Application Security & Penetration Testing Engineer
AI Summary
The Application Security & Penetration Testing Engineer performs penetration testing, application security assessments, source code reviews, and security protocol reviews to safeguard Safetrust’s products and SDLC.
About this role
About the role:
The Application Security & Penetration Testing Engineer is responsible for penetration testing, application security, source code review, and security protocol review across Safetrust's products. This position plays a key role in the security function, simulating attacks, reviewing code, and testing web and mobile apps against OWASP standards.
This role focuses on offensive and defensive application security work, and contributes to Safetrust's continued growth by ensuring our security protocols are built on strong key practices and sound design.
Key Responsibilities:
Penetration Testing
- Execute in-depth pentests on networks, web applications, mobile apps, and cloud environments.
- Use tools like Metasploit, Burp Suite, Nmap, and custom scripts to simulate sophisticated attacks.
Application & Web Security Testing
- Test web and mobile applications against OWASP Top 10 and OWASP ASVS.
- Conduct dynamic (DAST) and static (SAST) testing using tools like OWASP ZAP, SonarQube, or Checkmarx.
- Verify secure implementation of authentication, session management, and data validation.
Source Code Review
- Perform manual and automated code reviews to detect security issues (SQL injection, XSS, insecure dependencies).
- Partner with developers to implement secure coding standards and resolve findings.
Security Protocol Review
- Evaluate and enhance security protocols using strong key practices (least privilege, defense-in-depth, secure key management).
- Review the design of security architectures: firewalls, encryption schemes, and authentication systems.
- Identify design flaws or misconfigurations and recommend improvements aligned with NIST, ISO 27001, and MITRE ATT&CK.
Reporting & Collaboration
- Deliver comprehensive reports on pentest results, protocol reviews, and app security findings with actionable recommendations.
- Work with development, DevOps, and IT teams to embed security into the SDLC.
- Monitor emerging threats, vulnerabilities, and OWASP updates.
Skills & Experience:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent experience).
- 3+ years in penetration testing, red teaming, or application security roles (Senior: 5+).
- Demonstrated experience reviewing security protocol designs and conducting source code audits.
- Mastery of pentest tools: Metasploit, Burp Suite, Kali Linux.
- Proficiency with AppSec tools: OWASP ZAP, Postman, Checkmarx, or similar.
- Strong knowledge of programming languages (Python, Java, JavaScript) for code review and automation.
- Expertise in OWASP Top 10, OWASP ASVS, and security design principles (zero trust, defense-in-depth).
- Experience with cloud platforms (AWS, Azure) and modern web frameworks.
Nice to Have / Preferred
- Certifications: OSCP, OSCE, CRTP, GWAPT, CEH, or equivalent.
- Experience with red-team operations, APT simulations, or social engineering exercises.
- Exposure to IoT, embedded, or access-control product security.
- Experience developing proof-of-concept exploits for systems, code, or protocols.
Success Profile:
The ideal candidate is:
- An analytical thinker with a focus on secure design and vulnerability discovery.
- Able to articulate technical findings clearly to developers, architects, and leadership.
- Collaborative, with a proactive, adversarial perspective.
- Comfortable owning security assessments end-to-end, from testing to remediation follow-up.
- Comfortable working across regions and functions in a global environment (Vietnam, US, Australia).
Why you'll love working here
- Competitive salary based on experience and performance
- 13th-month salary
- Daily lunch is provided at the office
- Free coffee, tea, and refreshments
- Full statutory insurance (social, health, unemployment)
- Annual health check-up and paid annual leaves
- Professional, international working environment
Working Location:
Level 6 Khanh Hoi 2 Building 360A Ben Van Don, Vinh Hoi, Ho Chi Minh City
Safetrust is an equal opportunity employer and prohibits discrimination and harassment of any kind. We offer an inclusive workplace and will not tolerate discrimination against any job candidate or employee due to age, race, religion, color, ethnicity, national origin, gender, gender identity/expression, sexual orientation, membership in an employee organization, medical condition, family history, genetic information, veteran status, marital status or parental status.
Skills
Explore related jobs
More jobs at Safetrust
Senior Support Specialist (L2 Support Personnel)HO Chi Minh City, Hcmc
Lead Embedded Linux EngineerHO Chi Minh City, Hcmc
AI Computer Vision EngineerHO Chi Minh City, Hcmc
Lead Quality Engineer - Test Strategy & DesignHO Chi Minh City, Hcmc
Lead QA Automation EngineerHO Chi Minh City, Hcmc
Mobile QA EngineerHO Chi Minh City, Hcmc
Similar AWS jobs
Jobs in Ho Chi Minh City
Associate Data Operations AnalystConfluence Technologies · Ho Chi Minh City
Chuyên viên nhân sự (Xây dựng quy trình)Ant-Tech · Ho Chi Minh City, Vietnam- Native Vietnamese Speakers for AI TrainingLifted, an Upwork Company™ · Ho Chi Minh City, Ho Chi Minh
QUẢN LÝ PHÁP CHẾ CẤP CAOAnt-Tech · Ho Chi Minh City, Vietnam- [Vietnam] ETC Field Force Representative - Nhân Viên Xúc Tiến Thương Mại Kênh Bệnh Viện (HCM)Santen · Ho Chi Minh City, Ho Chi Minh
- [IT Delivery Center] Senior Information Security AnalystEurofins · Ho Chi Minh City, Ho Chi Minh
Browse these categories
Market data for this role
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.