Tìm kiếm theo:
Có phải bạn đang tìm
Từ khóa phổ biến
Việc làm nổi bật

Cyber Security Engineer AppSec/PenTest

Scandinavian Software Park

Địa điểm làm việc: Hà Nội
Hết hạn: 04/09/2026
Thu nhập: You'll love it
Loại hình: Toàn thời gian
Chức vụ: Nhân viên
Kinh nghiệm: 5 năm

Mô tả công việc

Top 3 Reasons To Join Us
Global growth with experienced engineers
Innovative, balanced, creative culture
Competitive salary, benefits, training
The Job

Scandinavian Software Park is the Hanoi-based tech hub and home to several of Scandinavia's market-leading B2B SaaS companies. Founded and operated by Monterro, the leading B2B software investor in the Nordics, Scandinavian Software Park enables portfolio companies to accelerate growth and build high-end engineering and product capabilities in Vietnam. This role sits within our product services, aiming to delivering expert-level services directly to Monterro's portfolio of 30+ B2B software companies.

This is a senior individual contributor role for a seasoned security professional who brings deep offensive and defensive expertise and can operate independently across multiple complex engagements. As a Cyber Security Specialist, you will be a key technical authority, leading continuous vulnerability intelligence operations, conducting advanced penetration tests and code security reviews, and advising on the security of AI-powered features across Monterro's portfolio of Nordic B2B SaaS products. You are also expected to bring the judgment and seniority to triage ambiguous findings, lead threat modeling sessions, support incident response and raise the security maturity of the products you work with.

What you'll do

Penetration Testing

  • Map the environment of each portfolio company, including LLMs, prompts, RAG pipelines, agentic workflows, APIs and connected systems, to define a precise attack surface before testing begins.
  • Plan and execute full-scope penetration tests against web applications, APIs, and internal systems for portfolio companies, from scoping and reconnaissance through to exploitation and reporting.
  • Stress-test system behavior under real-world adversarial conditions, evaluating how models and agents respond to manipulation, privilege abuse, and unexpected inputs.

Red Teaming

  • Conduct threat intelligence-led OSINT reconnaissance to map each portfolio company's digital footprint, identify exposed assets, and define realistic attack scenarios grounded in how real adversaries operate.
  • Execute multi-vector attack simulations combining external and internal network exploitation, social engineering, phishing, and lateral movement to reveal how far an attacker could realistically penetrate.
  • Run both Full Simulation engagements (end-to-end attack chain from initial access to exfiltration) and Assumed Compromise scenarios (focused on lateral movement and detection/response after access).
  • Validate detection and response capabilities: evaluate whether security controls, monitoring, and incident response processes would catch and contain a real attack.

Code-Based Security Review

  • Lead in-depth security reviews of application codebases, identifying logic flaws, injection vulnerabilities, broken authentication, insecure data handling and supply-chain risks.
  • Apply AI-assisted static analysis alongside manual review techniques to achieve deeper coverage across multiple languages and frameworks.
  • Delivery findings with severity ratings, exploitability assessments and precise remediation guidance; present results directly to engineering leads and CTOs.

Threat Modeling

  • Lead threat modeling sessions (STRIDE, PASTA, or equivalent) with portfolio company product and engineering teams during design and architecture phases, not just after the fact.
  • Translate threat models into actionable security requirements, test cases, and backlog items that engineering teams can act on.
  • Build and maintain threat profiles for portfolio companies, updating them as products evolve and new attack surfaces emerge.

System Security

  • Assess the security of AI-powered product features - covering prompt injections, indirect prompt injection, model data leakage, insecure LLM integrations and adversarial input scenarios.
  • Stay current on the evolving AI threat landscape (OWASP LLM Top 10, emerging jailbreak patterns, supply-chain risks in AI frameworks) and translate findings into practical guidance.

Your Skills and Experience

What we are looking for

Requirements:

  • 5+ years of hands-on experience in application security, penetration testing or vulnerability management.
  • Solid experience conducting vulnerability assessments and penetration tests on web applications and APIs with the ability to deliver professional reports independently.
  • Strong understanding of OWASP Top 10 and OWASP LLM Top 10, web and API vulnerability classes, authentication and authorization flaws and business logic abuse.
  • Experience with red teaming that covers traditional adversarial operations (threat intelligence-led attack planning, OSINT reconnaissance, multi-vector simulations and detection/response validation) and AI-specific targets (LLM jailbreaks, prompt injection, and adversarial testing of generative AI features in production).
  • Experience leading threat modeling sessions (STRIDE, PASTA, or equivalent) with engineering and product teams.
  • Familiarity with AI/LLM security risks: prompt injection, model data leakage, insecure LLM integrations and adversarial scenarios.
  • Strong code review skills across multiple languages (e.g., Python, JavaScript/TypeScript, Java, Go, C#) - able to identify vulnerabilities in unfamiliar codebases independently.
  • Experience with AI-assisted or automated security tooling (e.g., Semgrep, Snyk, GitHub Advanced Security...) and the judgment to critically evaluate their output.
  • Cloud penetration testing experience (AWS, Azure, GCP) and container/Kubernetes security.
  • Understanding of B2B SaaS security patterns: multi-tenancy, OAuth/OIDC, API authentication and cloud-native privilege models.
  • Strong English communication skills, both written and spoken.

Nice to have

  • OSCP, OSWoE, GPEN, GWAPT, or equivalent offensive security certification
  • Experience with TIBER-EU or ART (Advanced Red Teaming) frameworks.
  • Knowledge of compliance and risk frameworks relevant to Nordic/European software companies: ISO 27001, SOC 2, GDPR, NIS2.
  • Prior experience working with B2B SaaS or Nordic/European software companies is a strong plus

Why this role is interesting

  • You get to work at the actual intersection of AI and offensive security, not just reading about it, but testing it against real products in production.
  • Full access to the best AI-assisted security tooling, no personal budget worries, no approval process, no waiting.
  • You'll work across 30+ different tech stacks and companies, not just one.
  • You'll see inside many different B2B software businesses through security reviews and threat modeling.
  • Scandinavian work culture: trust, autonomy and a sensible view on work-life balance.
  • Modern office at Peakview Tower in central Hanoi
  • Competitive salary for the Hanoi market

Why You'll Love Working Here

What will you get?

Join our innovative and market-leading Scandinavian SaaS company and accelerate your growth alongside experienced software engineers from around the world. We value creativity, innovation, and work-life balance in our Scandinavian work culture, and offer a competitive salary with 100% official salary during the probation period, annual reviews, and 13th month salary.

We prioritize the well-being of our employees with premium healthcare and accident insurance, as well as a wellness package to help you stay healthy and wealthy. You'll also have the chance to participate in exciting company outings, team-building activities, and on-site training opportunities in the Nordic region.

Work in a modern and supportive environment where your individuality is valued, and collaborate with a talented team on a mission to become global players in the industry.

Yêu cầu

Pentest, AI, Cybersecurity, Cloud Security, Application Security

Quyền lợi

What will you get?

Join our innovative and market-leading Scandinavian SaaS company and accelerate your growth alongside experienced software engineers from around the world. We value creativity, innovation, and work-life balance in our Scandinavian work culture, and offer a competitive salary with 100% official salary during the probation period, annual reviews, and 13th month salary.

We prioritize the well-being of our employees with premium healthcare and accident insurance, as well as a wellness package to help you stay healthy and wealthy. You'll also have the chance to participate in exciting company outings, team-building activities, and on-site training opportunities in the Nordic region.

Work in a modern and supportive environment where your individuality is valued, and collaborate with a talented team on a mission to become global players in the industry.

Thông tin chung

  • Thu nhập: You'll love it

Nơi làm việc

  • Tầng 19, tòa nhà Peakview Tower, 36 Hoàng Cầu, Ô Chợ Dừa, Hà Nội, Dong Da, Ha Noi

Cách thức ứng tuyển

Ứng viên nộp hồ sơ trực tuyến bằng cách bấm nút Ứng tuyển bên dưới:
Hạn nộp: 04/09/2026
Giới thiệu công ty Xem trang công ty
Scandinavian Software Park tập hợp các kỹ sư phần mềm tại một số công ty SaaS hàng đầu thị trường của Scandinavia. Các công ty SaaS hàng đầu này đang phát triển các sản phẩm tiên tiến cho nhiều ngành công nghiệp trên khắp thế giới. The Park được thành lập bởi nhà đầu tư tăng trưởng Scandinavia...
Quy mô công ty
Từ 26 - 100 nhân viên

Các thông tin được cung cấp chỉ nhằm mục đích cho người dùng tham khảo, JobOKO không đại diện và không có sự liên quan tới doanh nghiệp scandinavian software park trong các hoạt động tuyển dụng. Các thông tin bản quyền, nhãn hiệu hoặc bất kỳ quyền sở hữu trí tuệ nào liên quan đến nội dung, thương hiệu hay hình ảnh doanh nghiệp này không thuộc sở hữu của JobOKO.

Người dùng cần tự xác minh thông tin trước khi ứng tuyển, giao dịch hoặc đưa ra bất kỳ quyết định nào dựa trên các nội dung này.

Scandinavian Software Park
Địa chỉ công ty: Peakview Tower, 36 Hoang Cau, Hà Nội

Phúc lợi dành cho bạn

  • Thưởng
  • Nghỉ phép
HOT

Job hot

Aeon Fantasy Vietnam Co.,ltd.
10 - 12 Triệu VND + Phụ Cấp
Thanh Hóa
TỔNG CÔNG TY CP BẢO HIỂM NGÂN HÀNG ĐẦU TƯ VÀ PHÁT TRIỂN VIỆT NAM - BIC
Thỏa Thuận
Hà Nội, Hồ Chí Minh, Bà Rịa - Vũng Tàu, Hải Dương, Quảng Ninh
CÔNG TY TNHH MAY MẶC QTF
Từ 20 triệu VND
Hồ Chí Minh
CÔNG TY TNHH MAY MẶC QTF
Từ 40 triệu VND
Hồ Chí Minh
CÔNG TY CỔ PHẦN X-MEDIA
13.000.000 - 18.000.000đ/tháng
Hà Nội

Job liên quan

Công ty Cổ phần Chứng khoán VNDIRECT
thỏa thuận
Hà Nội
Công ty cổ phần công nghệ Savis
Thỏa thuận
Hà Nội
Ngân hàng Thương mại TNHH MTV Kỷ Nguyên Thịnh Vượng (GPBank)
55tr-58tr ₫/tháng
Hà Nội
Công ty Cổ phần Chứng khoán VNDIRECT
thỏa thuận
Hà Nội

Việc làm tương tự

TỔNG CÔNG TY TRUYỀN THÔNG (VNPT - MEDIA)
Thỏa thuận
15/08/2026
Hà Nội
[HN] Tập Đoàn Cung Cấp Dịch Vụ Kế Toán Tài Chính TMF Group
Thương lượng
20/08/2026
Hà Nội
Công ty Cổ phần Chứng khoán VNDIRECT
thỏa thuận
31/08/2026
Hà Nội
Chi nhánh Công Ty Cổ phần Y Học Vĩnh Thiện - Bệnh viện Đại học Phenikaa
25 Tr - 40 Tr VND
27/08/2026
Hà Nội
Praxis Automation Vietnam Representative Office
Thương lượng
22/08/2026
Hà Nội, Hải Phòng
CÔNG TY TNHH DR.JOY VIỆT NAM
Up to 60M
25/08/2026
Hà Nội
Tập đoàn Bưu chính Viễn thông Việt Nam VNPT
Thương lượng
03/09/2026
Hà Nội
LPBank - Ngân Hàng TMCP Lộc Phát Việt Nam (Tên Gọi Cũ Ngân Hàng TMCP Bưu Điện Liên Việt)
Thương lượng
02/09/2026
Hà Nội
CÔNG TY CỔ PHẦN KINH DOANH F88
25 Tr - 35 Tr VND
31/08/2026
Hà Nội
MB Life
Thỏa Thuận
07/09/2026
Hà Nội

Giải thưởng của chúng tôi

Giải đồng

Chương trình Make in Viet-Nam 2023

Top 3

Nền tảng số tiêu biểu của Bộ TT&TT 2022

Top 10

Dự án xuất sắc nhất Viet-Solutions 2020 - Chương trình Chuyển đổi số  Quốc gia của Bộ TT&TT