Senior Penetration Tester
Vị trí kiểm thử xâm nhập cấp cao tại HD Global Career cho phép làm việc remote tại Việt Nam với mức lương lên đến 62 triệu VND/tháng cùng chế độ thưởng, bảo hiểm, thiết bị làm việc và cơ hội phát triển. Vai trò này tập trung kiểm thử xâm nhập chuyên sâu (web, API, mạng, cloud...) kết hợp tự động hóa, phát triển công cụ, báo cáo kết quả cho khách hàng và tham gia các dự án an ninh nội bộ.
Yêu cầu tối thiểu 5 năm kinh nghiệm làm kiểm thử xâm nhập, thành thạo Python, TypeScript, quen thuộc với AWS/Azure/GCP và sở hữu chứng chỉ OSCP hoặc tương đương. Cần Tiếng Anh tốt cho trao đổi kỹ thuật, kỹ năng làm việc độc lập, tư duy giải quyết vấn đề và ưu tiên ứng viên có bề dày đóng góp cho cộng đồng an ninh.
About the Role
We are building a new Offensive Security Center of Excellence in Vietnam and are looking for senior penetration testers to form the founding team. You will focus primarily on hands-on offensive security engagements, with a strong preference for candidates who have depth in at least two of the following areas:
- Web application and API penetration testing
- External network penetration testing
- Internal network and Active Directory penetration testing
- Cloud penetration testing and cloud security assessment
- Mobile application security (iOS / Android)
- AI / LLM application penetration testing
- Desktop or thick client application testing
- Social engineering
- Red team and adversary simulation
You do not need to be an expert in every area above. Strong expertise in two or more, and solid familiarity with several others, is exactly what we are looking for. From time to time, you may also participate in client-facing cyber engineering work or internal security engineering and software development projects, so good programming skills are also important (we’re a Python and TypeScript shop). This is a senior role with real influence on how we test, build tools, and operate as a global security team.
Key Responsibilities
Penetration testing and red teaming
- Plan and execute manual penetration tests depending on your areas of expertise.
- Conduct red team and adversary simulation style engagements where required.
- Perform scoping, threat modeling, and test plan design for complex engagements.
- Identify, exploit, and chain vulnerabilities using industry standard methodologies and frameworks.
- Produce clear, actionable reports with risk ratings and remediation guidance.
- Present findings to customers and internal stakeholders and support them through remediation.
Tooling, automation, and AI
- Design, build, and maintain internal utilities.
- Experiment with automation and AI to improve test coverage.
- Contribute tools, scripts, or research back to the security community.
Cyber engineering and internal projects
- Support client facing cyber engineering requirements.
- Contribute to internal security engineering or software development projects.
- Build robust, maintainable solutions using programming skills.
Similar Jobs





