Việc làm này đã được thêm vào mục Việc làm đã lưu.
Bạn đã lưu tối đa 20 việc làm. Nếu bạn muốn lưu mới, hãy cập nhật Việc làm đã lưu.
3 Lý do để gia nhập công ty
- Global growth with experienced engineers
- Innovative, balanced, creative culture
- Competitive salary, benefits, training
Mô tả công việc
Scandinavian Software Park is the Hanoi-based tech hub and home to several of Scandinavia’s market-leading B2B SaaS companies. Founded and operated by Monterro, the leading B2B software investor in the Nordics, Scandinavian Software Park enables portfolio companies to accelerate growth and build high-end engineering and product capabilities in Vietnam. This role sits within our product services, aiming to delivering expert-level services directly to Monterro’s portfolio of 30+ B2B software companies.
This is a senior individual contributor role for a seasoned security professional who brings deep offensive and defensive expertise and can operate independently across multiple complex engagements. As a Cyber Security Specialist, you will be a key technical authority, leading continuous vulnerability intelligence operations, conducting advanced penetration tests and code security reviews, and advising on the security of AI-powered features across Monterro’s portfolio of Nordic B2B SaaS products. You are also expected to bring the judgment and seniority to triage ambiguous findings, lead threat modeling sessions, support incident response and raise the security maturity of the products you work with.
What you’ll do
AI Penetration Testing
- Map the AI environment of each portfolio company, including LLMs, prompts, RAG pipelines, agentic workflows, APIs and connected systems, to define a precise attack surface before testing begins.
- Plan and execute full-scope penetration tests against web applications, APIs, and internal systems for portfolio companies, from scoping and reconnaissance through to exploitation and reporting.
- Stress-test AI system behavior under real-world adversarial conditions, evaluating how models and agents respond to manipulation, privilege abuse, and unexpected inputs.
- Produce professional pen test reports that are rigorous enough for engineering teams and comprehensible enough for product leadership, with clear risk ratings and remediation roadmaps.
Red Teaming
- Conduct threat intelligence-led OSINT reconnaissance to map each portfolio company’s digital footprint, identify exposed assets, and define realistic attack scenarios grounded in how real adversaries operate.
- Execute multi-vector attack simulations combining external and internal network exploitation, social engineering, phishing, and lateral movement to reveal how far an attacker could realistically penetrate.
- Run both Full Simulation engagements (end-to-end attack chain from initial access to exfiltration) and Assumed Compromise scenarios (focused on lateral movement and detection/response after access).
- Validate detection and response capabilities: evaluate whether security controls, monitoring, and incident response processes would catch and contain a real attack.
- Deliver actionable reporting with full attack path documentation, exploited weaknesses, business impact assessment, and prioritized recommendations to strengthen resilience.
Code-Based Security Review
- Lead in-depth security reviews of application codebases, identifying logic flaws, injection vulnerabilities, broken authentication, insecure data handling, and supply-chain risks.
- Apply AI-assisted static analysis alongside manual review techniques to achieve deeper coverage across multiple languages and frameworks.
- Delivery findings with severity ratings, exploitability assessments and precise remediation guidance; present results directly to engineering leads and CTOs.
AI System Security
- Assess the security of AI-powered product features – covering prompt injections, indirect prompt injection, model data leakage, insecure LLM integrations and adversarial input scenarios.
- Review how portfolio companies handle AI-generated outputs in security-sensitive contexts: access control, data isolation, and auditability of AI-driven decisions.
- Stay current on the evolving AI threat landscape (OWASP LLM Top 10, emerging jailbreak patterns, supply-chain risks in AI frameworks) and translate findings into practical guidance.
Threat Modeling
- Lead threat modeling sessions (STRIDE, PASTA, or equivalent) with portfolio company product and engineering teams during design and architecture phases, not just after the fact.
- Translate threat models into actionable security requirements, test cases, and backlog items that engineering teams can act on.
- Build and maintain threat profiles for portfolio companies, updating them as products evolve and new attack surfaces emerge.
Yêu cầu công việc
What we are looking for
Requirements:
- 5+ years of hands-on experience in application security, penetration testing or vulnerability management.
- Solid experience conducting vulnerability assessments and penetration tests on web applications and APIs with the ability to deliver professional reports independently.
- Strong understanding of OWASP Top 10 and OWASP LLM Top 10, web and API vulnerability classes, authentication and authorization flaws and business logic abuse.
- Experience with AI red teaming that covers traditional adversarial operations (threat intelligence-led attack planning, OSINT reconnaissance, multi-vector simulations and detection/response validation) and AI-specific targets (LLM jailbreaks, prompt injection, and adversarial testing of generative AI features in production).
- Experience leading threat modeling sessions (STRIDE, PASTA, or equivalent) with engineering and product teams.
- Familiarity with AI/LLM security risks: prompt injection, model data leakage, insecure LLM integrations and adversarial scenarios.
- Strong code review skills across multiple languages (e.g., Python, JavaScript/TypeScript, Java, Go, C#) – able to identify vulnerabilities in unfamiliar codebases independently.
- Experience with AI-assisted or automated security tooling (e.g., Semgrep, Snyk, GitHub Advanced Security…) and the judgment to critically evaluate their output.
- Cloud penetration testing experience (AWS, Azure, GCP) and container/Kubernetes security.
- Understanding of B2B SaaS security patterns: multi-tenancy, OAuth/OIDC, API authentication and cloud-native privilege models.
- Strong English communication skills, both written and spoken.
Nice to have
- OSCP, OSWoE, GPEN, GWAPT, or equivalent offensive security certification
- Experience with TIBER-EU or ART (Advanced Red Teaming) frameworks.
- Knowledge of compliance and risk frameworks relevant to Nordic/European software companies: ISO 27001, SOC 2, GDPR, NIS2.
- Prior experience working with B2B SaaS or Nordic/European software companies is a strong plus
Why this role is interesting
- You get to work at the actual intersection of AI and offensive security, not just reading about it, but testing it against real products in production.
- Full access to the best AI-assisted security tooling, no personal budget worries, no approval process, no waiting.
- You’ll work across 30+ different tech stacks and companies, not just one.
- You’ll see inside many different B2B software businesses through security reviews and threat modeling.
- Scandinavian work culture: trust, autonomy and a sensible view on work-life balance.
- Modern office at Peakview Tower in central Hanoi
- Competitive salary for the Hanoi market
Tại sao bạn sẽ yêu thích làm việc tại đây
What will you get?
Join our innovative and market-leading Scandinavian SaaS company and accelerate your growth alongside experienced software engineers from around the world. We value creativity, innovation, and work-life balance in our Scandinavian work culture, and offer a competitive salary with 100% official salary during the probation period, annual reviews, and 13th month salary.
We prioritize the well-being of our employees with premium healthcare and accident insurance, as well as a wellness package to help you stay healthy and wealthy. You'll also have the chance to participate in exciting company outings, team-building activities, and on-site training opportunities in the Nordic region.
Work in a modern and supportive environment where your individuality is valued, and collaborate with a talented team on a mission to become global players in the industry.
Scandinavian Software Park is a tech hub for Scandinavia’s market leading SaaS companies.
