Lead Penetration Tester

    Key Activities

    Penetration Testing & Security Assessment

    • Conduct authorized penetration testing across web applications, mobile applications, APIs, networks, infrastructure, cloud environments, and digital platforms.
    • Identify, validate, and where authorized exploit security vulnerabilities across authentication, authorization, session management, input validation, encryption, access control, and business logic.
    • Perform security assessments aligned with OWASP Top 10, OWASP API Security Top 10, OWASP Mobile Security Testing Guide, and other relevant industry standards.
    • Analyze application architecture, user journeys, transaction flows, access controls, and data handling processes to identify security weaknesses.
    • Perform vulnerability assessments and manual validation to confirm exploitability and minimize false positives.
    • Conduct remediation verification and retesting to ensure identified vulnerabilities are effectively resolved.
    • Support security activities throughout the SDLC, including security requirements review, threat analysis, test planning, and pre release security validation.
    • Monitor emerging threats, attack techniques, vulnerabilities, and security testing methodologies.

    Technical Leadership & Delivery

    • Lead the planning, scoping, execution, and delivery of penetration testing engagements.
    • Define testing methodologies, scope, priorities, timelines, test strategies, and evidence requirements based on project and client needs.
    • Provide technical guidance and mentorship to penetration testers and security engineers.
    • Review vulnerability findings, risk ratings, technical evidence, and remediation recommendations for accuracy and consistency.
    • Serve as the primary technical contact for penetration testing activities, coordinating with clients, security teams, developers, DevOps, infrastructure, and compliance teams.
    • Lead vulnerability walkthroughs, risk discussions, remediation reviews, and retesting activities.
    • Support project estimation, resource planning, progress tracking, issue escalation, and delivery reporting.
    • Contribute to improving security testing methodologies, checklists, reporting standards, and reusable testing practices.
    • Provide technical evidence, security reports, remediation updates, and clarification to support audit, regulatory, and compliance requirements.

    Required Skills & Experience

    • Strong hands on experience in penetration testing, ethical hacking, vulnerability assessment, and security testing across applications, APIs, mobile, network, and cloud environments.
    • Proven experience leading or coordinating penetration testing engagements from planning and execution through findings review, stakeholder communication, and retesting.
    • Strong knowledge of web and API security, including OWASP Top 10, authentication, authorization, token management, IDOR, injection, broken access control, and business logic vulnerabilities.
    • Practical experience testing iOS and Android applications, including local storage, certificate pinning, authentication, session management, and secure communications.
    • Experience assessing networks, servers, operating systems, access controls, configurations, and infrastructure vulnerabilities.
    • Understanding of cloud security and security testing across AWS, Azure, or GCP environments.
    • Hands on experience with tools such as Burp Suite, OWASP ZAP, Nmap, Nessus, Metasploit, Wireshark, Postman, MobSF, or equivalent.
    • Ability to validate vulnerabilities, assess exploitability and business impact, and provide practical remediation recommendations.
    • Strong security reporting skills, including vulnerability descriptions, risk ratings, evidence, business impact, and remediation guidance.
    • Ability to communicate technical security findings clearly to both technical and non technical stakeholders.
    • Experience collaborating with engineering teams on root cause analysis, remediation, and vulnerability retesting.
    • Good knowledge of secure coding, encryption, data privacy, identity and access management, and common security frameworks.
    • Understanding of security requirements within regulated and compliance driven environments.
    • Strong analytical and problem solving skills, attention to detail, ownership, and ability to manage multiple engagements simultaneously.
    • Excellent English communication skills, with confidence working directly with international clients and technical stakeholders.

    HOW TO APPLY: Please send your CV to the consultant in charge:

    Ms. Nhu Hoa

    E-mail: nhuhoa.nguyen@ev-search.com

    All applications will be considered without regard to race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, parental status, military service, or any other non-merit factor.

    Interested in this position?

    Get in touch with us now!

    Quick Apply
    Email