Position Overview:
- Directly perform in-depth penetration testing (black-box/gray-box/white-box) on the Company’s/Subsidiaries’ Web applications, APIs, mobile backends, and AI/LLM-integrated applications.
- Exploit and demonstrate vulnerabilities through controlled PoCs; rank risks based on technical severity in conjunction with business impact; perform retesting to verify remediation.
- Research new vulnerabilities and CVEs, write exploits, develop tools and automation scripts to support continuous testing and CI/CD integration.
- Provide technical consultation to development teams on root causes, remediation approaches, and secure coding; support Blue Team/SOC in developing detection scenarios (Purple Team).
- Comply with and contribute to improving methodologies, checklists, and report templates; provide technical guidance and mentoring to junior-level specialists.
Key Responsibilities:
1. In-depth Penetration Testing of Web Applications and APIs
- Perform manual testing in accordance with OWASP WSTG/ASVS: business logic flaws, IDOR/BOLA, privilege escalation, race conditions, SSRF, deserialization, HTTP request smuggling, client-side attacks (XSS, prototype pollution, DOM clobbering).
- Test REST/GraphQL/gRPC/Webhook APIs in accordance with the OWASP API Security Top 10; test authentication and authorization flows including OAuth 2.0/OIDC, SAML, JWT, SSO, MFA, and passkeys.
- Perform white-box testing: review source code (Java, .NET, Node.js, PHP, Python) to identify vulnerabilities that dynamic testing may not detect.
- Strictly control the testing scope (Rules of Engagement), minimizing impact on production systems and real data.
2. Testing Cloud-Native Applications and AI/LLM-Integrated Applications
- Test applications deployed on container/Kubernetes/Serverless platforms: misconfigurations, container escape, service account abuse, secret exposure, and Infrastructure-as-Code risks.
- Test AI/LLM-integrated and Agentic AI applications: direct and indirect prompt injection, data leakage through RAG, abuse of agent/tool privileges, MCP connection controls, and trust boundaries.
- Assess software supply chain risks: third-party libraries, SBOM, compromised dependencies, and credential leakage in CI/CD pipelines.
3. Vulnerability Research, Tool Development, and Automation
- Monitor and analyze CVEs and new attack techniques; assess their impact on the Group’s systems and propose response actions.
- Write PoCs/exploit code for publicly disclosed vulnerabilities and self-discovered vulnerabilities; research vulnerabilities in open-source frameworks currently in use.
- Develop internal scripts and tools (Python/Go/Bash), write Nuclei templates, and extend Burp Suite to shorten testing time.
- Participate in integrating SAST/DAST/SCA into CI/CD and fine-tune rules to reduce false positives.
4. Reporting, Remediation Consulting, and Defensive Coordination
- Prepare bilingual Vietnamese–English penetration testing reports: technical descriptions, exploitation evidence, CVSS 4.0-based ranking and business impact, and feasible remediation recommendations.
- Present findings to development teams and stakeholders; provide consultation on root causes and compensating controls (workarounds) when immediate patching is not possible.
- Convert exploitation scenarios into detection use cases based on MITRE ATT&CK; coordinate with the Blue Team/SOC to validate detection capabilities.
- Track remediation progress and perform retesting for Remediation Verification before closing vulnerabilities.
5. Methodology Standardization and Knowledge Sharing
- Contribute to improving the team’s processes, checklists, payload libraries, and report templates.
- Provide technical guidance and review the results and reports of junior-level specialists.
- Organize internal knowledge-sharing sessions on new attack techniques; contribute security awareness training content for development teams.
- Participate in advanced-level incident response and ad-hoc assessments when required.
Job Requirements:
Mandatory Requirements:
- Bachelor’s degree or higher in Information Technology/Information Security. Candidates from other majors are accepted if they can demonstrate equivalent hands-on capabilities (practical certifications, published CVEs, Bug Bounty/CTF achievements).
- More than 4 years of experience in IT/Information Security.
- More than 3 years of direct experience in Web/API application penetration testing (excluding time spent on system operations, network administration, or purely SOC monitoring).
- Have directly performed at least 15 Web/API application penetration testing projects and be able to present in detail one self-conducted exploitation case.
- Professional English: ability to read technical documentation and write reports.
- Cloud & AI: AWS/Azure/GCP security certifications; training courses or certifications in AI Security – AI Red Teaming (e.g., SANS SEC535).
(Acceptable alternative evidence of capabilities in lieu of certifications: HTB CPTS/CBBH/CWEE, PNPT; rankings on HackerOne/Bugcrowd/Intigriti; published CVEs; national/international CTF awards; self-developed open-source tools)
Preferred:
- Strong preference (Web/API application penetration testing): OSCP/OSCP+, OSWA, OSWE, Burp Suite Certified Practitioner (BSCP), GWAPT (SANS SEC542).
- Additional specialization: SANS SEC522 (Application Security), SEC540 (Cloud Native Security & DevSecOps), SEC588 (Cloud Penetration Testing), SEC560, CRTO, CREST CPSA/CRT.
- Experience testing applications involving financial transactions or large-scale personal data processing is a significant advantage.
- Experience testing cloud-native applications, large-scale APIs, or AI/LLM-integrated applications is a significant advantage.
- Preference for candidates who have worked at penetration testing/Red Team service companies or regularly participated in Bug Bounty programs.
- Knowledge of highly regulated environments (finance – banking, aviation, real estate, digital services) is an advantage.
Knowledge:
- OWASP standards: Top 10 (latest version), WSTG, ASVS, API Security Top 10, Top 10 for LLM Applications, and Agentic AI risks.
- Testing methodologies: PTES, NIST SP 800-115, MITRE ATT&CK, threat modeling (STRIDE), and risk rating based on CVSS 4.0.
- Modern application architecture: SPA/JavaScript frameworks, microservices, API Gateway, GraphQL, WebSocket, and mobile application backends.
- Identity and access: OAuth 2.0/OIDC, SAML, JWT, session management, MFA/passkeys, and Zero Trust principles.
- Cloud and containers: AWS/Azure/GCP, Kubernetes, Docker, Serverless, Infrastructure-as-Code, and common misconfigurations.
- DevSecOps and software supply chain: CI/CD, SAST/DAST/SCA, SBOM, secret management, and pipeline attacks.
- AI security: LLM/RAG/Agentic AI risks, prompt injection, AI red teaming; reference NIST AI RMF.
- Programming and automation: proficient in Python; capable of using Go/Bash/JavaScript; able to read and understand source code for white-box testing.
- Tools: Burp Suite Professional, ZAP, Nuclei, ffuf, sqlmap, Semgrep, Metasploit, Frida/objection, Postman/Insomnia.
- Standards and regulations: ISO/IEC 27001:2022, PCI DSS 4.0.1, NIST CSF 2.0, Cybersecurity Law, Personal Data Protection Law No. 91/2025/QH15.
Skills:
- Systematic offensive mindset: persist in exploiting vulnerability chains rather than stopping at automated tool results.
- Translate technical vulnerabilities into business impact to convince development teams to prioritize remediation.
- Write clear, reproducible reports and present results bilingually in Vietnamese–English.
- Analytical, problem-solving, and self-learning skills for researching new technologies.
- Time management and ability to handle multiple penetration testing projects in parallel according to committed timelines.
- Cross-functional collaboration with development, operations, and SOC teams, and ability to mentor colleagues.
Other Requirements:
- Professional ethics and strict compliance with the testing scope (Rules of Engagement), NDA, and data protection regulations.
- Ability to work independently, proactively research, and continuously learn at the pace of change in the field.
- Willingness to perform testing outside regular working hours within approved testing windows.
- Team spirit, strong commitment, and honesty in reporting results.
- Clear criminal record/background check (mandatory for positions with access to critical systems).
Benefits:
- Competitive salary package (Base salary and performance bonuses).
- Probation period salary is 100% of the official salary.
- Comprehensive health and accident insurance.
- 15 days of annual leave, 3 remote work days per month.
- Provision of work equipment (Macbook/ Laptop, mouse, monitor, etc.).
- A creative and modern working environment.
Working location: Galaxy Innovation Hub – D1 Hi Tech Park, Tang Nhon Phu Ward, HCMC
Kindly send your CV to: talent@galaxyholdings.co







