Lead Penetration Tester – Web, API & AI Applications

Position Overview:

  • Lead the penetration testing (Offensive Security) capabilities for all Web applications, APIs, Mobile backends, and AI/LLM-integrated applications of the Company/Subsidiaries.
  • Build and operate a continuous testing model (CTEM/PTaaS): combining in-depth manual testing with automation and integration into CI/CD under the DevSecOps model.
  • Perform and coordinate penetration testing across Web/API application environments, cloud-native infrastructure (Container, Kubernetes, Serverless), and the software supply chain.
  • Translate testing results into risk mitigation recommendations for the Blue Team/SOC and development teams; lead Purple Team activities.
  • Standardize methodologies (OWASP WSTG/ASVS, PTES, NIST SP 800-115), processes, and ensure compliance with ISO/IEC 27001:2022, PCI DSS 4.x, Cybersecurity Law, and Personal Data Protection Law No. 91/2025/QH15.
  • Manage resources, develop the team, and report application risk exposure levels to senior management.

Key Responsibilities:

1. Build and Operate Continuous – Automated Testing Capabilities

  • Deploy and operate testing platforms and toolsets (Burp Suite Professional/Enterprise, ZAP, Nuclei, SAST/DAST/SCA/IAST).
  • Integrate security testing into the CI/CD pipeline (shift-left), manage SBOM and software supply chain risks.
  • Research new CVEs, write PoCs/exploit code, develop internal tools (Python/Go), and automate testing processes.
  • Apply AI/LLM to accelerate analysis and report preparation, while controlling data leakage risks when using AI.
  • Advise senior management on new application security technologies and solutions for entities within the ecosystem.

2. Penetration Testing of Web, API, and AI-Integrated Applications

  • Perform in-depth manual testing according to OWASP WSTG/ASVS: business logic flaws, IDOR/BOLA, race conditions, SSRF, deserialization, HTTP request smuggling, client-side attacks.
  • Test APIs (REST/GraphQL/gRPC/Webhook) according to the OWASP API Security Top 10; test authorization, OAuth 2.0/OIDC, SAML, JWT, SSO, and passwordless authentication (passkey) flows.
  • Test AI/LLM-integrated and Agentic AI applications: prompt injection, data leakage through RAG, abuse of agent/tool privileges, and MCP connection controls.
  • Provide exploitation evidence (PoC), rank risks according to CVSS 4.0 linked to business impact; perform retesting to verify remediation (Remediation Verification).
  • Coordinate with relevant departments to develop remediation and reassessment plans.

3. Support Blue Team/SOC in Enhancing Defensive Capabilities (Purple Team)

  • Convert attack scenarios into detection use cases based on MITRE ATT&CK; measure detection and response capabilities.
  • Advise on application defense architecture: WAF/WAAP, API Gateway, bot and API abuse protection, and Zero Trust principles.
  • Monitor the vulnerability remediation lifecycle (MTTR), and provide early warnings of exposure risks on the Internet attack surface (EASM).

4. Standardize Processes, Methodologies, and Compliance

  • Develop and periodically review processes, regulations, checklists, and bilingual Vietnamese–English penetration testing report templates.
  • Ensure testing activities comply with ISO/IEC 27001:2022, PCI DSS 4.0.1, NIST CSF 2.0, Cybersecurity Law, Personal Data Protection Law No. 91/2025/QH15, and industry-specific regulations.
  • Manage, back up, and upgrade the testing lab infrastructure; strictly protect sensitive data generated during testing.

5. Team Management, Resource Coordination, and Reporting

  • Assign tasks, monitor quality, and review all reports before release.
  • Develop capability development roadmaps, training programs, and performance evaluations for the team.
  • Manage independent penetration testing vendors, Bug Bounty/VDP programs, and tool budgets.
  • Periodically report application risk and exposure dashboards to senior management.

Job Requirements:

Mandatory Requirements:

  • Bachelor’s degree or higher in Information Technology/Information Security. Candidates from other majors are accepted if they can demonstrate equivalent hands-on capabilities (certifications, CVEs, Bug Bounty, CTF).
  • Professional English: ability to read technical documentation and write reports.
  • Cloud & AI: AWS/Azure/GCP security certifications, CCSP; training courses/certifications in AI Security – AI Red Teaming (e.g., SANS SEC535).
  • (Acceptable alternative evidence of capabilities: HTB CPTS/CBBH/CWEE, PNPT; rankings on HackerOne/Bugcrowd/Intigriti; published CVEs; national/international CTF achievements.)
  • More than 6 years of experience in IT/Information Security.
  • More than 4 years of direct experience in Web/API application penetration testing (excluding time spent purely on system operations).
  • More than 2 years of experience managing a technical team of 3 or more members, or serving as Technical Lead for a Group-scale penetration testing project.
  • Have led or directly performed at least 20 Web/API application penetration testing projects.

Preferred:

  • Strong preference (Web/API application penetration testing): OSCP/OSCP+, OSWE, OSWA, Burp Suite Certified Practitioner (BSCP), GWAPT (SANS SEC542).
  • Additional specialization: SANS SEC522 (Application Security), SEC540 (Cloud Native Security & DevSecOps), SEC588 (Cloud Penetration Testing), SEC560, OSEP, CRTO, CREST CPSA/CRT/CCT.
  • Management certifications: CISSP, CISM, CISA, or ISO/IEC 27001 Lead Auditor/Lead Implementer are an advantage.
  • Experience in highly regulated environments: finance – banking, aviation, real estate, commerce, and services; familiarity with the Group’s ecosystem is an advantage.
  • Experience testing cloud-native applications, large-scale APIs, and AI/LLM-integrated applications is a significant advantage.
  • Preference for candidates who have worked at penetration testing/Red Team service companies or participated in Bug Bounty programs.
  • Knowledge of the Group’s organizational structure, business areas, and culture is an advantage.

Knowledge:

  • OWASP standards: Top 10 (latest version), WSTG, ASVS, API Security Top 10, Top 10 for LLM Applications, and Agentic AI risks.
  • Testing methodologies: PTES, NIST SP 800-115, MITRE ATT&CK, threat modeling (STRIDE), and CVSS 4.0 risk rating.
  • Modern application architecture: SPA/JavaScript frameworks, microservices, API Gateway, GraphQL, WebSocket, and mobile application backends.
  • Cloud and container security: AWS/Azure/GCP, Kubernetes, Docker, Serverless, Infrastructure-as-Code, CNAPP/CSPM.
  • Identity and access: OAuth 2.0/OIDC, SAML, JWT, MFA/passkey, and Zero Trust architecture.
  • DevSecOps and software supply chain: CI/CD, SAST/DAST/SCA, SBOM, secret management, and pipeline attacks.
  • AI security: LLM/RAG/Agentic AI risks, prompt injection, AI red teaming, with reference to NIST AI RMF.
  • Programming and automation: Python, Go, Bash, JavaScript; ability to read and understand source code (Java, .NET, Node.js, PHP) for white-box testing.
  • Standards and regulations: ISO/IEC 27001:2022, PCI DSS 4.0.1, NIST CSF 2.0, Cybersecurity Law, Personal Data Protection Law No. 91/2025/QH15, and regulations on ensuring system security by level.

Skills:

  • Business-oriented risk mindset: translate technical vulnerabilities into business impact.
  • Write reports and present findings bilingually in Vietnamese–English to both technical teams and senior management.
  • Plan, organize, and manage projects using the Agile model.
  • Analytical, problem-solving, and decision-making skills under time pressure.
  • Team management, task assignment, and mentoring skills for developing successors.
  • Communication, cross-functional coordination, and effective teamwork.

Other Requirements:

  • Professional ethics and strict compliance with the testing scope (Rules of Engagement), NDA, and data protection regulations.
  • Ability to work independently, proactively research, and continuously learn at the pace of change in the field.
  • Willingness to perform testing outside regular working hours within approved testing windows.
  • Team spirit, strong commitment, and honesty in reporting results.
  • Clear criminal record/background check (mandatory for positions with access to critical systems).

Benefits:

  • Competitive salary package (Base salary and performance bonuses).
  • Probation period salary is 100% of the official salary.
  • Comprehensive health and accident insurance.
  • 15 days of annual leave, 3 remote work days per month.
  • Provision of work equipment (Macbook/ Laptop, mouse, monitor, etc.).
  • A creative and modern working environment.

Working location: Galaxy Innovation Hub – D1 Hi Tech Park, Tang Nhon Phu Ward, HCMC

Kindly send your CV to: talent@galaxyholdings.co 

Other hiring positions

Contact with
Galaxy Holdings

Contact Us