{"id":1319737,"url":"https://alion.io/job/safetrust-application-security-penetration-testing-engineer","title":"Application Security & Penetration Testing Engineer","company":{"id":3828175,"name":"Safetrust","domain":"safetrust.com","url":"https://alion.io/company/safetrust","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"BambooHR","truth_index":null},"role":"Security","role_family":"Security","seniority":null,"employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Ho Chi Minh City, Vietnam"],"countries":["VN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":14000,"max_usd":39000,"period":"year","method":null,"sample_n":2929},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Burp Suite","optional":false},{"name":"Checkmarx","optional":false},{"name":"Defense in Depth","optional":false},{"name":"ISO 27001","optional":false},{"name":"JavaScript","optional":false},{"name":"Kali Linux","optional":false},{"name":"Least Privilege","optional":false},{"name":"Linux","optional":false},{"name":"Metasploit","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"Nmap","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP ASVS","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"OWASP ZAP","optional":false},{"name":"Postman","optional":false},{"name":"Python","optional":false},{"name":"Red Teaming","optional":false},{"name":"SonarQube","optional":false},{"name":"SQL","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-07-16T00:00:00Z","employer_posted_date":"2026-07-16","last_verified_at":"2026-10-01T03:30:35Z","board_verified":true,"closed_at":null,"days_open":78,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":78},"description":"About the role:\nThe Application Security & Penetration Testing Engineer is responsible for penetration testing, application security, source code review, and security protocol review across Safetrust's products. This position plays a key role in the security function, simulating attacks, reviewing code, and testing web and mobile apps against OWASP standards.\nThis role focuses on offensive and defensive application security work, and contributes to Safetrust's continued growth by ensuring our security protocols are built on strong key practices and sound design.\nKey Responsibilities:\nPenetration Testing\nExecute in-depth pentests on networks, web applications, mobile apps, and cloud environments.\nUse tools like Metasploit, Burp Suite, Nmap, and custom scripts to simulate sophisticated attacks.\nApplication & Web Security Testing\nTest web and mobile applications against OWASP Top 10 and OWASP ASVS.\nConduct dynamic (DAST) and static (SAST) testing using tools like OWASP ZAP, SonarQube, or Checkmarx.\nVerify secure implementation of authentication, session management, and data validation.\nSource Code Review\nPerform manual and automated code reviews to detect security issues (SQL injection, XSS, insecure dependencies).\nPartner with developers to implement secure coding standards and resolve findings.\nSecurity Protocol Review\nEvaluate and enhance security protocols using strong key practices (least privilege, defense-in-depth, secure key management).\nReview the design of security architectures: firewalls, encryption schemes, and authentication systems.\nIdentify design flaws or misconfigurations and recommend improvements aligned with NIST, ISO 27001, and MITRE ATT&CK.\nReporting & Collaboration\nDeliver comprehensive reports on pentest results, protocol reviews, and app security findings with actionable recommendations.\nWork with development, DevOps, and IT teams to embed security into the SDLC.\nMonitor emerging threats, vulnerabilities, and OWASP updates.\nSkills & Experience:\nBachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent experience).\n3+ years in penetration testing, red teaming, or application security roles (Senior: 5+).\nDemonstrated experience reviewing security protocol designs and conducting source code audits.\nMastery of pentest tools: Metasploit, Burp Suite, Kali Linux.\nProficiency with AppSec tools: OWASP ZAP, Postman, Checkmarx, or similar.\nStrong knowledge of programming languages (Python, Java, JavaScript) for code review and automation.\nExpertise in OWASP Top 10, OWASP ASVS, and security design principles (zero trust, defense-in-depth).\nExperience with cloud platforms (AWS, Azure) and modern web frameworks.\nNice to Have / Preferred\nCertifications: OSCP, OSCE, CRTP, GWAPT, CEH, or equivalent.\nExperience with red-team operations, APT simulations, or social engineering exercises.\nExposure to IoT, embedded, or access-control product security.\nExperience developing proof-of-concept exploits for systems, code, or protocols.\nSuccess Profile:\nThe ideal candidate is:\nAn analytical thinker with a focus on secure design and vulnerability discovery.\nAble to articulate technical findings clearly to developers, architects, and leadership.\nCollaborative, with a proactive, adversarial perspective.\nComfortable owning security assessments end-to-end, from testing to remediation follow-up.\nComfortable working across regions and functions in a global environment (Vietnam, US, Australia).\nWhy you'll love working here\nCompetitive salary based on experience and performance\n13th-month salary \nDaily lunch is provided at the office\nFree coffee, tea, and refreshments\nFull statutory insurance (social, health, unemployment)\nAnnual health check-up and paid annual leaves\nProfessional, international working environment\nWorking Location:\nLevel 6 Khanh Hoi 2 Building 360A Ben Van Don, Vinh Hoi, Ho Chi Minh City\nSafetrust is an equal opportunity employer and prohibits discrimination and harassment of any kind. We offer an inclusive workplace and will not tolerate discrimination against any job candidate or employee due to age, race, religion, color, ethnicity, national origin, gender, gender identity/expression, sexual orientation, membership in an employee organization, medical condition, family history, genetic information, veteran status, marital status or parental status.","description_format":"text","description_chars":4389,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Annual leave"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Penetration Testing","Information Security","Application Security","Vulnerability Management"],"lifecycle":[{"event":"open","at":"2026-09-26T20:47:43Z"}],"liveness":{"score":10,"band":"cold","label":"Long shot","p_open":1,"p_active":0.363,"p_room":0.28,"age_days":77,"expected_fill_days":36,"reasons":["conf:2","win:tail","crowd:"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/safetrust-application-security-penetration-testing-engineer","json_url":"https://alion.io/job/safetrust-application-security-penetration-testing-engineer.json","meta":{"generated_at":"2026-10-02T02:18:14Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3080,"day_limit":5000,"remaining_today":1920,"minute_limit":60,"resets_at":"2026-10-03T00:00:00Z"}}}