About GFT GFT Technologies is an AI-centric global digital transformation company. We design advanced data and AI transformation solutions, modernize technology architectures and develop next-generation core systems for …
Skills: Penetration Testing, Ethical Hacking, Web Security, API Security, Mobile Application Security
ACG_3721_JOB Our client is a leading fintech company who is looking for a qualified candidate to join their firm. Risk Governance and Strategy Develop and maintain an enterprise-wide risk management framework aligned wit…
About GFT GFT Technologies is an AI-centric global digital transformation company. We design advanced data and AI transformation solutions, modernize technology architectures and develop next-generation core systems for …
Skills: Penetration Testing, Ethical Hacking, Web Security, API Security, Mobile Application Security
ACG_3715_JOB Our client, a leading company in financial services sector in Vietnam, is looking for a qualified candidate to join their firm. Lead the establishment, implementation, and continuous enhancement of the Compa…
Skills: Risk Management Framework, Enterprise Risk Management, Risk Appetite Statement, Three Lines of Defence, Risk Governance
Alice builds adversarial evaluation infrastructure used by the world's leading AI labs to stress-test their most capable agents before deployment. We're hiring interns for our RL Gym environments: adversarial training gr…
Skills: Prompt Injection, YAML, Adversarial Thinking, AI Security, Command Line Interface
We are seeking a highly skilled and hands-on Senior IT Security Engineer to own and operate Niteco's security operations function, strengthen enterprise security management, and support security compliance across infrast…
Skills: Security Operations Center, Incident Response, Vulnerability Management, Microsoft Defender, Microsoft Entra ID
Line of Service Assurance Industry/Sector Not Applicable Specialism Conduct and Compliance Management Level Associate Job Description & Summary At PwC, our people in audit and assurance focus on providing independent and…
Skills: IT Audit, Compliance Management, Risk Management, Data Analysis, Information Security
Line of Service Assurance Industry/Sector Not Applicable Specialism Conduct and Compliance Management Level Senior Associate Job Description & Summary About IT Risk Assurance: Our focus is on creating effective and effic…
Skills: IT Audit, IT Risk Management, ERP Review, Data Analytics, Cybersecurity Control Review
Job Posting End Date: Worker Type: Maximum Term/Fixed Term (Fixed Term) YOUR JOB RESPONSIBILITIES The primary purpose of this role is to ensure NAB meets its obligations in relation to Know Your Customer (KYC) for existi…
Skills: Customer Due Diligence, Know Your Customer, Anti-Money Laundering, Counter-Terrorism Financing, Data Analysis
JLL empowers you to shape a brighter way. Our people at JLL are shaping the future of real estate for a better world by combining world class services, advisory and technology for our clients. We are committed to hiring …
Summary We are searching for a motivated and enthusiastic Assistant Airport Operations Manager (Based in Danang) with extensive knowledge in airport operations to join us! You will be part of the Ground Department team a…
Skills: Airport Operations Management, Stakeholder Management, On Time Performance (OTP), SLA Management, Audit and Compliance
CÔNG VIỆC CHÍNH: Quản trị rủi ro và kiểm soát nội bộ theo chuẩn COSO: Tham gia xây dựng, triển khai chính sách, quy trình, quy định về Quản lý rủi ro của Công ty. Tham gia xây dựng các quy định phân quyền và giám sát phâ…
Skills: Risk Management, Internal Control, ISO 9001:2015, ISO 22301:2019, COSO Framework
Kỹ thuật Viên Dịch vụ Kiểm soát Côn trùng Dịch hại (Hà Nội)
Hà Nội, Vietnam · On-site
Entry level$39M raised
Thực hiện công việc kiểm soát côn trùng dịch hại và đưa ra các đề xuất cho khách hàng Phản hồi về các vấn đề liên quan đến dịch vụ của khách hàng lên cấp trên; Bảo quản tất cả các thiết bị, công cụ, phương tiện đi lại và…
Skills: Pest Control, Customer Service, Communication Skills, Chemical Handling, Planning
Line of Service Assurance Industry/Sector Not Applicable Specialism Cybersecurity & Privacy Management Level Associate Job Description & Summary At PwC, our people in cybersecurity focus on protecting organisations from …
Prudential’s purpose is to be partners for every life and protectors for every future. Our purpose encourages everything we do by creating a culture in which diversity is celebrated and inclusion assured, for our people,…
Job Posting End Date: Worker Type: Maximum Term/Fixed Term (Fixed Term) ABOUT THE ROLE This role is responsible for contributing to the development and delivery of SOAR playbooks used as automation and orchestration tool…
Company Description SGS has been providing quality, reputable, independent, international services in Vietnam since 1989. These services assist Vietnamese businesses access world markets, increasing their reputation as a…
Skills: ESG Auditing, Technical Support, Sales Support, Relationship Management, Business Development
ACG_3675_JOB Our client is a leading food manufacturing company in Vietnam, seeking experienced professionals to join their firm. Quality Management Control and maintain quality management systems. Develop SOPs, work ins…
Skills: Quality Management, HSE Management, Team Leadership, Food Safety, ISO 22000
JLL empowers you to shape a brighter way. Our people at JLL are shaping the future of real estate for a better world by combining world class services, advisory and technology for our clients. We are committed to hiring …
Skills: Facilities Management, Property Management, Vendor Management, Occupational Health and Safety, Budgeting
Our Mission At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology an…
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Full-time
professional certificate
Posted 14d ago
~40 hrs/week
Responsibilities
Lead and execute end-to-end penetration testing across web, mobile, API, cloud, and banking platforms to identify and validate security vulnerabilities. Collaborate with stakeholders to guide remediation efforts and ensure alignment with regulatory and security standards.
Requirements
Requires deep expertise in ethical hacking and penetration testing with a strong understanding of banking systems and digital transaction workflows. Proficiency with security tools like Burp Suite and knowledge of OWASP standards are essential.
Full job description
About GFT
GFT Technologies is an AI-centric global digital transformation company. We design advanced data and AI transformation solutions, modernize technology architectures and develop next-generation core systems for industry leaders in Banking, Insurance, Manufacturing and Robotics. Partnering closely with our clients, we push boundaries to unlock their full potential. With deep industry expertise, cutting-edge technology, and a strong partner ecosystem, GFT delivers responsible AI-centric solutions that combine engineering excellence, high-performance delivery and cost efficiency. Our team of 12,000+ technology experts operates in 20+ countries worldwide offering career opportunities at the forefront of software innovation.
Role Summary
As a Lead Penetration Tester at GFT, you will be responsible for leading and performing authorized security testing activities across applications, digital platforms, APIs, infrastructure, cloud environments, and related systems. This role is designed as a hands-on technical leadership position, with approximately 70% focus on penetration testing execution and 30% focus on leading, guiding, reviewing, and coordinating security testing activities.
The role focuses on identifying security vulnerabilities, validating risks, supporting remediation, and ensuring that systems meet security, regulatory, and industry requirements. You will be expected to act as a senior technical expert, providing direction on testing approach, reviewing findings, mentoring team members, and ensuring high-quality penetration testing deliverables.
You will work closely with security teams, application teams, infrastructure teams, DevOps, architects, business stakeholders, and compliance teams to plan and perform penetration testing across web, mobile, API, cloud, and network environments. The role requires strong hands-on technical security skills, practical experience in ethical hacking, and the ability to communicate security risks clearly to both technical and non-technical stakeholders.
This role requires the candidate to work onsite at the client’s office based on project needs and client requirements. The onsite frequency, working schedule, location, and duration will be aligned with the client’s expectations and may vary depending on the project phase, testing activities, stakeholder meetings, security assessment timeline, and remediation support needs.
Key Activities
Hands-on Penetration Testing
Perform authorized penetration testing for web applications, mobile applications, APIs, infrastructure, cloud environments, and digital platforms.
Identify, validate, exploit where appropriate, and document security vulnerabilities, including authentication, authorization, session management, input validation, encryption, access control, and business logic issues.
Conduct security assessments based on industry standards such as OWASP Top 10, OWASP API Security Top 10, OWASP Mobile Security Testing Guide, and relevant security practices.
Analyze application flows, user journeys, transaction processes, access controls, and data handling mechanisms to identify potential security risks.
Perform vulnerability assessment and manual verification to reduce false positives and confirm actual exploitability in authorized environments.
Conduct retesting activities to validate remediation effectiveness and ensure vulnerabilities are properly resolved.
Support security testing activities within the SDLC, including security requirement review, threat analysis, test planning, and release security validation.
Stay updated with emerging cyber threats, attack techniques, security risks, and security testing best practices.
Technical Leadership & Delivery Support
Lead the planning, scoping, and execution of penetration testing activities across assigned projects or workstreams.
Define penetration testing approach, test strategy, testing scope, priorities, timelines, and required evidence based on project and client requirements.
Guide and mentor penetration testers or security engineers in testing methodology, vulnerability validation, reporting quality, and remediation discussions.
Review vulnerability findings, risk ratings, evidence, and remediation recommendations to ensure accuracy, consistency, and practical value.
Act as the main technical point of contact for penetration testing activities, working with client stakeholders, security teams, development teams, DevOps, infrastructure teams, and compliance teams.
Facilitate vulnerability walkthroughs, risk clarification sessions, remediation discussions, and retesting alignment with relevant stakeholders.
Support estimation, planning, status tracking, issue escalation, and delivery reporting for security testing activities.
Contribute to improving security testing processes, reporting templates, testing checklists, knowledge sharing, and reusable testing practices.
Support regulatory, audit, and compliance requirements by providing security testing evidence, reports, remediation status, and technical clarification when needed.
Required Skills
Strong hands-on experience in penetration testing, vulnerability assessment, ethical hacking, and security testing across application, API, mobile, network, and cloud environments.
Proven experience leading or coordinating penetration testing activities, including test planning, execution tracking, finding review, stakeholder communication, and retesting coordination.
Strong knowledge of web and API security vulnerabilities, including OWASP Top 10, API authentication, authorization, token handling, insecure direct object references, injection, broken access control, and business logic flaws.
Experience testing iOS and Android applications, including mobile application security controls, local storage, certificate pinning, authentication, session handling, and secure communication.
Experience in assessing network services, servers, operating systems, misconfigurations, access controls, and common infrastructure vulnerabilities.
Familiarity with cloud security concepts and security testing considerations for AWS, Azure, or GCP environments.
Hands-on experience with tools such as Burp Suite, OWASP ZAP, Nmap, Nessus, Metasploit, Wireshark, Postman, MobSF, or equivalent security testing tools.
Ability to independently validate vulnerabilities, assess exploitability, determine business impact, and provide clear remediation recommendations.
Ability to write and review clear security reports, including vulnerability details, risk ratings, technical evidence, business impact, and remediation guidance.
Ability to explain technical findings to both technical and non-technical stakeholders in a clear, structured, and practical manner.
Ability to work with engineering teams to clarify root causes, support fix implementation, and perform retesting.
Good understanding of secure coding principles, data privacy, encryption, identity and access management, and common security frameworks.
Understanding of security requirements in regulated, audit, or compliance-driven environments.
Strong problem-solving skills, ownership mindset, attention to detail, and ability to manage multiple testing activities in parallel.
Excellent English communication skills are required, with the ability to communicate fluently and confidently with client stakeholders, security teams, business users, and technical teams.
Nice-to-have Requirements
Prior experience working on penetration testing or security assessment projects for banks, fintechs, payment platforms, card systems, or financial institutions.
Good understanding of banking systems, digital banking, payments, cards, customer onboarding, AML/KYC, fraud management, account services, and transaction flows.
Familiarity with banking security practices and financial industry security requirements.
Familiarity with PCI DSS, ISO 27001, SOC 2, SWIFT Customer Security Controls Framework, local banking regulations, or other financial industry security requirements.
Experience conducting secure code review or working with SAST tools to identify security issues in application code.
Experience integrating security testing into CI/CD pipelines and working with tools such as SAST, DAST, SCA, container scanning, or secrets detection.
Familiarity with cloud misconfiguration assessment, container security, Kubernetes security, Docker security, and infrastructure-as-code security checks.
Experience with controlled red team exercises, attack simulation, phishing simulation, or adversary emulation in authorized environments.
Ability to use Python, Bash, PowerShell, or similar scripting languages to automate testing, validation, or reporting tasks.
Experience building security testing methodology, playbooks, checklists, report templates, or quality review practices.
Experience mentoring junior or mid-level penetration testers and supporting capability development within a security testing team.
Relevant certifications such as CEH, eJPT, PNPT, OSCP, GWAPT, GPEN, CISSP, CISM, or equivalent are preferred.
(Note: Due to the high volume of applications we receive, we are unable to respond to every candidate individually. If you have not received a response from GFT regarding your application within 10 workdays, please consider that we have decided to proceed with other candidates. We truly appreciate your interest in GFT and thank you for your understanding)
Related keywords
Penetration TestingEthical HackingOWASP Top 10OWASP API Top 10OWASP MSTGBurp SuiteOWASP ZAPNmapNessusMetasploitWiresharkPostmanMobSFAWSAzureGCP
GFT Technologies is an AI-centric global digital transformation company. We design advanced data and AI transformation solutions, modernize technology architectures and develop next-generation core systems for industry leaders in Banking, Insurance, Manufacturing and Robotics. Partnering closely with our clients, we push boundaries to unlock their full potential. With deep industry expertise, cutting-edge technology, and a strong partner ecosystem, GFT delivers responsible AI-centric solutions that combine engineering excellence, high-performance delivery and cost efficiency. Our team of 12,000+ technology experts operate in 20+ countries worldwide offering career opportunities at the forefront of software innovation.
Let’s Go Beyond_
Legal Disclaimer: https://www.gft.com/int/en/legal-disclaimer
Offices: Schelmenwasenstr. 34, Stuttgart, Baden-Württemberg 70567, DE · Via Sile, 18, Milan, MI 20139, IT · 6th Floor, 7 Bishopsgate, London, EC2N 3AR, GB · Al. Rio Negro, núm 585, Ed. Jaçarí, 1 andar, cj 18, Barueri - Alphaville, São Paulo 06.454-000, BR · Avinguda Alcalde Barnils, 71, Sant Cugat del Vallès, Barcelona, 08174, ES
Information TechnologyServiceNowTechnologyBankingInsuranceIndustryCloudITSoftwareBlockchain
How many Security & Safety jobs are open in Hà Nội, Vietnam right now?
There are currently 68 open security & safety positions in Hà Nội, Vietnam listed on Clera. New openings are added daily as companies post roles.
Which companies are hiring for Security & Safety roles in Hà Nội, Vietnam?
Companies currently hiring include Aloha Consulting Group, Techcombank (TCB), VINFAST, PwC, GFT Technologies, among others. Browse the listings above to see every active employer.
Are there remote or hybrid Security & Safety jobs in Hà Nội, Vietnam?
Yes — 13 of the 68 open security & safety positions offer remote or hybrid work (2 remote, 11 hybrid).
How do I apply for Security & Safety jobs in Hà Nội, Vietnam?
Each listing links directly to the employer's application page. Apply early — fresh listings get the most recruiter attention in the first two weeks.