

4. Reporting, Remediation Consulting, and Defensive Coordination

  • Prepare bilingual Vietnamese–English penetration testing reports: technical descriptions, exploitation evidence, CVSS 4.0-based ranking and business impact, and feasible remediation recommendations.
  • Present findings to development teams and stakeholders; provide consultation on root causes and compensating controls (workarounds) when immediate patching is not possible.
  • Convert exploitation scenarios into detection use cases based on MITRE ATT&CK; coordinate with the Blue Team/SOC to validate detection capabilities.
  • Track remediation progress and perform retesting for Remediation Verification before closing vulnerabilities.

5. Methodology Standardization and Knowledge Sharing

  • Contribute to improving the team’s processes, checklists, payload libraries, and report templates.
  • Provide technical guidance and review the results and reports of junior-level specialists.
  • Organize internal knowledge-sharing sessions on new attack techniques; contribute security awareness training content for development teams.
  • Participate in advanced-level incident response and ad-hoc assessments when required.

Job Requirements:

Mandatory Requirements:

  • Bachelor’s degree or higher in Information Technology/Information Security. Candidates from other majors are accepted if they can demonstrate equivalent hands-on capabilities (practical certifications, published CVEs, Bug Bounty/CTF achievements).
  • More than 4 years of experience in IT/Information Security.
  • More than 3 years of direct experience in Web/API application penetration testing (excluding time spent on system operations, network administration, or purely SOC monitoring).
  • Have directly performed at least 15 Web/API application penetration testing projects and be able to present in detail one self-conducted exploitation case.
  • Professional English: ability to read technical documentation and write reports.
  • Cloud & AI: AWS/Azure/GCP security certifications; training courses or certifications in AI Security – AI Red Teaming (e.g., SANS SEC535).

(Acceptable alternative evidence of capabilities in lieu of certifications: HTB CPTS/CBBH/CWEE, PNPT; rankings on HackerOne/Bugcrowd/Intigriti; published CVEs; national/international CTF awards; self-developed open-source tools)

Preferred:

  • Strong preference (Web/API application penetration testing): OSCP/OSCP+, OSWA, OSWE, Burp Suite Certified Practitioner (BSCP), GWAPT (SANS SEC542).
  • Additional specialization: SANS SEC522 (Application Security), SEC540 (Cloud Native Security & DevSecOps), SEC588 (Cloud Penetration Testing), SEC560, CRTO, CREST CPSA/CRT.
  • Experience testing applications involving financial transactions or large-scale personal data processing is a significant advantage.
  • Experience testing cloud-native applications, large-scale APIs, or AI/LLM-integrated applications is a significant advantage.
  • Preference for candidates who have worked at penetration testing/Red Team service companies or regularly participated in Bug Bounty programs.
  • Knowledge of highly regulated environments (finance – banking, aviation, real estate, digital services) is an advantage.

Knowledge:

  • OWASP standards: Top 10 (latest version), WSTG, ASVS, API Security Top 10, Top 10 for LLM Applications, and Agentic AI risks.
  • Testing methodologies: PTES, NIST SP 800-115, MITRE ATT&CK, threat modeling (STRIDE), and risk rating based on CVSS 4.0.
  • Modern application architecture: SPA/JavaScript frameworks, microservices, API Gateway, GraphQL, WebSocket, and mobile application backends.
  • Identity and access: OAuth 2.0/OIDC, SAML, JWT, session management, MFA/passkeys, and Zero Trust principles.
  • Cloud and containers: AWS/Azure/GCP, Kubernetes, Docker, Serverless, Infrastructure-as-Code, and common misconfigurations.
  • DevSecOps and software supply chain: CI/CD, SAST/DAST/SCA, SBOM, secret management, and pipeline attacks.
  • AI security: LLM/RAG/Agentic AI risks, prompt injection, AI red teaming; reference NIST AI RMF.
  • Programming and automation: proficient in Python; capable of using Go/Bash/JavaScript; able to read and understand source code for white-box testing.
  • Tools: Burp Suite Professional, ZAP, Nuclei, ffuf, sqlmap, Semgrep, Metasploit, Frida/objection, Postman/Insomnia.
  • Standards and regulations: ISO/IEC 27001:2022, PCI DSS 4.0.1, NIST CSF 2.0, Cybersecurity Law, Personal Data Protection Law No. 91/2025/QH15.

Skills:

  • Systematic offensive mindset: persist in exploiting vulnerability chains rather than stopping at automated tool results.
  • Translate technical vulnerabilities into business impact to convince development teams to prioritize remediation.
  • Write clear, reproducible reports and present results bilingually in Vietnamese–English.
  • Analytical, problem-solving, and self-learning skills for researching new technologies.
  • Time management and ability to handle multiple penetration testing projects in parallel according to committed timelines.
  • Cross-functional collaboration with development, operations, and SOC teams, and ability to mentor colleagues.

Other Requirements:

  • Professional ethics and strict compliance with the testing scope (Rules of Engagement), NDA, and data protection regulations.
  • Ability to work independently, proactively research, and continuously learn at the pace of change in the field.
  • Willingness to perform testing outside regular working hours within approved testing windows.
  • Team spirit, strong commitment, and honesty in reporting results.
  • Clear criminal record/background check (mandatory for positions with access to critical systems).

Benefits:

  • Competitive salary package (Base salary and performance bonuses).
  • Probation period salary is 100% of the official salary.
  • Comprehensive health and accident insurance.
  • 15 days of annual leave, 3 remote work days per month.
  • Provision of work equipment (Macbook/ Laptop, mouse, monitor, etc.).
  • A creative and modern working environment.

Working location: Galaxy Innovation Hub – D1 Hi Tech Park, Tang Nhon Phu Ward, HCMC

Kindly send your CV to: talent@galaxyholdings.co 

Other hiring positions

Contact with
Galaxy Holdings

Contact Us