Pentest Intern (Part-time)
Company Description
THD Cybersecurity Joint Stock Company (THD - Tran Hung Dao) is a Vietnam-based cybersecurity company dedicated to protecting the information systems and digital assets of enterprises and organizations.
Inspired by the strategic thinking and resilience of General Tran Hung Dao, THD delivers practical cybersecurity solutions aligned with international standards and tailored to the Vietnamese market. Our services include SOC-as-a-Service, vulnerability assessment and penetration testing, data protection, ISO/NIST compliance consulting, and secure digital transformation.
We are committed to helping organizations remain secure, resilient, and confident throughout their digital growth.
Role Description
We are looking for a part-time, on-site Pentest Intern based in Ho Chi Minh City. In this role, you will work under the guidance of experienced security engineers and gain hands-on experience in assessing the security of web applications, APIs, networks, servers, and other information systems.
You will participate in different stages of penetration testing engagements, from test preparation and vulnerability identification to evidence collection and technical reporting. This position is suitable for students or recent graduates who want to develop practical skills and pursue a career in offensive security.
Key Responsibilities
Assist in planning and executing penetration testing activities under the supervision of senior security engineers.
Perform security testing on web applications, APIs, networks, servers, and other systems within authorized scopes.
Use penetration testing and vulnerability assessment tools such as Nmap, Burp Suite, Metasploit, and vulnerability scanners.
Identify, analyze, validate, and document potential security vulnerabilities.
Collect technical evidence and develop clear proof-of-concept demonstrations.
Assist in preparing vulnerability descriptions, risk assessments, remediation recommendations, and security assessment reports.
Research emerging vulnerabilities, attack techniques, security tools, and industry best practices.
Contribute to internal security knowledge bases, testing checklists, scripts, and technical playbooks.
Participate in technical training, knowledge-sharing sessions, and team discussions.
Follow the company's penetration testing methodologies, reporting standards, confidentiality requirements, and professional ethics.
Qualifications
Current student or recent graduate in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field.
Foundational knowledge of computer networks, TCP/IP, operating systems, and common cybersecurity concepts.
Basic understanding of Linux and Windows environments.
Familiarity with common web application vulnerabilities, particularly the OWASP Top 10.
Basic experience with penetration testing tools such as Nmap, Burp Suite, Metasploit, or vulnerability scanners.
Ability to read and understand technical documentation, vulnerability advisories, and security guidelines.
Strong analytical and problem-solving skills with attention to detail.
Ability to document technical findings clearly and accurately.
Good written and verbal communication skills.
Willingness to learn, receive feedback, and collaborate effectively with team members.
Strong interest in offensive security, ethical hacking, and penetration testing.
Ability to work on-site in Ho Chi Minh City according to a part-time schedule agreed with the company.
Preferred Qualifications
Experience with personal labs, Capture the Flag competitions, cybersecurity clubs, or security research projects.
Basic knowledge of web technologies, APIs, databases, Active Directory, or mobile application security.
Familiarity with scripting or programming languages such as Python, Bash, PowerShell, JavaScript, or PHP.
Familiarity with penetration testing methodologies and standards such as OWASP WSTG, OWASP ASVS, PTES, NIST, or ISO/IEC 27001.
Relevant cybersecurity certifications or completed training courses are an advantage but not required.
What You Will Gain
Hands-on experience with real-world security assessment activities.
Practical knowledge of professional penetration testing workflows and methodologies.
Guidance and mentorship from experienced cybersecurity professionals.
Opportunities to improve technical testing, vulnerability analysis, and security reporting skills.
Exposure to security projects across different industries and technology environments.
Potential opportunities for long-term employment based on performance and business needs.
Thông tin chung