Central Retail logo

Senior Penetration Tester

Central Retail โ€ข Bangkok, Thailand

onsitefull-time
Posted Aug 31, 2026Apply by Sep 30, 2026

**Role & seniority: ** Application Security / Penetration Tester (security subject matter expertise; senior/independent expected due to SME + incident response + training)

**Stack/tools: **

  • Web/API/mobile security testing: Burp Suite, OWASP ZAP

  • Recon/vuln scanning: Nmap, Nessus

  • Methodologies: OWASP Testing, Agile processes

  • Security concepts: browser security model, cryptography, network security

  • Testing approaches: automated + manual, static/dynamic analysis, penetration testing, IDS

  • Scripting/programming: basic PHP / Python / Node.js

  • Top 3 responsibilities:

    1. Conduct penetration testing across web apps, mobile apps, APIs, OS, and networks

    2. Produce and communicate professional reports/presentations to technical and non-technical audiences

    3. Improve security via CI/CD automation for vulnerability discovery and engineering guidance (design input/code review, secure coding guidelines)

  • Must-have skills:

    • Excellent English (written/spoken)

    • Agile knowledge

    • OWASP testing methodology and understanding of attacks/countermeasures

    • Strong web vulnerability identification/protection experience

    • Ability to explain vulnerabilities/risk clearly

    • Familiarity with relevant security tools and security testing techniques

    • Understanding of cryptography, browser security, network security, mobile security

  • Nice-to-haves:

Full Description

Required Skills

  • Excellent Spoken and Written English.
  • Knowledge of Agile Development processes
  • Knowledge of OWASP Testing Methodology
  • Familiar with application security attacks and countermeasures.
  • Familiar with both automated and manual assessment techniques.
  • Comfortable explaining technical vulnerabilities and risks to both technical and non-technical audiences.
  • In-depth experience identifying and protecting against web application vulnerabilities.
  • Experience with various application and infrastructure security tools and products (Burp Suite, Nmap, Nessus, and OWASP ZAP).
  • Strong knowledge of browser security model, mobile app security, cryptography, and network security.
  • Experience with security tools for static analysis, dynamic analysis, penetration testing, intrusion detection.
  • Basic programing ability, ideally with PHP, Python, or Node.js.

Educational Qualifications (Desirable)

  • GIAC Penetration Tester (GPEN)
  • CompTIA PenTest+
  • Offensive Security Certified Professional (OSCP)
  • Burp Suite Certified Practitioner

Roles and Responsibilities

  • Perform penetration testing on web applications, mobile applications, APIs, operating systems, and network infrastructure.
  • Generate and deliver professional penetration testing reports and presentations.
  • Implement automation for finding vulnerabilities in CI/CD process.
  • Improving data security through use of encryption/key management, segregation, or other techniques.
  • Helping engineers design more secure systems via design input and code review.
  • Develop secure coding guidelines.
  • Deliver web application security training to developers.
  • Be a security subject matter expert and respond to any internal security engineering questions/request.
  • Perform reactive incident response when a security event occurs.
  • Perform proactive research to detect new attack vectors
  • Perform periodic testing of defensive controls through red/purple teaming engagements
  • Serve as a subject matter expert in all things related to vulnerability management.
Penetration TestingOWASP Testing MethodologyWeb Application SecurityMobile App SecurityBurp SuiteNmapNessusOWASP ZAPCryptographyNetwork SecurityStatic AnalysisDynamic AnalysisPHPPythonNode.jsIncident Responsemulti-location

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.