

Search by job, company or skills

Job information:
Level: Mid - Senior
Location: 5th Floor, Victory Tower, 318-320 Nguyen Oanh, Go Vap Ward, HCMC
About the Role
We are looking for a Product Security Engineer with an offensive security mindset to proactively identify, validate, and help eliminate security risks across our products and cloud infrastructure.
You will operate as an internal security researcher, continuously assessing the security posture of our web applications, APIs, cloud infrastructure (AWS), source code, and software development lifecycle to identify vulnerabilities before attackers do.
Beyond vulnerability research, you will continuously improve the security posture of our products through proactive security reviews, attack simulations, runtime monitoring, security automation, and close collaboration with engineering teams.
Key Responsibilities
1. Product Security Ownership
Own the security posture of assigned products throughout the entire Software Development Lifecycle (SDLC).
Responsibilities include:
• Act as the security champion for assigned products.
• Continuously assess security risks throughout the product lifecycle.
• Work closely with Engineering, DevOps and Product teams to improve product security.
• Ensure security is considered from design through production.
2. Product Security Assessment
Perform security assessments across:
• Web Applications
• REST / GraphQL APIs
• Backend Services
• Mobile APIs (where applicable)
• AWS Cloud Infrastructure
• Kubernetes & Docker
• Internal Services
• Authentication & Authorization
• CI/CD Pipelines
• Third-party Integrations
Conduct:
• Manual Security Assessments
• Penetration Testing
• Architecture Security Reviews
• Secure Design Reviews
• Threat Modeling
3. Offensive Security & Vulnerability Research
Proactively discover, validate and assess security vulnerabilities, including:
Web & API Security
• Broken Access Control
• IDOR
• Authentication & Authorization Bypass
• Business Logic Flaws
• Privilege Escalation
• SQL / NoSQL Injection
• Command Injection
• SSRF
• XSS
• CSRF
• XXE
• Path Traversal
• File Upload Vulnerabilities
• Insecure Deserialization
• Open Redirect
• Rate Limit Bypass
• API Abuse
• Session Management Weaknesses
Cloud & Infrastructure Security
• IAM Misconfigurations
• Excessive Privileges
• Cross-account Access Risks
• IAM Trust Relationship Issues
• Public S3 Buckets
• Exposed Secrets
• KMS & Secrets Manager Misconfigurations
• Security Group Misconfigurations
• Open Management Ports
• Kubernetes RBAC & IRSA Misconfigurations
• Container Escape Risks
• TLS/SSL Weaknesses
• DNS Misconfigurations
• Sensitive Information Disclosure
Dependency & Supply Chain Security
• CVE Assessment
• Dependency Vulnerability Analysis
• Open Source Component Risks
• Outdated Packages
• Software Supply Chain Security
4. Source Code Security Assessment
Perform manual and AI-assisted source code security reviews.
Responsibilities include:
• Identify insecure coding practices.
• Review authentication and authorization logic.
• Review cryptography implementation.
• Review session management.
• Identify business logic vulnerabilities.
• Validate security fixes before release.
• Work with development teams to eliminate security weaknesses early.
5. Security Monitoring & Threat Detection
Continuously monitor production environments to identify abnormal behaviors and potential attacks.
Monitor and investigate:
• Abnormal Traffic Patterns
• DDoS / DoS Attempts
• Brute-force Attacks
• Credential Stuffing
• Automated Bot Activities
• API Abuse
• Rate Limit Bypass Attempts
• Reconnaissance Activities
• Vulnerability Scanning
• Exploitation Attempts
• Suspicious Requests
• WAF Events
• AWS GuardDuty Findings
• AWS CloudTrail Events
• Suspicious IAM Activities
• Privilege Escalation Attempts
• Sudden Error Rate Increases
• Unusual CPU, Memory, Network or Application Workloads that may indicate attacks or compromise
Recommend and implement improvements to:
• Detection Rules
• Alerting
• Monitoring
• Security Controls
• Mitigation Strategies
6. Security Validation
• Develop Proof-of-Concepts (PoCs)
• Validate exploitability
• Assess business impact
• Prioritize vulnerabilities using CVSS
• Eliminate false positives
• Recommend remediation strategies
• Verify fixes after remediation
7. Secure SDLC
Drive security integration throughout the Software Development Lifecycle.
Responsibilities include:
• Security Code Reviews
• Threat Modeling
• Security Requirements Definition
• Secure Design Reviews
• Security Architecture Reviews
• Security Sign-off before Production Release
• Security Gates in CI/CD Pipelines
• Security Acceptance Criteria
• Promote Security-by-Design and Secure-by-Default principles
8. Proactive Security Review for New Features
Review every new feature before production release to identify security risks as early as possible.
Responsibilities include:
• Reviewing new APIs, features and architectural changes.
• Identifying new attack surfaces.
• Performing security impact analysis.
• Providing remediation recommendations before implementation.
• Working closely with engineering teams to build secure-by-default solutions.
9. Threat Simulation & Attack Validation
Conduct periodic offensive security exercises to validate the effectiveness of security controls and detection capabilities.
Responsibilities include:
• Simulating realistic attack scenarios.
• Conducting adversary emulation.
• Validating security controls.
• Evaluating detection and alerting capabilities.
• Identifying monitoring and logging gaps.
• Improving product resilience against real-world attacks.
10. Security Automation & AI-assisted Security
Improve security efficiency through automation and AI.
Responsibilities include:
• Automate vulnerability scanning.
• Automate secret detection.
• Automate security validation.
• Automate regression security testing.
• Develop internal security tools.
• Utilize AI-assisted tools for source code analysis, vulnerability research, attack path discovery and Proof-of-Concept generation.
11. Threat Intelligence
Continuously research emerging threats relevant to company products.
Responsibilities include:
• Track newly published CVEs.
• Monitor emerging attack techniques.
• Research exploitation trends.
• Evaluate applicability to company products.
• Recommend mitigation strategies before exploitation occurs.
12. Security Reporting
Produce and maintain:
• Vulnerability Reports
• Security Assessment Reports
• Security Advisories
• Risk Assessments
• Proof-of-Concept Documentation
• Remediation Tracking
• Executive Security Summaries
Qualifications
Technical Knowledge
Strong understanding of:
• Linux
• Networking
• HTTP/HTTPS
• DNS
• TLS/SSL
• OAuth2 / OpenID Connect
• JWT
• AWS Security
• Kubernetes Security
Strong familiarity with:
• OWASP Top 10
• OWASP API Security Top 10
• MITRE ATT&CK
• CVSS
• CWE
• Secure SDLC
Technical Skills
Experience with one or more of:
• Burp Suite
• Nuclei
• Nmap
• ffuf
• Amass
• Subfinder
• ProjectDiscovery Tools
• Trivy
• Semgrep
• Gitleaks
• TruffleHog
• Snyk / Dependabot
Additional skills:
• Source code review (preferably .NET / C#)
• Python, Bash or PowerShell scripting
• Security automation
• Log analysis
• Digital forensics
• AI-assisted security tooling
Preferred Qualifications
• Experience in Bug Bounty or Responsible Disclosure programs.
• Experience discovering High or Critical vulnerabilities.
• Experience with DevSecOps, SAST, DAST, IaC Security, Container Security or Application Security.
• Experience securing AWS-based SaaS platforms.
• Security certifications such as OSCP, PNPT, eJPT, CRTO, CISSP or equivalent.
Success Metrics (KPIs)
• Reduction of security risks across products.
• Number of High/Critical vulnerabilities identified.
• Number of Business Logic vulnerabilities discovered.
• Security review coverage before production releases.
• Mean Time to Validate (MTTV).
• Mean Time to Remediate (MTTR).
• Security automation coverage.
• Threat detection effectiveness.
• Reduction in false positives.
• Improvements in attack detection and product resilience demonstrated through threat simulation exercises.
Who You Are
You think like an attacker but work to protect products.
You are naturally curious and constantly ask:
• How could this feature be abused
• Can this protection be bypassed
• Is this traffic normal or an attack
• Can multiple low-risk issues be chained into a critical exploit
• What would an attacker try next
• How can we detect and prevent this earlier
You enjoy proactively discovering vulnerabilities, researching emerging threats, validating real-world attack scenarios, and building secure products before incidents happen.
BENEFITS
1. Compensation and benefit package
2. Exciting career and development opportunities
3. Friendly and English-speaking working environment
Job ID: 151550785
Skills:
.NET, security automation , Digital Forensics, Networking, Dns, Powershell Scripting, Https, Tls, Python, Oauth2, Log Analysis, Jwt, Nmap, Bash, Http, SSL, C Sharp, Burp Suite, Linux, Subfinder, ProjectDiscovery Tools, Gitleaks, Kubernetes Security, Nuclei, AWS Security, Trivy, OpenID Connect, AI-assisted security tooling, Snyk, Dependabot, Amass, TruffleHog, Semgrep, ffuf