{"id":16170,"date":"2026-09-24T14:52:24","date_gmt":"2026-09-24T07:52:24","guid":{"rendered":"https:\/\/galaxyholdings.co\/?post_type=job&#038;p=16170"},"modified":"2026-09-24T14:52:24","modified_gmt":"2026-09-24T07:52:24","slug":"lead-penetration-tester-web-api-ai-applications","status":"publish","type":"job","link":"https:\/\/galaxyholdings.co\/en\/job\/lead-penetration-tester-web-api-ai-applications\/","title":{"rendered":"Lead Penetration Tester \u2013 Web, API &#038; AI Applications"},"content":{"rendered":"<h2 data-section-id=\"1f787jk\" data-start=\"122\" data-end=\"140\"><strong><span style=\"font-size: 18pt; color: #0000ff;\">Position Overview:<\/span><\/strong><\/h2>\n<ul>\n<li>Lead the penetration testing (Offensive Security) capabilities for all Web applications, APIs, Mobile backends, and AI\/LLM-integrated applications of the Company\/Subsidiaries.<\/li>\n<li>Build and operate a continuous testing model (CTEM\/PTaaS): combining in-depth manual testing with automation and integration into CI\/CD under the DevSecOps model.<\/li>\n<li>Perform and coordinate penetration testing across Web\/API application environments, cloud-native infrastructure (Container, Kubernetes, Serverless), and the software supply chain.<\/li>\n<li>Translate testing results into risk mitigation recommendations for the Blue Team\/SOC and development teams; lead Purple Team activities.<\/li>\n<li>Standardize methodologies (OWASP WSTG\/ASVS, PTES, NIST SP 800-115), processes, and ensure compliance with ISO\/IEC 27001:2022, PCI DSS 4.x, Cybersecurity Law, and Personal Data Protection Law No. 91\/2025\/QH15.<\/li>\n<li>Manage resources, develop the team, and report application risk exposure levels to senior management.<\/li>\n<\/ul>\n<h2 data-section-id=\"1f787jk\" data-start=\"122\" data-end=\"140\"><span style=\"font-size: 18pt; color: #0000ff;\">Key Responsibilities:<\/span><\/h2>\n<h3><span style=\"font-size: 14pt;\">1. Build and Operate Continuous \u2013 Automated Testing Capabilities<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Deploy and operate testing platforms and toolsets (Burp Suite Professional\/Enterprise, ZAP, Nuclei, SAST\/DAST\/SCA\/IAST).<\/li>\n<li>Integrate security testing into the CI\/CD pipeline (shift-left), manage SBOM and software supply chain risks.<\/li>\n<li>Research new CVEs, write PoCs\/exploit code, develop internal tools (Python\/Go), and automate testing processes.<\/li>\n<li>Apply AI\/LLM to accelerate analysis and report preparation, while controlling data leakage risks when using AI.<\/li>\n<li>Advise senior management on new application security technologies and solutions for entities within the ecosystem.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">2. Penetration Testing of Web, API, and AI-Integrated Applications<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Perform in-depth manual testing according to OWASP WSTG\/ASVS: business logic flaws, IDOR\/BOLA, race conditions, SSRF, deserialization, HTTP request smuggling, client-side attacks.<\/li>\n<li>Test APIs (REST\/GraphQL\/gRPC\/Webhook) according to the OWASP API Security Top 10; test authorization, OAuth 2.0\/OIDC, SAML, JWT, SSO, and passwordless authentication (passkey) flows.<\/li>\n<li>Test AI\/LLM-integrated and Agentic AI applications: prompt injection, data leakage through RAG, abuse of agent\/tool privileges, and MCP connection controls.<\/li>\n<li>Provide exploitation evidence (PoC), rank risks according to CVSS 4.0 linked to business impact; perform retesting to verify remediation (Remediation Verification).<\/li>\n<li>Coordinate with relevant departments to develop remediation and reassessment plans.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">3. Support Blue Team\/SOC in Enhancing Defensive Capabilities (Purple Team)<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Convert attack scenarios into detection use cases based on MITRE ATT&amp;CK; measure detection and response capabilities.<\/li>\n<li>Advise on application defense architecture: WAF\/WAAP, API Gateway, bot and API abuse protection, and Zero Trust principles.<\/li>\n<li>Monitor the vulnerability remediation lifecycle (MTTR), and provide early warnings of exposure risks on the Internet attack surface (EASM).<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">4. Standardize Processes, Methodologies, and Compliance<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Develop and periodically review processes, regulations, checklists, and bilingual Vietnamese\u2013English penetration testing report templates.<\/li>\n<li>Ensure testing activities comply with ISO\/IEC 27001:2022, PCI DSS 4.0.1, NIST CSF 2.0, Cybersecurity Law, Personal Data Protection Law No. 91\/2025\/QH15, and industry-specific regulations.<\/li>\n<li>Manage, back up, and upgrade the testing lab infrastructure; strictly protect sensitive data generated during testing.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">5. Team Management, Resource Coordination, and Reporting<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Assign tasks, monitor quality, and review all reports before release.<\/li>\n<li>Develop capability development roadmaps, training programs, and performance evaluations for the team.<\/li>\n<li>Manage independent penetration testing vendors, Bug Bounty\/VDP programs, and tool budgets.<\/li>\n<li>Periodically report application risk and exposure dashboards to senior management.<\/li>\n<\/ul>\n<h2 data-section-id=\"1uxnuvu\" data-start=\"2250\" data-end=\"2270\"><span style=\"font-size: 18pt; color: #0000ff;\">Job Requirements:<\/span><\/h2>\n<h3><span style=\"font-size: 14pt;\">Mandatory Requirements:<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Bachelor&#8217;s degree or higher in Information Technology\/Information Security. Candidates from other majors are accepted if they can demonstrate equivalent hands-on capabilities (certifications, CVEs, Bug Bounty, CTF).<\/li>\n<li>Professional English: ability to read technical documentation and write reports.<\/li>\n<li>Cloud &amp; AI: AWS\/Azure\/GCP security certifications, CCSP; training courses\/certifications in AI Security \u2013 AI Red Teaming (e.g., SANS SEC535).<\/li>\n<li>(Acceptable alternative evidence of capabilities: HTB CPTS\/CBBH\/CWEE, PNPT; rankings on HackerOne\/Bugcrowd\/Intigriti; published CVEs; national\/international CTF achievements.)<\/li>\n<li>More than 6 years of experience in IT\/Information Security.<\/li>\n<li>More than 4 years of direct experience in Web\/API application penetration testing (excluding time spent purely on system operations).<\/li>\n<li>More than 2 years of experience managing a technical team of 3 or more members, or serving as Technical Lead for a Group-scale penetration testing project.<\/li>\n<li>Have led or directly performed at least 20 Web\/API application penetration testing projects.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">Preferred:<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Strong preference (Web\/API application penetration testing): OSCP\/OSCP+, OSWE, OSWA, Burp Suite Certified Practitioner (BSCP), GWAPT (SANS SEC542).<\/li>\n<li>Additional specialization: SANS SEC522 (Application Security), SEC540 (Cloud Native Security &amp; DevSecOps), SEC588 (Cloud Penetration Testing), SEC560, OSEP, CRTO, CREST CPSA\/CRT\/CCT.<\/li>\n<li>Management certifications: CISSP, CISM, CISA, or ISO\/IEC 27001 Lead Auditor\/Lead Implementer are an advantage.<\/li>\n<li>Experience in highly regulated environments: finance \u2013 banking, aviation, real estate, commerce, and services; familiarity with the Group&#8217;s ecosystem is an advantage.<\/li>\n<li>Experience testing cloud-native applications, large-scale APIs, and AI\/LLM-integrated applications is a significant advantage.<\/li>\n<li>Preference for candidates who have worked at penetration testing\/Red Team service companies or participated in Bug Bounty programs.<\/li>\n<li>Knowledge of the Group&#8217;s organizational structure, business areas, and culture is an advantage.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">Knowledge:<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>OWASP standards: Top 10 (latest version), WSTG, ASVS, API Security Top 10, Top 10 for LLM Applications, and Agentic AI risks.<\/li>\n<li>Testing methodologies: PTES, NIST SP 800-115, MITRE ATT&amp;CK, threat modeling (STRIDE), and CVSS 4.0 risk rating.<\/li>\n<li>Modern application architecture: SPA\/JavaScript frameworks, microservices, API Gateway, GraphQL, WebSocket, and mobile application backends.<\/li>\n<li>Cloud and container security: AWS\/Azure\/GCP, Kubernetes, Docker, Serverless, Infrastructure-as-Code, CNAPP\/CSPM.<\/li>\n<li>Identity and access: OAuth 2.0\/OIDC, SAML, JWT, MFA\/passkey, and Zero Trust architecture.<\/li>\n<li>DevSecOps and software supply chain: CI\/CD, SAST\/DAST\/SCA, SBOM, secret management, and pipeline attacks.<\/li>\n<li>AI security: LLM\/RAG\/Agentic AI risks, prompt injection, AI red teaming, with reference to NIST AI RMF.<\/li>\n<li>Programming and automation: Python, Go, Bash, JavaScript; ability to read and understand source code (Java, .NET, Node.js, PHP) for white-box testing.<\/li>\n<li>Standards and regulations: ISO\/IEC 27001:2022, PCI DSS 4.0.1, NIST CSF 2.0, Cybersecurity Law, Personal Data Protection Law No. 91\/2025\/QH15, and regulations on ensuring system security by level.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">Skills:<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Business-oriented risk mindset: translate technical vulnerabilities into business impact.<\/li>\n<li>Write reports and present findings bilingually in Vietnamese\u2013English to both technical teams and senior management.<\/li>\n<li>Plan, organize, and manage projects using the Agile model.<\/li>\n<li>Analytical, problem-solving, and decision-making skills under time pressure.<\/li>\n<li>Team management, task assignment, and mentoring skills for developing successors.<\/li>\n<li>Communication, cross-functional coordination, and effective teamwork.<\/li>\n<\/ul>\n<h3><span style=\"font-size: 14pt;\">Other Requirements:<\/span><\/h3>\n<ul data-spread=\"false\">\n<li>Professional ethics and strict compliance with the testing scope (Rules of Engagement), NDA, and data protection regulations.<\/li>\n<li>Ability to work independently, proactively research, and continuously learn at the pace of change in the field.<\/li>\n<li>Willingness to perform testing outside regular working hours within approved testing windows.<\/li>\n<li>Team spirit, strong commitment, and honesty in reporting results.<\/li>\n<li>Clear criminal record\/background check (mandatory for positions with access to critical systems).<\/li>\n<\/ul>\n<h2><span style=\"font-size: 18pt; color: #0000ff;\"><strong><span class=\"rnc2Gd\">Benefits:<\/span><\/strong><\/span><\/h2>\n<ul>\n<li>Competitive salary package (Base salary and performance bonuses).<\/li>\n<li>Probation period salary is 100% of the official salary.<\/li>\n<li>Comprehensive health and accident insurance.<\/li>\n<li>15 days of annual leave, 3 remote work days per month.<\/li>\n<li>Provision of work equipment (Macbook\/ Laptop, mouse, monitor, etc.).<\/li>\n<li>A creative and modern working environment.<\/li>\n<\/ul>\n<p><span style=\"color: #0000ff;\"><span style=\"font-weight: 400;\">Working location: <\/span><b>Galaxy Innovation Hub \u2013 D1 Hi Tech Park, Tang Nhon Phu Ward, HCMC<\/b><\/span><\/p>\n<p><span style=\"color: #0000ff;\"><span style=\"font-weight: 400;\">Kindly send your CV to: <\/span><b>talent@galaxyholdings.co\u00a0<\/b><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Position Overview: Lead the penetration testing (Offensive Security) capabilities for all Web applications, APIs, Mobile backends, and AI\/LLM-integrated applications of the Company\/Subsidiaries. Build and operate a continuous testing model (CTEM\/PTaaS): combining in-depth manual testing with automation and integration into CI\/CD under the DevSecOps model. Perform and coordinate penetration testing across Web\/API application environments, cloud-native infrastructure [&hellip;]<\/p>\n","protected":false},"template":"","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}}},"class_list":["post-16170","job","type-job","status-publish","hentry","company-galaxy-holdings","field-tech-en","job_type-full-time-en","location-ho-chi-minh"],"acf":[],"_links":{"self":[{"href":"https:\/\/galaxyholdings.co\/en\/wp-json\/wp\/v2\/job\/16170","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/galaxyholdings.co\/en\/wp-json\/wp\/v2\/job"}],"about":[{"href":"https:\/\/galaxyholdings.co\/en\/wp-json\/wp\/v2\/types\/job"}],"wp:attachment":[{"href":"https:\/\/galaxyholdings.co\/en\/wp-json\/wp\/v2\/media?parent=16170"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}