← Scandinavian Software Park
Cyber Security Specialist
Scandinavian Software Park · Hà Nội
Apply on official site ↗
Type
Full-time
Work mode
On-site
Level
Staff
Industry
Other
Salary
Thương lượng
Location
Quận Đống Đa, Hà Nội, Hà Nội
Overview
- AI Penetration Testing
- Map the AI environment of each portfolio company, including LLMs, prompts, RAG pipelines, agentic workflows, APIs and connected systems, to define a precise attack surface before testing begins.
- Plan and execute full-scope penetration tests against web applications, APIs, and internal systems for portfolio companies, from scoping and reconnaissance through to exploitation and reporting.
- Stress-test AI system behavior under real-world adversarial conditions, evaluating how models and agents respond to manipulation, privilege abuse, and unexpected inputs.
- Produce professional pen test reports that are rigorous enough for engineering teams and comprehensible enough for product leadership, with clear risk ratings and remediation roadmaps.
- Red Teaming
- Conduct threat intelligence-led OSINT reconnaissance to map each portfolio company’s digital footprint, identify exposed assets, and define realistic attack scenarios grounded in how real adversaries operate.
- Execute multi-vector attack simulations combining external and internal network exploitation, social engineering, phishing, and lateral movement to reveal how far an attacker could realistically penetrate.
- Run both Full Simulation engagements (end-to-end attack chain from initial access to exfiltration) and Assumed Compromise scenarios (focused on lateral movement and detection/response after access).
- Validate detection and response capabilities: evaluate whether security controls, monitoring, and incident response processes would catch and contain a real attack.
- Deliver actionable reporting with full attack path documentation, exploited weaknesses, business impact assessment, and prioritized recommendations to strengthen resilience.
- Code-Based Security Review
- Lead in-depth security reviews of application codebases, identifying logic flaws, injection vulnerabilities, broken authentication, insecure data handling, and supply-chain risks.
- Apply AI-assisted static analysis alongside manual review techniques to achieve deeper coverage across multiple languages and frameworks.
- Delivery findings with severity ratings, exploitability assessments and precise remediation guidance; present results directly to engineering leads and CTOs.
- AI System Security
- Assess the security of AI-powered product features – covering prompt injections, indirect prompt injection, model data leakage, insecure LLM integrations and adversarial input scenarios.
- Review how portfolio companies handle AI-generated outputs in security-sensitive contexts: access control, data isolation, and auditability of AI-driven decisions.
- Stay current on the evolving AI threat landscape (OWASP LLM Top 10, emerging jailbreak patterns, supply-chain risks in AI frameworks) and translate findings into practical guidance.
- Threat Modeling
- Lead threat modeling sessions (STRIDE, PASTA, or equivalent) with portfolio company product and engineering teams during design and architecture phases, not just after the fact.
- Translate threat models into actionable security requirements, test cases, and backlog items that engineering teams can act on.
- Build and maintain threat profiles for portfolio companies, updating them as products evolve and new attack surfaces emerge.
- Your Skills and Experience
- What we are looking for
Requirements
- 5+ years of hands-on experience in application security, penetration testing or vulnerability management.
- Solid experience conducting vulnerability assessments and penetration tests on web applications and APIs with the ability to deliver professional reports independently.
- Strong understanding of OWASP Top 10 and OWASP LLM Top 10, web and API vulnerability classes, authentication and authorization flaws and business logic abuse.
- Experience with AI red teaming that covers traditional adversarial operations (threat intelligence-led attack planning, OSINT reconnaissance, multi-vector simulations and detection/response validation) and AI-specific targets (LLM jailbreaks, prompt injection, and adversarial testing of generative AI features in production).
- Experience leading threat modeling sessions (STRIDE, PASTA, or equivalent) with engineering and product teams.
- Familiarity with AI/LLM security risks: prompt injection, model data leakage, insecure LLM integrations and adversarial scenarios.
- Strong code review skills across multiple languages (e.g., Python, JavaScript/TypeScript, Java, Go, C#) – able to identify vulnerabilities in unfamiliar codebases independently.
- Experience with AI-assisted or automated security tooling (e.g., Semgrep, Snyk, GitHub Advanced Security…) and the judgment to critically evaluate their output.
- Cloud penetration testing experience (AWS, Azure, GCP) and container/Kubernetes security.
- Understanding of B2B SaaS security patterns: multi-tenancy, OAuth/OIDC, API authentication and cloud-native privilege models.
- Strong English communication skills, both written and spoken.
- Nice to have
- OSCP, OSWoE, GPEN, GWAPT, or equivalent offensive security certification
- Experience with TIBER-EU or ART (Advanced Red Teaming) frameworks.
- Knowledge of compliance and risk frameworks relevant to Nordic/European software companies: ISO 27001, SOC 2, GDPR, NIS2.
- Prior experience working with B2B SaaS or Nordic/European software companies is a strong plus
- Why this role is interesting
- You get to work at the actual intersection of AI and offensive security, not just reading about it, but testing it against real products in production.
- Full access to the best AI-assisted security tooling, no personal budget worries, no approval process, no waiting.
- You’ll work across 30+ different tech stacks and companies, not just one.
- You’ll see inside many different B2B software businesses through security reviews and threat modeling.
- Scandinavian work culture: trust, autonomy and a sensible view on work-life balance.
- Modern office at Peakview Tower in central Hanoi
Benefits
- The Job
- Scandinavian Software Park is the Hanoi-based tech hub and home to several of Scandinavia’s market-leading B2B SaaS companies. Founded and operated by Monterro, the leading B2B software investor in the Nordics, Scandinavian Software Park enables portfolio companies to accelerate growth and build high-end engineering and product capabilities in Vietnam. This role sits within our product services,…
- This is a senior individual contributor role for a seasoned security professional who brings deep offensive and defensive expertise and can operate independently across multiple complex engagements. As a Cyber Security Specialist, you will be a key technical authority, leading continuous vulnerability intelligence operations, conducting advanced penetration tests and code security reviews, and…
HealthcareTraining
Summary of facts from the official posting. View original ↗
Interested in this role?
You'll be taken to the employer's official application page.
Apply on official site ↗
Is this your business?
Claim this page, request edits or removal
→