Safetrust

Application Security & Penetration Testing Engineer

Ho Chi Minh City, HCMCFull TimePosted Jul 21, 2026

About the role:

The Application Security & Penetration Testing Engineer is responsible for penetration testing, application security, source code review, and security protocol review across Safetrust's products. This position plays a key role in the security function, simulating attacks, reviewing code, and testing web and mobile apps against OWASP standards.

This role focuses on offensive and defensive application security work, and contributes to Safetrust's continued growth by ensuring our security protocols are built on strong key practices and sound design.



Key Responsibilities:

Penetration Testing

  • Execute in-depth pentests on networks, web applications, mobile apps, and cloud environments.
  • Use tools like Metasploit, Burp Suite, Nmap, and custom scripts to simulate sophisticated attacks.

Application & Web Security Testing

  • Test web and mobile applications against OWASP Top 10 and OWASP ASVS.
  • Conduct dynamic (DAST) and static (SAST) testing using tools like OWASP ZAP, SonarQube, or Checkmarx.
  • Verify secure implementation of authentication, session management, and data validation.

Source Code Review

  • Perform manual and automated code reviews to detect security issues (SQL injection, XSS, insecure dependencies).
  • Partner with developers to implement secure coding standards and resolve findings.

Security Protocol Review

  • Evaluate and enhance security protocols using strong key practices (least privilege, defense-in-depth, secure key management).
  • Review the design of security architectures: firewalls, encryption schemes, and authentication systems.
  • Identify design flaws or misconfigurations and recommend improvements aligned with NIST, ISO 27001, and MITRE ATT&CK.

Reporting & Collaboration

  • Deliver comprehensive reports on pentest results, protocol reviews, and app security findings with actionable recommendations.
  • Work with development, DevOps, and IT teams to embed security into the SDLC.
  • Monitor emerging threats, vulnerabilities, and OWASP updates.



Skills & Experience:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent experience).
  • 3+ years in penetration testing, red teaming, or application security roles (Senior: 5+).
  • Demonstrated experience reviewing security protocol designs and conducting source code audits.
  • Mastery of pentest tools: Metasploit, Burp Suite, Kali Linux.
  • Proficiency with AppSec tools: OWASP ZAP, Postman, Checkmarx, or similar.
  • Strong knowledge of programming languages (Python, Java, JavaScript) for code review and automation.
  • Expertise in OWASP Top 10, OWASP ASVS, and security design principles (zero trust, defense-in-depth).
  • Experience with cloud platforms (AWS, Azure) and modern web frameworks.

Nice to Have / Preferred

  • Certifications: OSCP, OSCE, CRTP, GWAPT, CEH, or equivalent.
  • Experience with red-team operations, APT simulations, or social engineering exercises.
  • Exposure to IoT, embedded, or access-control product security.
  • Experience developing proof-of-concept exploits for systems, code, or protocols.



Success Profile:

The ideal candidate is:

  • An analytical thinker with a focus on secure design and vulnerability discovery.
  • Able to articulate technical findings clearly to developers, architects, and leadership.
  • Collaborative, with a proactive, adversarial perspective.
  • Comfortable owning security assessments end-to-end, from testing to remediation follow-up.
  • Comfortable working across regions and functions in a global environment (Vietnam, US, Australia).



Why you'll love working here

  • Competitive salary based on experience and performance
  • 13th-month salary 
  • Daily lunch is provided at the office
  • Free coffee, tea, and refreshments
  • Full statutory insurance (social, health, unemployment)
  • Annual health check-up and paid annual leaves
  • Professional, international working environment


Working Location: 

Level 6 Khanh Hoi 2 Building 360A Ben Van Don, Vinh Hoi, Ho Chi Minh City


Safetrust is an equal opportunity employer and prohibits discrimination and harassment of any kind. We offer an inclusive workplace and will not tolerate discrimination against any job candidate or employee due to age, race, religion, color, ethnicity, national origin, gender, gender identity/expression, sexual orientation, membership in an employee organization, medical condition, family history, genetic information, veteran status, marital status or parental status.

Keep exploring

View all software engineering jobs