Bỏ qua đến nội dung
joblake.
Tìm việc làmThống kêVề JobLake
Bớt tìm kiếm. Thêm cơ hội.
Trở lại danh sách
ITviec

Penetration Tester (all levels)

GFT Technologies Vietnam

Mức lươngChưa có thông tin lương
Địa điểmHồ Chí Minh · Hà Nội
Hình thứcToàn thời gian
Nơi làm việcKết hợp văn phòng và từ xa
Cấp bậcJunior · Middle · Senior
01

Mô tả công việc

Role Summary As a Penetration Tester at GFT, you will assess and strengthen the security of banking applications, APIs, cloud platforms, infrastructure, and digital systems through authorised penetration testing. You will identify vulnerabilities, validate risks, support remediation, and ensure compliance with security and regulatory standards. Working closely with security, engineering, DevOps, architecture, and business teams, you will perform security assessments across web, mobile, API, network, and cloud environments. This role requires strong ethical hacking expertise, knowledge of banking systems, and the flexibility to work onsite at client locations when required. Role Responsibilities Conduct penetration testing across web, mobile, APIs, cloud, infrastructure, and banking platforms. Identify, validate, and document security vulnerabilities, including authentication, authorization, encryption, access control, session management, input validation, and business logic flaws. Perform security assessments using OWASP Top 10, OWASP API Top 10, OWASP MSTG, and banking security standards. Assess banking workflows, including payments, cards, accounts, AML/KYC, fraud management, and digital banking services. Produce penetration testing reports with risk ratings, business impact, evidence, and remediation recommendations. Partner with engineering and security teams to explain findings, support remediation, and validate fixes. Support security activities across the SDLC, including threat modelling, test planning, and release validation. Perform vulnerability assessments, validate exploitability, and eliminate false positives. Support audit and compliance activities with security evidence and remediation tracking. Stay current with emerging threats, attack techniques, and security best practice.

02

Yêu cầu công việc

Hands-on experience in penetration testing, ethical hacking, and vulnerability assessments across web, mobile, API, network, and cloud environments. Strong understanding of banking systems, digital banking, payments, AML/KYC, fraud management, and transaction workflows. Deep knowledge of web and API security, including OWASP Top 10, API security, IDOR, injection, broken access control, authentication, authorization, and business logic vulnerabilities. Experience testing iOS and Android applications, including authentication, session management, local storage, certificate pinning, and secure communications. Experience assessing networks, servers, operating systems, infrastructure security, and common vulnerabilities Knowledge of cloud security principles across AWS, Azure, or GCP. Proficiency with Burp Suite, OWASP ZAP, Nmap, Nessus, Metasploit, Wireshark, Postman, MobSF, or similar tools. Ability to produce clear security reports and communicate findings to technical and business stakeholders. Experience working with engineering teams to validate vulnerabilities, support remediation, and perform retesting. Understanding of secure coding, encryption, IAM, data privacy, and common security frameworks. Familiarity with security requirements in regulated industries, particularly banking and financial services. Excellent English communication skills. Nice to Have Experience delivering penetration testing for banks, fintechs, payment platforms, or financial institutions. Knowledge of PCI DSS, ISO 27001, SOC 2, SWIFT CSCF, and other banking security standards. Experience with secure code reviews and SAST tools. Experience integrating security into CI/CD pipelines using SAST, DAST, SCA, container scanning, or secrets detection. Knowledge of container, Kubernetes, Docker, cloud, and Infrastructure-as-Code (IaC) security. Experience with red teaming, attack simulation, or adversary emulation. Scripting skills in Python, Bash, or PowerShell for automation. Security certifications such as CEH, eJPT, PNPT, OSCP, GPEN, GWAPT, CISSP, CISM, or equivalent. (Note: Due to the high volume of applications we receive, we are unable to respond to every candidate individually. If you have not received a response from GFT regarding your application within 10 workdays, please consider that we have decided to proceed with other candidates. We truly appreciate your interest in GFT and thank you for your understanding)

03

Quyền lợi

HR benefits Competitive salary Salary band per level are reviewed once per year 13th month salary pro rata depending on the employee’s length of service (within a calender year), paid with the December salary Monthly lunch allowance: 700,000 VND/employee Parking: GFT covers the monthly parking fee for employee motorbikes Performance evaluation is once per year, for 2 purposes: > Performance bonus > Salary increments Health care Private health insurance: including accident, outpatient, in-patient, maternity, and dental for all permanent employees who pass 2-month probation. Optical: expense claim for eyewear Annual health check-ups. Vacation Maximum 18-day vacation leave/year (with the ability to carry over 05 days till 31st March of the following year) Adding one more annual leave day for each two-year anniversary. Healthy lifestyle Sports and hobby clubs: company has an annual fund for fitness activities, which is allocated per month as team’s vote. Range of healthy snacks, tea, coffee, milk and beer on tap Social Company townhall: each 6 weeks CSR activities: as per company’s CSR guideline Onsite tour/training courses at other GFT offices and client’s destination overseas (where applicable).

↳

Kỹ năng bắt buộc

Penetration testingEthical hackingVulnerability assessmentsWeb securityMobile securityAPI securityNetwork securityCloud securityOWASP Top 10Burp SuiteOWASP ZAPNmapNessusMetasploitWiresharkPostmanMobSFEnglish
↳

Kỹ năng ưu tiên

PCI DSSISO 27001SOC 2SWIFT CSCFSecure code reviewsSASTDASTSCAKubernetesDockerInfrastructure-as-CodeRed teamingPythonBashPowerShellCEHeJPTPNPTOSCPGPENGWAPTCISSPCISM
Tiếng AnhBắt buộcOWASP Top 10Bắt buộcPostmanBắt buộcBashƯu tiênDockerƯu tiênISO 27001Ưu tiênKubernetesƯu tiênPowerShellƯu tiênPythonƯu tiên
↳

Kỹ năng từ nguồn

Penetration TestingEnglishPentest
BƯỚC TIẾP THEO

Cơ hội này
dành cho bạn?

Xem thông tin đầy đủ và ứng tuyển trực tiếp tại ITviec.

Xem tin gốc / Ứng tuyển
JobLake ghi nhận lần đầu
07/10/2026
Lần gần nhất thấy trên nguồn
07/10/2026

JobLake không nhận hồ sơ. Thông tin và tình trạng tuyển dụng do website nguồn cung cấp.

KẾT NỐI VỚI MÌNH

Bùi Nguyên Phong

Góp ý cho JobLake hoặc trao đổi công việc, đừng ngại liên hệ mình.

Portfolio GitHub LinkedIn
buinguyenphong2003.work@gmail.com
MỘT CHÚT ĐỘNG LỰC

Ủng hộ JobLake

Nếu JobLake giúp bạn tìm được cơ hội mới, bạn có thể gửi một chút ủng hộ để mình tiếp tục chăm chút dự án.

Bùi Nguyên Phong MB

Cảm ơn bạn đã đồng hành.

Ủng hộ JobLake

Mã VietQR MB — Bùi Nguyên Phong Tải ảnh QR

Ủng hộ hoàn toàn tùy tâm. Cảm ơn bạn!

joblake.

Việc làm từ nhiều nguồn, gom về một nơi.

JobLake tổng hợp thông tin tuyển dụng.
Vui lòng kiểm tra thông tin và ứng tuyển tại website nguồn.

DÀNH CHO BƯỚC TIẾP THEO CỦA BẠN