Application Security & Penetration Testing Engineer
Job description
About the role
As an , you will play a pivotal role in safeguarding our digital assets and ensuring the security of our applications. Your expertise in identifying vulnerabilities and implementing robust security measures will be essential in protecting our systems from potential threats. This position not only requires technical proficiency but also a proactive mindset to stay ahead of emerging security challenges. You will collaborate with cross-functional teams to enhance our security posture and contribute to the overall success of our organization.
Key facts
What you'll do
- Conduct thorough penetration testing on web applications, APIs, and mobile applications to identify security vulnerabilities and weaknesses.
- Develop and execute comprehensive security assessment plans, including threat modeling and risk analysis, to evaluate the security of our applications.
- Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC), ensuring that security is a priority from the outset.
- Create detailed reports outlining findings from security assessments, including actionable recommendations for remediation and risk mitigation.
- Stay updated on the latest security threats, vulnerabilities, and industry trends to continuously enhance the security framework of the organization.
- Participate in the design and implementation of security tools and technologies to automate security testing and improve efficiency.
- Conduct security training and awareness programs for developers and other stakeholders to foster a culture of security within the organization.
- Work closely with incident response teams to investigate security incidents and provide expertise in root cause analysis and remediation strategies.
Requirements
- A minimum of 3 years of experience in application security, penetration testing, or a related field.
- Strong understanding of web application architecture, security protocols, and common vulnerabilities (e.g., OWASP Top Ten).
- Proficiency in using penetration testing tools such as Burp Suite, OWASP ZAP, Metasploit, or similar.
- Familiarity with programming languages such as Python, Java, or JavaScript, and the ability to write custom scripts for testing purposes.
- Experience with security frameworks and standards such as NIST, ISO 27001, or PCI DSS.
- Excellent analytical and problem-solving skills, with a keen eye for detail and the ability to think like an attacker.
Nice to have
- Relevant certifications such as Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), or Certified Information Systems Security Professional (CISSP).
- Experience with cloud security and securing applications hosted on platforms like AWS, Azure, or Google Cloud.
- Knowledge of DevSecOps practices and tools to integrate security into CI/CD pipelines.
- Familiarity with mobile application security testing and tools specific to mobile platforms.
Skills & tools
- Proficient in penetration testing methodologies and frameworks, including but not limited to OWASP, NIST, and SANS.
- Hands-on experience with security assessment tools and technologies, including static and dynamic analysis tools.
- Strong communication skills to effectively convey technical findings to non-technical stakeholders.
- Ability to work independently and manage multiple projects simultaneously in a fast-paced environment.
Practical notes
- This position is based in Ho Chi Minh City, HCMC, and may require occasional travel for on-site assessments or training sessions.
- The salary for this role is competitive and will be determined based on your experience and qualifications.
- Visa sponsorship is available for qualified candidates who require work authorization to join our team.
- Candidates should be prepared to undergo a background check as part of the hiring process.
META
Company: Safetrust
Title: Application Security & Penetration Testing Engineer
Listed
location: Ho Chi Minh City, HCMC
Job type: Full-time
Apply URL: https://safetrust.bamboohr.com/careers/76
Tags: Security, Penetration Testing, Engineering, Testing
At Safetrust, we are committed to creating a secure environment for our customers and employees. If you are passionate about application security and eager to make a significant impact, we encourage you to apply for this exciting opportunity. Join us in our mission to protect digital assets and innovate in the field of security.