.png)
Lead Penetration Tester Pentester
Chưa có CV? Tạo CV miễn phí ở đây →
Mô tả công việc
ITviec's client is an AI-centric global digital transformation company. We design advanced data and AI transformation solutions, modernize technology architectures and develop next-generation core systems for industry leaders in Banking, Insurance, Manufacturing and Robotics. Partnering closely with our clients, we push boundaries to unlock their full potential.
As a Lead Penetration Tester, you will be responsible for leading and performing authorized security testing activities across applications, digital platforms, APIs, infrastructure, cloud environments, and related systems. This role is designed as a hands-on technical leadership position, with approximately 70% focus on penetration testing execution and 30% focus on leading, guiding, reviewing, and coordinating security testing activities.
The role focuses on identifying security vulnerabilities, validating risks, supporting remediation, and ensuring that systems meet security, regulatory, and industry requirements. You will be expected to act as a senior technical expert, providing direction on testing approach, reviewing findings, mentoring team members, and ensuring high-quality penetration testing deliverables.
You will work closely with security teams, application teams, infrastructure teams, DevOps, architects, business stakeholders, and compliance teams to plan and perform penetration testing across web, mobile, API, cloud, and network environments. The role requires strong hands-on technical security skills, practical experience in ethical hacking, and the ability to communicate security risks clearly to both technical and non-technical stakeholders.
This role requires the candidate to work onsite at the client’s office based on project needs and client requirements. The onsite frequency, working schedule, location, and duration will be aligned with the client’s expectations and may vary depending on the project phase, testing activities, stakeholder meetings, security assessment timeline, and remediation support needs.
Key Activities
Hands-on Penetration Testing
- Perform authorized penetration testing for web applications, mobile applications, APIs, infrastructure, cloud environments, and digital platforms.
- Identify, validate, exploit where appropriate, and document security vulnerabilities, including authentication, authorization, session management, input validation, encryption, access control, and business logic issues.
- Conduct security assessments based on industry standards such as OWASP Top 10, OWASP API Security Top 10, OWASP Mobile Security Testing Guide, and relevant security practices.
- Analyze application flows, user journeys, transaction processes, access controls, and data handling mechanisms to identify potential security risks.
- Perform vulnerability assessment and manual verification to reduce false positives and confirm actual exploitability in authorized environments.
- Conduct retesting activities to validate remediation effectiveness and ensure vulnerabilities are properly resolved.
- Support security testing activities within the SDLC, including security requirement review, threat analysis, test planning, and release security validation.
- Stay updated with emerging cyber threats, attack techniques, security risks, and security testing best practices.
Technical Leadership & Delivery Support
- Lead the planning, scoping, and execution of penetration testing activities across assigned projects or workstreams.
- Define penetration testing approach, test strategy, testing scope, priorities, timelines, and required evidence based on project and client requirements.
- Guide and mentor penetration testers or security engineers in testing methodology, vulnerability validation, reporting quality, and remediation discussions.
- Review vulnerability findings, risk ratings, evidence, and remediation recommendations to ensure accuracy, consistency, and practical value.
- Act as the main technical point of contact for penetration testing activities, working with client stakeholders, security teams, development teams, DevOps, infrastructure teams, and compliance teams.
- Facilitate vulnerability walkthroughs, risk clarification sessions, remediation discussions, and retesting alignment with relevant stakeholders.
- Support estimation, planning, status tracking, issue escalation, and delivery reporting for security testing activities.
- Contribute to improving security testing processes, reporting templates, testing checklists, knowledge sharing, and reusable testing practices.
- Support regulatory, audit, and compliance requirements by providing security testing evidence, reports, remediation status, and technical clarification when needed.
Required Skills
- Strong hands-on experience in penetration testing, vulnerability assessment, ethical hacking, and security testing across application, API, mobile, network, and cloud environments.
- Proven experience leading or coordinating penetration testing activities, including test planning, execution tracking, finding review, stakeholder communication, and retesting coordination.
- Strong knowledge of web and API security vulnerabilities, including OWASP Top 10, API authentication, authorization, token handling, insecure direct object references, injection, broken access control, and business logic flaws.
- Experience testing iOS and Android applications, including mobile application security controls, local storage, certificate pinning, authentication, s
Nhà tuyển dụng
ITviec Recruitment Consulting · 📍 Hồ Chí Minh, Hà Nội
Việc khác tại ITviec Recruitment Consulting
- I
Senior C++ Developer C++11, Algorithms, Linuxhôm qua · Còn 34 ngày - I
Project Leader/ Project Manager Japanese N2+1 tháng trước · Còn 1 ngày - I
Lead Java Engineer1 tháng trước - I
Technical Scrum Master1 tháng trước - I
Senior Fullstack Developer AI/GenAI/AI AGENT/LLM/RAG7 ngày trước · Còn 27 ngày - I
Solution Architect Banking/Fintechhôm qua · Còn 34 ngày