About GFT GFT Technologies is an AI-centric global digital transformation company. We design advanced data and AI transformation solutions, modernize technology architectures and develop next-generation core systems for …
Skills: Penetration Testing, Ethical Hacking, Web Security, API Security, Mobile Application Security
[Từ Liêm, Hà Đông, Thanh Xuân, Cầu Giấy] Chuyên gia Bảo Hiểm
Hà Nội, Vietnam · On-site
Mid level
Job Purpose Người đảm nhận vị trí chịu trách nhiệm cung cấp các phương án bảo vệ, an toàn tài chính tốt nhất tới Khách hàng sử dụng sản phẩm Bảo hiểm và làm gia tăng sự gắn kết bền chặt giữa Khách hàng và Techcombank Key…
Job Purpose The Job Holder: - Performing Quality Assurance/Quality Control/Testing jobs is complexity, difficult with limited timeline and high quality requirement. Key Accountabilities (1) 1. Deploy the work - Directly …
Skills: Manual Testing, Automated Testing, Performance Testing, API Testing, Web Testing
Job Purpose Thực hiện bán bảo hiểm doanh nghiệp và quản lý pipeline khách hàng doanh nghiệp theo phân công; trực tiếp tham gia tư vấn, chào giá và xử lý thương vụ có mức độ phức tạp trung bình, nhằm đảm bảo hoàn thành ch…
Job Purpose Own complex quality engineering assignments and deliver reliable test outcomes under tight timelines. Combine testing expertise with business analysis to improve requirement quality, test coverage, and releas…
Skills: Quality Engineering, Manual Testing, Automated Testing, Business Analysis, Test Design
Job Purpose - Người đảm nhiệm công việc này chịu trách nhiệm đảm bảo tư vấn và cung cấp các sản phẩm, dịch vụ tài chính cá nhân theo đúng nhu cầu của khách hàng, nhằm mang lại trải nghiệm tốt nhất cho khách hàng. - Người…
Chuyên viên cao cấp kinh doanh bảo hiểm doanh nghiệp (50000375)
Hà Nội, Vietnam · On-site
Senior
Mục tiêu Trách nhiệm chính (1) Trách nhiệm chính (2) Trách nhiệm chính (3) Mạng lưới tương tác - Cấp Quản lý Mạng lưới tương tác - Cấp báo cáo Mạng lưới tương tác - Quan hệ nội bộ Mạng lưới tương tác - Quan hệ bên ngoài …
Chuyên viên Cao cấp Hoạch định chất lượng công nghệ (40001138)
Hà Nội, Vietnam · On-site
Senior
Mục tiêu Người đảm nhiệm vị trí: - Thực hiện các công việc Đảm bảo chất lượng/Kiểm soát chất lượng/ Kiểm thử mức độ phức tạp với thời gian hạn chế và yêu cầu chất lượng cao. Trách nhiệm chính (1) 1. Triển khai công việc …
Skills: Manual Testing, Automation Testing, Performance Testing, API Testing, Web Testing
Job Posting End Date: Worker Type: Maximum Term/Fixed Term (Fixed Term) ABOUT THE JOB We're seeking experienced and talented testing engineers to work on our banking services that serves millions of customers daily. You …
Job Purpose 'The Expert, Software Engineering role within TechcomBank’s IT Division – Development Engineering function is responsible for providing deep technical expertise, leading complex software development projects,…
Some Careers Grow Faster Than Others. If you’re looking for a career that will help you to stand out, join HSBC and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in a…
ACG_3722_JOB Our client is a leading fintech company who is looking for a qualified candidate to join their firm. Lead and oversee all legal affairs of the Company, ensuring compliance with applicable laws, proactively i…
ACG_3721_JOB Our client is a leading fintech company who is looking for a qualified candidate to join their firm. Risk Governance and Strategy Develop and maintain an enterprise-wide risk management framework aligned wit…
Job Purpose The job holder responsible for: Perform the preparation and issuance of periodic and irregular reports related to banking activities at the request of the State Bank, relevant agencies, partners fully, timely…
Skills: Regulatory reporting, Financial reporting, Accounting, Data analysis, Banking regulations
About Airwallex Airwallex is the only unified payments and financial platform for global businesses. Powered by our unique combination of proprietary infrastructure and software, we empower over 250,000 businesses worldw…
Skills: Partnership Management, Business Development, Account Management, Sales, Relationship Building
ACG_3522_JOB Our client is a leading financial services company who is looking for a qualified candidate to join their firm. JOB PURPOSE: Safeguard the enterprise’s financial stability and ensure regulatory compliance by…
Line of Service Assurance Industry/Sector Not Applicable Specialism Corporate and Business Strategy Management Level Intern/Trainee Job Description & Summary We help clients meet the increasing demands of regulators, sha…
Skills: Risk management, Data cleaning, Data processing, VBA, Microsoft Excel
ACG_3723_JOB Our client is a leading fintech company who is looking for a qualified candidate to join their firm. Develop the QA strategy, framework, and quality assurance processes for both manual and automated testing,…
Skills: QA strategy, Test automation, Manual testing, Fintech, Payment gateways
Chuyên viên phát triển phần mềm 1C (1C Development Executive)
Hà Nội, Vietnam · On-site
Mid level
TRÁCH NHIỆM CÔNG VIỆC Tham gia phát triển và tùy chỉnh ứng dụng: Tham gia vào việc thiết kế, lập trình và cấu hình các mô-đun trên nền tảng 1C:Enterprise để đáp ứng các nhu cầu kinh doanh cụ thể. Bảo trì và tối ưu hóa hệ…
Are you ready to unleash your potential? At Deloitte, our purpose is to make an impact that matters for our clients, our people, and the communities we serve. We believe we have a responsibility to be a force for good, a…
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Full-time
professional certificate
Posted 14d ago
~40 hrs/week
Responsibilities
Lead and execute end-to-end penetration testing across web, mobile, API, cloud, and banking platforms to identify and validate security vulnerabilities. Collaborate with stakeholders to guide remediation efforts and ensure alignment with regulatory and security standards.
Requirements
Requires deep expertise in ethical hacking and penetration testing with a strong understanding of banking systems and digital transaction workflows. Proficiency with security tools like Burp Suite and knowledge of OWASP standards are essential.
Full job description
About GFT
GFT Technologies is an AI-centric global digital transformation company. We design advanced data and AI transformation solutions, modernize technology architectures and develop next-generation core systems for industry leaders in Banking, Insurance, Manufacturing and Robotics. Partnering closely with our clients, we push boundaries to unlock their full potential. With deep industry expertise, cutting-edge technology, and a strong partner ecosystem, GFT delivers responsible AI-centric solutions that combine engineering excellence, high-performance delivery and cost efficiency. Our team of 12,000+ technology experts operates in 20+ countries worldwide offering career opportunities at the forefront of software innovation.
Role Summary
As a Lead Penetration Tester at GFT, you will be responsible for leading and performing authorized security testing activities across applications, digital platforms, APIs, infrastructure, cloud environments, and related systems. This role is designed as a hands-on technical leadership position, with approximately 70% focus on penetration testing execution and 30% focus on leading, guiding, reviewing, and coordinating security testing activities.
The role focuses on identifying security vulnerabilities, validating risks, supporting remediation, and ensuring that systems meet security, regulatory, and industry requirements. You will be expected to act as a senior technical expert, providing direction on testing approach, reviewing findings, mentoring team members, and ensuring high-quality penetration testing deliverables.
You will work closely with security teams, application teams, infrastructure teams, DevOps, architects, business stakeholders, and compliance teams to plan and perform penetration testing across web, mobile, API, cloud, and network environments. The role requires strong hands-on technical security skills, practical experience in ethical hacking, and the ability to communicate security risks clearly to both technical and non-technical stakeholders.
This role requires the candidate to work onsite at the client’s office based on project needs and client requirements. The onsite frequency, working schedule, location, and duration will be aligned with the client’s expectations and may vary depending on the project phase, testing activities, stakeholder meetings, security assessment timeline, and remediation support needs.
Key Activities
Hands-on Penetration Testing
Perform authorized penetration testing for web applications, mobile applications, APIs, infrastructure, cloud environments, and digital platforms.
Identify, validate, exploit where appropriate, and document security vulnerabilities, including authentication, authorization, session management, input validation, encryption, access control, and business logic issues.
Conduct security assessments based on industry standards such as OWASP Top 10, OWASP API Security Top 10, OWASP Mobile Security Testing Guide, and relevant security practices.
Analyze application flows, user journeys, transaction processes, access controls, and data handling mechanisms to identify potential security risks.
Perform vulnerability assessment and manual verification to reduce false positives and confirm actual exploitability in authorized environments.
Conduct retesting activities to validate remediation effectiveness and ensure vulnerabilities are properly resolved.
Support security testing activities within the SDLC, including security requirement review, threat analysis, test planning, and release security validation.
Stay updated with emerging cyber threats, attack techniques, security risks, and security testing best practices.
Technical Leadership & Delivery Support
Lead the planning, scoping, and execution of penetration testing activities across assigned projects or workstreams.
Define penetration testing approach, test strategy, testing scope, priorities, timelines, and required evidence based on project and client requirements.
Guide and mentor penetration testers or security engineers in testing methodology, vulnerability validation, reporting quality, and remediation discussions.
Review vulnerability findings, risk ratings, evidence, and remediation recommendations to ensure accuracy, consistency, and practical value.
Act as the main technical point of contact for penetration testing activities, working with client stakeholders, security teams, development teams, DevOps, infrastructure teams, and compliance teams.
Facilitate vulnerability walkthroughs, risk clarification sessions, remediation discussions, and retesting alignment with relevant stakeholders.
Support estimation, planning, status tracking, issue escalation, and delivery reporting for security testing activities.
Contribute to improving security testing processes, reporting templates, testing checklists, knowledge sharing, and reusable testing practices.
Support regulatory, audit, and compliance requirements by providing security testing evidence, reports, remediation status, and technical clarification when needed.
Required Skills
Strong hands-on experience in penetration testing, vulnerability assessment, ethical hacking, and security testing across application, API, mobile, network, and cloud environments.
Proven experience leading or coordinating penetration testing activities, including test planning, execution tracking, finding review, stakeholder communication, and retesting coordination.
Strong knowledge of web and API security vulnerabilities, including OWASP Top 10, API authentication, authorization, token handling, insecure direct object references, injection, broken access control, and business logic flaws.
Experience testing iOS and Android applications, including mobile application security controls, local storage, certificate pinning, authentication, session handling, and secure communication.
Experience in assessing network services, servers, operating systems, misconfigurations, access controls, and common infrastructure vulnerabilities.
Familiarity with cloud security concepts and security testing considerations for AWS, Azure, or GCP environments.
Hands-on experience with tools such as Burp Suite, OWASP ZAP, Nmap, Nessus, Metasploit, Wireshark, Postman, MobSF, or equivalent security testing tools.
Ability to independently validate vulnerabilities, assess exploitability, determine business impact, and provide clear remediation recommendations.
Ability to write and review clear security reports, including vulnerability details, risk ratings, technical evidence, business impact, and remediation guidance.
Ability to explain technical findings to both technical and non-technical stakeholders in a clear, structured, and practical manner.
Ability to work with engineering teams to clarify root causes, support fix implementation, and perform retesting.
Good understanding of secure coding principles, data privacy, encryption, identity and access management, and common security frameworks.
Understanding of security requirements in regulated, audit, or compliance-driven environments.
Strong problem-solving skills, ownership mindset, attention to detail, and ability to manage multiple testing activities in parallel.
Excellent English communication skills are required, with the ability to communicate fluently and confidently with client stakeholders, security teams, business users, and technical teams.
Nice-to-have Requirements
Prior experience working on penetration testing or security assessment projects for banks, fintechs, payment platforms, card systems, or financial institutions.
Good understanding of banking systems, digital banking, payments, cards, customer onboarding, AML/KYC, fraud management, account services, and transaction flows.
Familiarity with banking security practices and financial industry security requirements.
Familiarity with PCI DSS, ISO 27001, SOC 2, SWIFT Customer Security Controls Framework, local banking regulations, or other financial industry security requirements.
Experience conducting secure code review or working with SAST tools to identify security issues in application code.
Experience integrating security testing into CI/CD pipelines and working with tools such as SAST, DAST, SCA, container scanning, or secrets detection.
Familiarity with cloud misconfiguration assessment, container security, Kubernetes security, Docker security, and infrastructure-as-code security checks.
Experience with controlled red team exercises, attack simulation, phishing simulation, or adversary emulation in authorized environments.
Ability to use Python, Bash, PowerShell, or similar scripting languages to automate testing, validation, or reporting tasks.
Experience building security testing methodology, playbooks, checklists, report templates, or quality review practices.
Experience mentoring junior or mid-level penetration testers and supporting capability development within a security testing team.
Relevant certifications such as CEH, eJPT, PNPT, OSCP, GWAPT, GPEN, CISSP, CISM, or equivalent are preferred.
(Note: Due to the high volume of applications we receive, we are unable to respond to every candidate individually. If you have not received a response from GFT regarding your application within 10 workdays, please consider that we have decided to proceed with other candidates. We truly appreciate your interest in GFT and thank you for your understanding)
Related keywords
Penetration TestingEthical HackingOWASP Top 10OWASP API Top 10OWASP MSTGBurp SuiteOWASP ZAPNmapNessusMetasploitWiresharkPostmanMobSFAWSAzureGCP
GFT Technologies is an AI-centric global digital transformation company. We design advanced data and AI transformation solutions, modernize technology architectures and develop next-generation core systems for industry leaders in Banking, Insurance, Manufacturing and Robotics. Partnering closely with our clients, we push boundaries to unlock their full potential. With deep industry expertise, cutting-edge technology, and a strong partner ecosystem, GFT delivers responsible AI-centric solutions that combine engineering excellence, high-performance delivery and cost efficiency. Our team of 12,000+ technology experts operate in 20+ countries worldwide offering career opportunities at the forefront of software innovation.
Let’s Go Beyond_
Legal Disclaimer: https://www.gft.com/int/en/legal-disclaimer
Offices: Schelmenwasenstr. 34, Stuttgart, Baden-Württemberg 70567, DE · Via Sile, 18, Milan, MI 20139, IT · 6th Floor, 7 Bishopsgate, London, EC2N 3AR, GB · Al. Rio Negro, núm 585, Ed. Jaçarí, 1 andar, cj 18, Barueri - Alphaville, São Paulo 06.454-000, BR · Avinguda Alcalde Barnils, 71, Sant Cugat del Vallès, Barcelona, 08174, ES
Information TechnologyServiceNowTechnologyBankingInsuranceIndustryCloudITSoftwareBlockchain
How many Finance & Accounting jobs are open in Hà Nội, Vietnam right now?
There are currently 268 open finance & accounting positions in Hà Nội, Vietnam listed on Clera. New openings are added daily as companies post roles.
Which companies are hiring for Finance & Accounting roles in Hà Nội, Vietnam?
Companies currently hiring include Techcombank (TCB), Aloha Consulting Group, EY, Monitor Deloitte, GFT Technologies, among others. Browse the listings above to see every active employer.
Are there remote or hybrid Finance & Accounting jobs in Hà Nội, Vietnam?
Yes — 19 of the 268 open finance & accounting positions offer remote or hybrid work (1 remote, 18 hybrid).
How do I apply for Finance & Accounting jobs in Hà Nội, Vietnam?
Each listing links directly to the employer's application page. Apply early — fresh listings get the most recruiter attention in the first two weeks.