Senior Associate - Cyber Security (Pentest)
Ngành nghề
- Hình thức và địa điểm làm việc
- Tại văn phòng
- Loại việc
- Toàn thời gian
- Số lượng tuyển
- 1 vị trí
- Đăng vào
- 1 tháng trước
- Hạn chót
- 21/09/2026
Mức lương
Thỏa thuận
Kinh nghiệm
3+ years of proven experience in conducting network/infrastructure, web/API, or mobile application penetration testing
description Về công việc
Trách nhiệm chính
- Lead the team in cybersecurity assessments, covering web and mobile application penetration testing using OWASP Top 10 and CWE Top 25 frameworks.
- Lead network penetration tests and vulnerability assessments to identify issues in access control and segmentation.
- Conduct source code reviews for logical errors, misconfigurations, and vulnerabilities.
- Execute red teaming engagements and cyber-attack simulations.
- Research and analyze cyber threat intelligence.
- Establish network infrastructure for red teaming activities, including C2 servers, SMTP relays, web servers, and proxies.
- Design and launch phishing campaigns for employee awareness.
- Provide pragmatic risk recommendations and deliver management-level and technical reporting.
- Train, coach, and mentor junior penetration testers.
- Manage day-to-day delivery, client communication, and technical quality control.
- Support proposal processing for global and cross-border clients.
- Stay current on security challenges across cloud, IoT, blockchain, and digital trust.
Yêu cầu công việc
- 3+ years of proven experience in penetration testing (network, infrastructure, web, API, or mobile) with independent engagement delivery capability.
- Experience leading and supervising teams in vulnerability assessment projects.
- Deep understanding of infrastructure/web vulnerabilities, OWASP, CVSS, and CWE Top 25.
- Demonstrated experience in working with diverse stakeholders and managing pressure.
- Excellent communication and interpersonal skills.
- Willingness to learn and work collaboratively.
- Hold at least one industry certification: OSCP, OSWA, eWPT, eCPPT, CRTP, PNPT, CREST CRT/CCT, or equivalent.
Yêu cầu ưu tiên
- Experience in red teaming, cyber-attack simulations, and developing hacking scripts/tools.
- Secure development or DevSecOps experience (securing code, code review, vulnerability management).
- Ability to communicate strategic security topics to diverse audiences.
- Experience with bug bounty programs or CVE hunting.
- Cloud certifications: AWS, Azure, GCP.
- Strong preference for advanced security certifications (OSWE, OSEP, OSCE, CRTO, CRTE, eCPTX, eWPTX, SANS).
- Strong preference for professional certifications: CISSP, CCSP, CSSLP, CISM, CRISC, PMP.
Mức lương
- Salary packaging offered to suit your personal and financial circumstances.
Phúc lợi
- Flexible work arrangements to support work/life balance.
- Professional certification sponsorship.
Hình thức làm việc
- Position based in either Hanoi or Ho Chi Minh City.
- Up to 20% travel required.
Thông tin khác
- Join a global Big Four firm with opportunities to collaborate across the PwC network.
- Work in an innovative and transformative business environment.
work_history Việc làm tương tự
KTV QC CƠ KHÍ-Nam-Fresher-Q7
Worklink VietNam
BẢO TRÌ THIẾT BỊ-Nam-Fresher
Worklink VietNam
Tổ trưởng HSE-NAM- tiếng Anh hoặc tiếng Nhật (giao tiếp tốt)
Worklink VietNam
Tổ phó (Nhân viên) QA-N3-Bình Dương
Worklink VietNam
Tìm kiếm phổ biến
Cho ứng viên
Thông tin công ty
- Công ty cổ phần TMI
- MST: 0109904638
- Tầng 21 tòa nhà Viwaseen, 48 Tố Hữu, Trung Văn, Nam Từ Liêm, Hà Nội