Penetration Tester

  •  Job Reference: 22369
  •  Posted Date: 12/08/2026
  •  Salary: 30000000 (VND) - 50000000 (VND)
  •  Industry: Technology

PENETRATION TESTER

JOB RESPONSIBILITIES
  • Perform Web Application and API penetration testing based on OWASP Top 10 and industry best practices.
  • Analyze and validate True/False Positive results from SAST, DAST, and SCA security tools.
  • Develop Proof‐of‐Concept (PoC) exploits for identified vulnerabilities, including CVE-level issues.
  • Conduct Mobile Application Security Testing for Android and iOS platforms.
  • Perform manual penetration testing on web-based enterprise systems and prepare detailed security reports.
  • Provide guidance on Secure Coding Practices to development teams.
  • Research new vulnerabilities (including potential 0‐days) and support CVE registration when applicable.
  • Collaborate closely with Backend, DevOps, Cloud, and QA teams to ensure remediation and secure system architectures.
  • Utilize scripting skills (Python, Go, Bash, etc.) to automate testing tasks and improve security workflows.
  • Participate in security architecture reviews and risk assessments.
  • Perform penetration testing and security assessments on Cloud Services (AWS, GCP).
JOB REQUIREMENTS
Require
  • Bachelor’s degree in Computer Science, Information Security, Software Engineering, or related field.
  • Hands-on experience in Application Security or Penetration Testing.
  • Strong understanding of OWASP Top 10 and secure application development principles.
  • Experience working with SAST, DAST, and SCA tools and validating their findings.
  • Ability to develop PoCs and exploit known vulnerabilities (CVE-level experience preferred).
  • Basic knowledge of security technologies such as Firewall, VPN, IPS/IDS, EDR.
  • Understanding of IT infrastructure fundamentals (Network, WAS, DB, OS, etc.).
  • Proficiency in scripting languages such as Python, Go, or Bash.
  • Experience with Mobile Application penetration testing (Android/iOS).
  • Certifications such as OSCP, CEH (strongly preferred).
  • Solid analytical, documentation, and communication skills.
  • English communication skills sufficient for team collaboration.
Preferred
  • Award history or strong performance in major CTF competitions.
  • Experience discovering and registering 0‐day vulnerabilities (CVE assignment).
  • Hands-on experience with Cloud environments such as AWS or GCP.
  • Familiarity with DevSecOps, CI/CD security, or security automation.
  • Experience with threat modeling or security design review.
BENEFITS
  • Attractive salary and bonus will be discussed after going through CV & Interview.
  • Topik allowance.
  • Review capacity annually and adjust salary increases according to work performance.
  • Health care: Premium health insurance, Annual health check-up.
  • Young working environment.
  • Good career development opportunities with interesting and challenging projects.
  • English, Korean, technical, soft skills training courses.
  • Opportunity to learn special courses, new technology and security.
  • Gifts on holidays (April 30th - May 1st, September 2nd, Tet, etc.).
  • Outdoor activities with company support: sports clubs, team building, happy hour parties, birthdays, travel, employee and family events, etc.



 

Your Safety and Data Security Matter to Us

Manpower is committed to a safe, secure, and transparent hiring process. We will never request any form of payment, banking details, or sensitive personal information at any stage of recruitment.

If you receive any suspicious communication claiming to be from Manpower, please report it immediately to: [email protected]


An toàn & Bảo mật Dữ liệu của bạn là ưu tiên của chúng tôi

Manpower cam kết mang đến quy trình tuyển dụng an toàn, minh bạch. Chúng tôi sẽ không bao giờ yêu cầu bất kỳ khoản phí nào, thông tin tài khoản ngân hàng hoặc dữ liệu cá nhân nhạy cảm trong suốt quá trình tuyển dụng.

Nếu bạn nhận được liên hệ đáng ngờ tự xưng là Manpower, vui lòng báo cáo ngay qua email: [email protected]