{"id":16167,"date":"2026-09-24T14:41:07","date_gmt":"2026-09-24T07:41:07","guid":{"rendered":"https:\/\/galaxyholdings.co\/?post_type=job&#038;p=16167"},"modified":"2026-09-24T14:41:07","modified_gmt":"2026-09-24T07:41:07","slug":"senior-web-api-penetration-tester","status":"publish","type":"job","link":"https:\/\/galaxyholdings.co\/en\/job\/senior-web-api-penetration-tester\/","title":{"rendered":"Senior Web &#038; API Penetration Tester"},"content":{"rendered":"<h2 data-section-id=\"1f787jk\" data-start=\"122\" data-end=\"140\"><strong><span style=\"font-size: 18pt; color: #0000ff;\">Position Overview:<\/span><\/strong><\/h2>\n<ul>\n<li>Directly perform in-depth penetration testing (black-box\/gray-box\/white-box) on the Company&#8217;s\/Subsidiaries&#8217; Web applications, APIs, mobile backends, and AI\/LLM-integrated applications.<\/li>\n<li>Exploit and demonstrate vulnerabilities through controlled PoCs; rank risks based on technical severity in conjunction with business impact; perform retesting to verify remediation.<\/li>\n<li>Research new vulnerabilities and CVEs, write exploits, develop tools and automation scripts to support continuous testing and CI\/CD integration.<\/li>\n<li>Provide technical consultation to development teams on root causes, remediation approaches, and secure coding; support Blue Team\/SOC in developing detection scenarios (Purple Team).<\/li>\n<li>Comply with and contribute to improving methodologies, checklists, and report templates; provide technical guidance and mentoring to junior-level specialists.<\/li>\n<\/ul>\n<h2 data-section-id=\"1f787jk\" data-start=\"122\" data-end=\"140\"><span style=\"font-size: 18pt; color: #0000ff;\">Key Responsibilities:<\/span><\/h2>\n<h3><span style=\"font-size: 14pt;\">1. In-depth Penetration Testing of Web Applications and APIs<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Perform manual testing in accordance with OWASP WSTG\/ASVS: business logic flaws, IDOR\/BOLA, privilege escalation, race conditions, SSRF, deserialization, HTTP request smuggling, client-side attacks (XSS, prototype pollution, DOM clobbering).<\/li>\n<li>Test REST\/GraphQL\/gRPC\/Webhook APIs in accordance with the OWASP API Security Top 10; test authentication and authorization flows including OAuth 2.0\/OIDC, SAML, JWT, SSO, MFA, and passkeys.<\/li>\n<li>Perform white-box testing: review source code (Java, .NET, Node.js, PHP, Python) to identify vulnerabilities that dynamic testing may not detect.<\/li>\n<li>Strictly control the testing scope (Rules of Engagement), minimizing impact on production systems and real data.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">2. Testing Cloud-Native Applications and AI\/LLM-Integrated Applications<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Test applications deployed on container\/Kubernetes\/Serverless platforms: misconfigurations, container escape, service account abuse, secret exposure, and Infrastructure-as-Code risks.<\/li>\n<li>Test AI\/LLM-integrated and Agentic AI applications: direct and indirect prompt injection, data leakage through RAG, abuse of agent\/tool privileges, MCP connection controls, and trust boundaries.<\/li>\n<li>Assess software supply chain risks: third-party libraries, SBOM, compromised dependencies, and credential leakage in CI\/CD pipelines.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">3. Vulnerability Research, Tool Development, and Automation<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Monitor and analyze CVEs and new attack techniques; assess their impact on the Group&#8217;s systems and propose response actions.<\/li>\n<li>Write PoCs\/exploit code for publicly disclosed vulnerabilities and self-discovered vulnerabilities; research vulnerabilities in open-source frameworks currently in use.<\/li>\n<li>Develop internal scripts and tools (Python\/Go\/Bash), write Nuclei templates, and extend Burp Suite to shorten testing time.<\/li>\n<li>Participate in integrating SAST\/DAST\/SCA into CI\/CD and fine-tune rules to reduce false positives.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">4. Reporting, Remediation Consulting, and Defensive Coordination<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Prepare bilingual Vietnamese\u2013English penetration testing reports: technical descriptions, exploitation evidence, CVSS 4.0-based ranking and business impact, and feasible remediation recommendations.<\/li>\n<li>Present findings to development teams and stakeholders; provide consultation on root causes and compensating controls (workarounds) when immediate patching is not possible.<\/li>\n<li>Convert exploitation scenarios into detection use cases based on MITRE ATT&amp;CK; coordinate with the Blue Team\/SOC to validate detection capabilities.<\/li>\n<li>Track remediation progress and perform retesting for Remediation Verification before closing vulnerabilities.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">5. Methodology Standardization and Knowledge Sharing<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Contribute to improving the team&#8217;s processes, checklists, payload libraries, and report templates.<\/li>\n<li>Provide technical guidance and review the results and reports of junior-level specialists.<\/li>\n<li>Organize internal knowledge-sharing sessions on new attack techniques; contribute security awareness training content for development teams.<\/li>\n<li>Participate in advanced-level incident response and ad-hoc assessments when required.<\/li>\n<\/ul>\n<h2 data-section-id=\"1uxnuvu\" data-start=\"2250\" data-end=\"2270\"><span style=\"font-size: 18pt; color: #0000ff;\">Job Requirements:<\/span><\/h2>\n<h3><span style=\"font-size: 14pt;\">Mandatory Requirements:<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Bachelor&#8217;s degree or higher in Information Technology\/Information Security. Candidates from other majors are accepted if they can demonstrate equivalent hands-on capabilities (practical certifications, published CVEs, Bug Bounty\/CTF achievements).<\/li>\n<li>More than 4 years of experience in IT\/Information Security.<\/li>\n<li>More than 3 years of direct experience in Web\/API application penetration testing (excluding time spent on system operations, network administration, or purely SOC monitoring).<\/li>\n<li>Have directly performed at least 15 Web\/API application penetration testing projects and be able to present in detail one self-conducted exploitation case.<\/li>\n<li>Professional English: ability to read technical documentation and write reports.<\/li>\n<li>Cloud &amp; AI: AWS\/Azure\/GCP security certifications; training courses or certifications in AI Security \u2013 AI Red Teaming (e.g., SANS SEC535).<\/li>\n<\/ul>\n<p class=\"isSelectedEnd\">(Acceptable alternative evidence of capabilities in lieu of certifications: HTB CPTS\/CBBH\/CWEE, PNPT; rankings on HackerOne\/Bugcrowd\/Intigriti; published CVEs; national\/international CTF awards; self-developed open-source tools)<\/p>\n<h3><span style=\"font-size: 14pt;\">Preferred:<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Strong preference (Web\/API application penetration testing): OSCP\/OSCP+, OSWA, OSWE, Burp Suite Certified Practitioner (BSCP), GWAPT (SANS SEC542).<\/li>\n<li>Additional specialization: SANS SEC522 (Application Security), SEC540 (Cloud Native Security &amp; DevSecOps), SEC588 (Cloud Penetration Testing), SEC560, CRTO, CREST CPSA\/CRT.<\/li>\n<li>Experience testing applications involving financial transactions or large-scale personal data processing is a significant advantage.<\/li>\n<li>Experience testing cloud-native applications, large-scale APIs, or AI\/LLM-integrated applications is a significant advantage.<\/li>\n<li>Preference for candidates who have worked at penetration testing\/Red Team service companies or regularly participated in Bug Bounty programs.<\/li>\n<li>Knowledge of highly regulated environments (finance \u2013 banking, aviation, real estate, digital services) is an advantage.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">Knowledge:<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>OWASP standards: Top 10 (latest version), WSTG, ASVS, API Security Top 10, Top 10 for LLM Applications, and Agentic AI risks.<\/li>\n<li>Testing methodologies: PTES, NIST SP 800-115, MITRE ATT&amp;CK, threat modeling (STRIDE), and risk rating based on CVSS 4.0.<\/li>\n<li>Modern application architecture: SPA\/JavaScript frameworks, microservices, API Gateway, GraphQL, WebSocket, and mobile application backends.<\/li>\n<li>Identity and access: OAuth 2.0\/OIDC, SAML, JWT, session management, MFA\/passkeys, and Zero Trust principles.<\/li>\n<li>Cloud and containers: AWS\/Azure\/GCP, Kubernetes, Docker, Serverless, Infrastructure-as-Code, and common misconfigurations.<\/li>\n<li>DevSecOps and software supply chain: CI\/CD, SAST\/DAST\/SCA, SBOM, secret management, and pipeline attacks.<\/li>\n<li>AI security: LLM\/RAG\/Agentic AI risks, prompt injection, AI red teaming; reference NIST AI RMF.<\/li>\n<li>Programming and automation: proficient in Python; capable of using Go\/Bash\/JavaScript; able to read and understand source code for white-box testing.<\/li>\n<li>Tools: Burp Suite Professional, ZAP, Nuclei, ffuf, sqlmap, Semgrep, Metasploit, Frida\/objection, Postman\/Insomnia.<\/li>\n<li>Standards and regulations: ISO\/IEC 27001:2022, PCI DSS 4.0.1, NIST CSF 2.0, Cybersecurity Law, Personal Data Protection Law No. 91\/2025\/QH15.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">Skills:<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Systematic offensive mindset: persist in exploiting vulnerability chains rather than stopping at automated tool results.<\/li>\n<li>Translate technical vulnerabilities into business impact to convince development teams to prioritize remediation.<\/li>\n<li>Write clear, reproducible reports and present results bilingually in Vietnamese\u2013English.<\/li>\n<li>Analytical, problem-solving, and self-learning skills for researching new technologies.<\/li>\n<li>Time management and ability to handle multiple penetration testing projects in parallel according to committed timelines.<\/li>\n<li>Cross-functional collaboration with development, operations, and SOC teams, and ability to mentor colleagues.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">Other Requirements:<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Professional ethics and strict compliance with the testing scope (Rules of Engagement), NDA, and data protection regulations.<\/li>\n<li>Ability to work independently, proactively research, and continuously learn at the pace of change in the field.<\/li>\n<li>Willingness to perform testing outside regular working hours within approved testing windows.<\/li>\n<li>Team spirit, strong commitment, and honesty in reporting results.<\/li>\n<li>Clear criminal record\/background check (mandatory for positions with access to critical systems).<\/li>\n<\/ul>\n<h2><span style=\"font-size: 18pt; color: #0000ff;\"><strong><span class=\"rnc2Gd\">Benefits:<\/span><\/strong><\/span><\/h2>\n<ul>\n<li>Competitive salary package (Base salary and performance bonuses).<\/li>\n<li>Probation period salary is 100% of the official salary.<\/li>\n<li>Comprehensive health and accident insurance.<\/li>\n<li>15 days of annual leave, 3 remote work days per month.<\/li>\n<li>Provision of work equipment (Macbook\/ Laptop, mouse, monitor, etc.).<\/li>\n<li>A creative and modern working environment.<\/li>\n<\/ul>\n<p><span style=\"color: #0000ff;\"><span style=\"font-weight: 400;\">Working location: <\/span><b>Galaxy Innovation Hub \u2013 D1 Hi Tech Park, Tang Nhon Phu Ward, HCMC<\/b><\/span><\/p>\n<p><span style=\"color: #0000ff;\"><span style=\"font-weight: 400;\">Kindly send your CV to: <\/span><b>talent@galaxyholdings.co\u00a0<\/b><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Position Overview: Directly perform in-depth penetration testing (black-box\/gray-box\/white-box) on the Company&#8217;s\/Subsidiaries&#8217; Web applications, APIs, mobile backends, and AI\/LLM-integrated applications. Exploit and demonstrate vulnerabilities through controlled PoCs; rank risks based on technical severity in conjunction with business impact; perform retesting to verify remediation. Research new vulnerabilities and CVEs, write exploits, develop tools and automation scripts to [&hellip;]<\/p>\n","protected":false},"template":"","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}}},"class_list":["post-16167","job","type-job","status-publish","hentry","company-galaxy-holdings","field-tech-en","job_type-full-time-en","location-ho-chi-minh"],"acf":[],"_links":{"self":[{"href":"https:\/\/galaxyholdings.co\/en\/wp-json\/wp\/v2\/job\/16167","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/galaxyholdings.co\/en\/wp-json\/wp\/v2\/job"}],"about":[{"href":"https:\/\/galaxyholdings.co\/en\/wp-json\/wp\/v2\/types\/job"}],"wp:attachment":[{"href":"https:\/\/galaxyholdings.co\/en\/wp-json\/wp\/v2\/media?parent=16167"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}