The Security Engineer will conduct security audits, identify vulnerabilities, propose fixes, design secure architectures, and drive cybersecurity initiatives within the company.
ABOUT US:
At Gradion, we are the strategic partner for ambitious businesses, helping them achieve breakthrough growth through Digital Innovation and Deep Tech. With a global vision and an AI-first approach, we enable clients to reshape strategies, optimize systems, and adopt cutting-edge technologies to create sustainable value.
From AI and data to cybersecurity, robotics, and large-scale enterprise platforms, Gradion designs practical solutions that lay the foundation for the next generation of billion-dollar companies.
OUR FACTS & FIGURES:
- 23+ years of expertise — Gradion builds digital platforms & deep-tech solutions.
- 3 continents: Asia, Europe and Africa.
- 300+ specialists across 7 countries Vietnam, Singapore, Thailand, Saudi Arabia, Germany, Egypt, Indonesia.
- 100+ enterprise clients, including several unicorns (e.g., Alaiko, HomeToGo, Roadsurfer).
- Vietnam’s Best IT Company – recognized by ITViec for 7 consecutive years, including 2 consecutive years of ranking #1 (2024 and 2025)
- ISO 27001.
We’re looking for a Security Engineer (Red Team) to help strengthen the security of the products we deliver to our clients and to build a long-term internal security framework for Gradion. You’ll audit existing client projects, identify vulnerabilities, propose preventive measures, and drive company-wide cybersecurity initiatives.
Our projects include web and mobile applications deployed on cloud platforms. You’ll work closely with delivery and engineering teams to ensure client products meet high security standards, while shaping Gradion’s overall approach to cybersecurity in a dynamic, collaborative environment that values ownership, excellence, and innovation.
In this role, you will:
- Conduct web application penetration testing focused on OWASP Top 10 and modern web attack techniques (SQLi, XSS, SSRF, RCE, IDOR, etc.).
- Analyze, assess, and exploit security vulnerabilities in web applications, APIs, and administrative systems.
- Support in developing defensive measures and guide Dev/DevSecOps teams in remediation.
- Research web exploitation techniques, create PoCs, and develop automated auditing tools for QC.
- Set up and operate attack simulation environments and provide detailed vulnerability reports.
What you will bring:
- At least 2 years of experience in penetration testing or Red Team operations.
- Deep understanding of OWASP Top 10, authentication/authorization mechanisms, session handling, cookies, CSRF, and API security practices.
- Skilled in both whitebox (source code analysis) and blackbox testing approaches.
- Hands-on experience with tools such as Burp Suite, OWASP ZAP, Nuclei, and Metasploit.
- Experience in testing or attacking applications hosted on Cloud platforms (AWS, GCP, Azure) is a plus.
- Possession of professional certifications like OSWE, OSCP, eWPTX, or equivalent is an advantage.
Nice to have:
- Experience as a white-hat hacker or bug bounty participant.
- Proficiency in business English, including the ability to draft professional emails, reports, and explanations.
🏆 Join Vietnam’s Best IT Company – Gradion Vietnam (formerly NFQ Vietnam) was recognized by ITViec for 7 consecutive years, including 2 successive years as the Winner. Work with some of the best minds in the industry and be part of a company that’s redefining how businesses scale through technology.
🌍 Career Growth & Leadership Development – Work closely with our leadership team, gain mentorship from experienced executives, and have direct exposure to high-level strategic decisions. Your growth is limitless, as long as you’re ready to step up, opportunities will always be there for you.
💰 Competitive Compensation – We believe great talent deserves great rewards. Expect an attractive salary, performance-based bonuses, and a benefits package that reflects your impact. We value talent over salary budgets - exceptional contributions deserve exceptional rewards.
✨ And Many More Benefits to Explore! But most importantly, a healthy work-life balance and an environment where you can thrive - professionally and personally. Including:
- A laptop is provided.
- Community Tech activities.
- A fun & dynamic environment and freedom to be creative.
- Modern office with a flexible, relaxing zone.
- Performance bonus (up to 2-month salary).
- Performance review 2 times/ year.
- Extra Premium Healthcare & Annual Health-check.
- 15 days of annual leave.
Working time: Monday – Friday (9 AM - 6 PM)
Location: Podium Floor, Sapphire 2 tower, 92 Nguyen Huu Canh Street, Thanh My Tay Ward, Ho Chi Minh City, Vietnam.
According to General Data Protection Regulation (GDPR), Singapore's Personal Data Protection Act (PDPA), Indonesia's PDP Law 2022, and Vietnam's Decree 13/2023/ND-CP, while also ensuring compliance with other applicable local data
protection laws in the jurisdictions where we operate, including but not limited to Vietnam, Indonesia, Thailand, Egypt, Singapore, Germany, and Saudi Arabia, Gradion applies the “Personal Data Protection Policy” to all candidates to ensure compliance with the laws.
By submitting your application to Gradion, you agree to allow us to process your provided information in accordance with the Personal Data Protection Policy that you have carefully read, understood, and agreed to in its entirety at Link.