Cyber Security Engineer AppSec/PenTest
Hạn nộp hồ sơ: 04/09/2026 (Còn 5 ngày)
Sắp hết thời gian ứng tuyển, chớp cơ hội ngay!
Kết nối với Nhà tuyển dụng để tìm hiểu thông tin và gia tăng cơ hội trúng tuyển
Nhà tuyển dụng đang online
Mô tả công việc
Tóm tắt công việc
Scandinavian Software Park is the Hanoi-based tech hub and home to several of Scandinavia's market-leading B2B SaaS companies. Founded and operated by Monterro, the leading B2B software investor in the Nordics, Scandinavian Software Park enables portfolio companies to accelerate growth and build high-end engineering and product capabilities in Vietnam. This role sits within our product services, aiming to delivering expert-level services directly to Monterro's portfolio of 30+ B2B software companies.
This is a senior individual contributor role for a seasoned security professional who brings deep offensive and defensive expertise and can operate independently across multiple complex engagements. As a Cyber Security Specialist, you will be a key technical authority, leading continuous vulnerability intelligence operations, conducting advanced penetration tests and code security reviews, and advising on the security of AI-powered features across Monterro's portfolio of Nordic B2B SaaS products. You are also expected to bring the judgment and seniority to triage ambiguous findings, lead threat modeling sessions, support incident response and raise the security maturity of the products you work with.
What you'll do
Penetration Testing
Map the environment of each portfolio company, including LLMs, prompts, RAG pipelines, agentic workflows, APIs and connected systems, to define a precise attack surface before testing begins.
Plan and execute full-scope penetration tests against web applications, APIs, and internal systems for portfolio companies, from scoping and reconnaissance through to exploitation and reporting.
Stress-test system behavior under real-world adversarial conditions, evaluating how models and agents respond to manipulation, privilege abuse, and unexpected inputs.
Red Teaming
Conduct threat intelligence-led OSINT reconnaissance to map each portfolio company's digital footprint, identify exposed assets, and define realistic attack scenarios grounded in how real adversaries operate.
Execute multi-vector attack simulations combining external and internal network exploitation, social engineering, phishing, and lateral movement to reveal how far an attacker could realistically penetrate.
Run both Full Simulation engagements (end-to-end attack chain from initial access to exfiltration) and Assumed Compromise scenarios (focused on lateral movement and detection/response after access).
Validate detection and response capabilities: evaluate whether security controls, monitoring, and incident response processes would catch and contain a real attack.
Code-Based Security Review
Lead in-depth security reviews of application codebases, identifying logic flaws, injection vulnerabilities, broken authentication, insecure data handling and supply-chain risks.
Apply AI-assisted static analysis alongside manual review techniques to achieve deeper coverage across multiple languages and frameworks.
Delivery findings with severity ratings, exploitability assessments and precise remediation guidance; present results directly to engineering leads and CTOs.
Threat Modeling
Lead threat modeling sessions (STRIDE, PASTA, or equivalent) with portfolio company product and engineering teams during design and architecture phases, not just after the fact.
Translate threat models into actionable security requirements, test cases, and backlog items that engineering teams can act on.
Build and maintain threat profiles for portfolio companies, updating them as products evolve and new attack surfaces emerge.
System Security
Assess the security of AI-powered product features - covering prompt injections, indirect prompt injection, model data leakage, insecure LLM integrations and adversarial input scenarios.
Stay current on the evolving AI threat landscape (OWASP LLM Top 10, emerging jailbreak patterns, supply-chain risks in AI frameworks) and translate findings into practical guidance.
What will you get?
Join our innovative and market-leading Scandinavian SaaS company and accelerate your growth alongside experienced software engineers from around the world. We value creativity, innovation, and work-life balance in our Scandinavian work culture, and offer a competitive salary with 100% official salary during the probation period, annual reviews, and 13th month salary.
We prioritize the well-being of our employees with premium healthcare and accident insurance, as well as a wellness package to help you stay healthy and wealthy. You'll also have the chance to participate in exciting company outings, team-building activities, and on-site training opportunities in the Nordic region.
Work in a modern and supportive environment where your individuality is valued, and collaborate with a talented team on a mission to become global players in the industry.
Scandinavian Software Park is the Hanoi-based tech hub and home to several of Scandinavia's market-leading B2B SaaS companies. Founded and operated by Monterro, the leading B2B software investor in the Nordics, Scandinavian Software Park enables portfolio companies to accelerate growth and build high-end engineering and product capabilities in Vietnam. This role sits within our product services, aiming to delivering expert-level services directly to Monterro's portfolio of 30+ B2B software companies.
This is a senior individual contributor role for a seasoned security professional who brings deep offensive and defensive expertise and can operate independently across multiple complex engagements. As a Cyber Security Specialist, you will be a key technical authority, leading continuous vulnerability intelligence operations, conducting advanced penetration tests and code security reviews, and advising on the security of AI-powered features across Monterro's portfolio of Nordic B2B SaaS products. You are also expected to bring the judgment and seniority to triage ambiguous findings, lead threat modeling sessions, support incident response and raise the security maturity of the products you work with.
What you'll do
Penetration Testing
Map the environment of each portfolio company, including LLMs, prompts, RAG pipelines, agentic workflows, APIs and connected systems, to define a precise attack surface before testing begins.
Plan and execute full-scope penetration tests against web applications, APIs, and internal systems for portfolio companies, from scoping and reconnaissance through to exploitation and reporting.
Stress-test system behavior under real-world adversarial conditions, evaluating how models and agents respond to manipulation, privilege abuse, and unexpected inputs.
Red Teaming
Conduct threat intelligence-led OSINT reconnaissance to map each portfolio company's digital footprint, identify exposed assets, and define realistic attack scenarios grounded in how real adversaries operate.
Execute multi-vector attack simulations combining external and internal network exploitation, social engineering, phishing, and lateral movement to reveal how far an attacker could realistically penetrate.
Run both Full Simulation engagements (end-to-end attack chain from initial access to exfiltration) and Assumed Compromise scenarios (focused on lateral movement and detection/response after access).
Validate detection and response capabilities: evaluate whether security controls, monitoring, and incident response processes would catch and contain a real attack.
Code-Based Security Review
Lead in-depth security reviews of application codebases, identifying logic flaws, injection vulnerabilities, broken authentication, insecure data handling and supply-chain risks.
Apply AI-assisted static analysis alongside manual review techniques to achieve deeper coverage across multiple languages and frameworks.
Delivery findings with severity ratings, exploitability assessments and precise remediation guidance; present results directly to engineering leads and CTOs.
Threat Modeling
Lead threat modeling sessions (STRIDE, PASTA, or equivalent) with portfolio company product and engineering teams during design and architecture phases, not just after the fact.
Translate threat models into actionable security requirements, test cases, and backlog items that engineering teams can act on.
Build and maintain threat profiles for portfolio companies, updating them as products evolve and new attack surfaces emerge.
System Security
Assess the security of AI-powered product features - covering prompt injections, indirect prompt injection, model data leakage, insecure LLM integrations and adversarial input scenarios.
Stay current on the evolving AI threat landscape (OWASP LLM Top 10, emerging jailbreak patterns, supply-chain risks in AI frameworks) and translate findings into practical guidance.
What will you get?
Join our innovative and market-leading Scandinavian SaaS company and accelerate your growth alongside experienced software engineers from around the world. We value creativity, innovation, and work-life balance in our Scandinavian work culture, and offer a competitive salary with 100% official salary during the probation period, annual reviews, and 13th month salary.
We prioritize the well-being of our employees with premium healthcare and accident insurance, as well as a wellness package to help you stay healthy and wealthy. You'll also have the chance to participate in exciting company outings, team-building activities, and on-site training opportunities in the Nordic region.
Work in a modern and supportive environment where your individuality is valued, and collaborate with a talented team on a mission to become global players in the industry.
Yêu cầu
What we are looking for
Requirements:
5+ years of hands-on experience in application security, penetration testing or vulnerability management.
Solid experience conducting vulnerability assessments and penetration tests on web applications and APIs with the ability to deliver professional reports independently.
Strong understanding of OWASP Top 10 and OWASP LLM Top 10, web and API vulnerability classes, authentication and authorization flaws and business logic abuse.
Experience with red teaming that covers traditional adversarial operations (threat intelligence-led attack planning, OSINT reconnaissance, multi-vector simulations and detection/response validation) and AI-specific targets (LLM jailbreaks, prompt injection, and adversarial testing of generative AI features in production).
Experience leading threat modeling sessions (STRIDE, PASTA, or equivalent) with engineering and product teams.
Familiarity with AI/LLM security risks: prompt injection, model data leakage, insecure LLM integrations and adversarial scenarios.
Strong code review skills across multiple languages (e.g., Python, JavaScript/TypeScript, Java, Go, C#) - able to identify vulnerabilities in unfamiliar codebases independently.
Experience with AI-assisted or automated security tooling (e.g., Semgrep, Snyk, GitHub Advanced Security...) and the judgment to critically evaluate their output.
Cloud penetration testing experience (AWS, Azure, GCP) and container/Kubernetes security.
Understanding of B2B SaaS security patterns: multi-tenancy, OAuth/OIDC, API authentication and cloud-native privilege models.
Strong English communication skills, both written and spoken.
Nice to have
OSCP, OSWoE, GPEN, GWAPT, or equivalent offensive security certification
Experience with TIBER-EU or ART (Advanced Red Teaming) frameworks.
Knowledge of compliance and risk frameworks relevant to Nordic/European software companies: ISO 27001, SOC 2, GDPR, NIS2.
Prior experience working with B2B SaaS or Nordic/European software companies is a strong plus
Why this role is interesting
You get to work at the actual intersection of AI and offensive security, not just reading about it, but testing it against real products in production.
Full access to the best AI-assisted security tooling, no personal budget worries, no approval process, no waiting.
You'll work across 30+ different tech stacks and companies, not just one.
You'll see inside many different B2B software businesses through security reviews and threat modeling.
Scandinavian work culture: trust, autonomy and a sensible view on work-life balance.
Modern office at Peakview Tower in central Hanoi
Competitive salary for the Hanoi market
Requirements:
5+ years of hands-on experience in application security, penetration testing or vulnerability management.
Solid experience conducting vulnerability assessments and penetration tests on web applications and APIs with the ability to deliver professional reports independently.
Strong understanding of OWASP Top 10 and OWASP LLM Top 10, web and API vulnerability classes, authentication and authorization flaws and business logic abuse.
Experience with red teaming that covers traditional adversarial operations (threat intelligence-led attack planning, OSINT reconnaissance, multi-vector simulations and detection/response validation) and AI-specific targets (LLM jailbreaks, prompt injection, and adversarial testing of generative AI features in production).
Experience leading threat modeling sessions (STRIDE, PASTA, or equivalent) with engineering and product teams.
Familiarity with AI/LLM security risks: prompt injection, model data leakage, insecure LLM integrations and adversarial scenarios.
Strong code review skills across multiple languages (e.g., Python, JavaScript/TypeScript, Java, Go, C#) - able to identify vulnerabilities in unfamiliar codebases independently.
Experience with AI-assisted or automated security tooling (e.g., Semgrep, Snyk, GitHub Advanced Security...) and the judgment to critically evaluate their output.
Cloud penetration testing experience (AWS, Azure, GCP) and container/Kubernetes security.
Understanding of B2B SaaS security patterns: multi-tenancy, OAuth/OIDC, API authentication and cloud-native privilege models.
Strong English communication skills, both written and spoken.
Nice to have
OSCP, OSWoE, GPEN, GWAPT, or equivalent offensive security certification
Experience with TIBER-EU or ART (Advanced Red Teaming) frameworks.
Knowledge of compliance and risk frameworks relevant to Nordic/European software companies: ISO 27001, SOC 2, GDPR, NIS2.
Prior experience working with B2B SaaS or Nordic/European software companies is a strong plus
Why this role is interesting
You get to work at the actual intersection of AI and offensive security, not just reading about it, but testing it against real products in production.
Full access to the best AI-assisted security tooling, no personal budget worries, no approval process, no waiting.
You'll work across 30+ different tech stacks and companies, not just one.
You'll see inside many different B2B software businesses through security reviews and threat modeling.
Scandinavian work culture: trust, autonomy and a sensible view on work-life balance.
Modern office at Peakview Tower in central Hanoi
Competitive salary for the Hanoi market
Thông tin khác
Cyber Security
Penetration testing
OWASP
Java
JavaScript
C#
Python
OAUTH
API
Github
TypeScript
SaaS
MS Azure
Golang
AWS
Kubernetes
ISO
SoC
GCP
OSCP
Snyk
Stride
GWAPT
GPEN
OIDC
LLM
NIS2
Penetration testing
OWASP
Java
JavaScript
C#
Python
OAUTH
API
Github
TypeScript
SaaS
MS Azure
Golang
AWS
Kubernetes
ISO
SoC
GCP
OSCP
Snyk
Stride
GWAPT
GPEN
OIDC
LLM
NIS2
Thông tin chung
- Thu nhập: Thỏa Thuận
Nơi làm việc
- Tầng 19, tòa nhà Peakview Tower, 36 Hoàng Cầu, Ô Chợ Dừa, Hà Nội, Dong Da, Ha Noi
Việc làm tương tự khác
TỔNG CÔNG TY DỊCH VỤ VIỄN THÔNG (VNPT VINAPHONE)
Hà Nội
Thu nhập từ 450 đến 600 tr
CÔNG TY CỔ PHẦN DI CHUYỂN XANH VÀ THÔNG MINH GSM
Hà Nội
$ 1,500-2,500 /tháng
Ngân hàng Thương mại TNHH MTV Kỷ Nguyên Thịnh Vượng (GPBank)
Hà Nội
55tr-58tr ₫/tháng
Scandinavian Software Park
Xem trang công ty- Địa chỉ công ty: Peakview Tower, 36 Hoang Cau, Hà Nội
- Quy mô: Từ 26 - 100 nhân viên
Thông tin công việc
Vị trí:
Nhân viên
Hình thức làm việc:
Toàn thời gian
Việc làm tương tự
Cảnh báo dấu hiệu lừa đảo tuyển dụng
Đội ngũ hỗ trợ của JobOKO sẵn sàng đồng hành, tư vấn và giới thiệu những cơ hội việc làm phù hợp, giúp Ứng viên tự tin phát triển sự nghiệp và chinh phục mục tiêu nghề nghiệp bền vững.
Hotline CSKH
1900.63.63.84
Công ty Cổ phần JobOKO Toàn cầu
Đội ngũ hỗ trợ của JobOKO luôn chủ động tư vấn các giải pháp tuyển dụng tối ưu, cam kết đồng hành và hỗ trợ Quý Nhà tuyển dụng đạt được hiệu quả tuyển dụng bền vững.
Hotline CSKH
0962.107.888
Công ty Cổ phần JobOKO Toàn cầu