Overview

Security Manager Jobs in Ho Chi Minh City, Vietnam at MYMIND Technology

Title: Security Manager

Company: MYMIND Technology

Location: Ho Chi Minh City, Vietnam

ABOUT THE COMPANY 

With over 10 years of relentless innovation, MyMind Joint Stock Company (MSM) is redefining the future of enterprise management. We deliver smart, scalable digital solutions that power business transformation across industries—from enterprises and agriculture to smart manufacturing.​ 

By combining deep domain expertise with cutting-edge technology, MSM helps organizations worldwide simplify complexity, accelerate growth, and lead with confidence in the digital era. 

 

ABOUT THE POSITION  

MSM is looking for a highly skilled Security Manager with a strong Offensive Security mindset to lead and enhance the company’s cybersecurity capabilities across applications, infrastructure, cloud-native systems, and DevSecOps practices. 

This role is ideal for someone who is deeply hands-on in penetration testing, vulnerability research, exploit development, and security automation, while also being capable of driving security processes, mentoring engineering teams, and improving the overall security posture of the organization. 

The ideal candidate is not only able to identify vulnerabilities but can also demonstrate real-world exploitability, automate offensive security workflows, and collaborate closely with Engineering and DevOps teams to build secure-by-design systems 

 

KEY RESPONSIBILITIES 

Offensive Security & Penetration Testing 

  • Perform advanced penetration testing on web applications, APIs, cloud infrastructure, Kubernetes environments, and containerized systems.  
  • Utilize offensive security tools such as Burp Suite, Metasploit, Nmap, Nuclei, and similar platforms to identify and validate vulnerabilities.  
  • Develop custom scripts and internal tools using Javascript, Python, Go, or Bash to automate large-scale vulnerability scanning and exploit workflows.  
  • Build and implement Continuous Pentesting capabilities integrated directly into CI/CD pipelines.  
  • Conduct in-depth assessments on Kubernetes security, container escape scenarios, API server security, and cloud-native applications.  
  • Assess Infrastructure-as-Code (IaC) environments such as Terraform and Ansible for security misconfigurations and weaknesses.  

 

Vulnerability Research & Exploitation 

  • Identify and exploit complex business logic vulnerabilities that cannot be detected through automated scanning tools.  
  • Chain multiple medium-severity vulnerabilities into realistic attack scenarios to demonstrate critical business impact.  
  • Evaluate the real-world exploitability of vulnerabilities within production environments and prioritize remediation accordingly.  
  • Develop Proof of Concept (PoC) exploits to validate risks and demonstrate security impact.  

 

Security Process & Team Leadership 

  • Design and optimize streamlined Pentest and Vulnerability Management processes focused on:  
  • Detection  
  • Validation  
  • Exploitation  
  • Remediation Tracking  
  • Establish security testing standards and execution checklists tailored for different product lines and systems.  
  • Collaborate with Engineering, DevOps, and Product teams to strengthen secure software development lifecycle (SSDLC) practices.  
  • Lead internal workshops, Capture The Flag (CTF) activities, and hands-on security training sessions to help developers understand offensive security techniques and secure coding practices.  
  • Promote a proactive security culture across the organization.  

 

Reporting & Remediation 

  • Produce detailed security assessment reports including:  
  • Root Cause Analysis  
  • Proof of Concept (PoC)  
  • Risk Assessment  
  • Remediation Recommendations  
  • Sample Remediation Code  
  • Track remediation progress and provide technical consultation to development teams.  
  • Prioritizing vulnerabilities based on practical business risk and exploitability rather than theoretical severity alone.  

 

REQUIREMENT 

  • Minimum 8 years of experience in Offensive Security, Penetration Testing, Application Security, or related cybersecurity fields.  
  • Strong hands-on experience with:  
  • Web & API Penetration Testing  
  • Cloud Security  
  • Container Security  
  • CI/CD Security  
  • Vulnerability Management  
  • Proficiency with tools such as: Burp Suite ,Metasploit ,Nmap ,Nuclei ,Nessus ,OWASP ZAP  
  • Solid scripting/programming skills in Python, Go, Bash, or similar languages for automation and exploit development.  
  • Experience securing Infrastructure-as-Code environments such as Terraform and Ansible.  
  • Strong analytical thinking, problem-solving, and attacker mindset.  
  • Excellent communication and stakeholder management skills.  
  • Ability to mentor teams and drive security awareness across Engineering organizations.  

 

Nice to Have 

  • Experience building DevSecOps or Continuous Security Testing frameworks.  
  • Hands-on experience in Red Team operations or Bug Bounty programs.  
  • Experience working in SaaS, Product, or Technology companies.  
  • AWS certifications are highly preferred.  
  • Other Security certifications such as (Nice to Have): OSCP, OSEP 
  • Hands-on experience with Kubernetes Security

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.