Job Openings
Security Engineer
About the job Security Engineer
Job Description
- Conduct penetration testing and vulnerability assessments on web, mobile, API, cloud, and internal systems.
- Simulate real-world cyberattacks to identify exploitable weaknesses.
- Provide detailed technical reports with actionable remediation guidance to development and infrastructure teams.
- Collaborate with DevSecOps, Software Engineering, and Cloud teams to integrate security into CI/CD pipelines (shift-left approach).
- Perform source code reviews and security architecture analysis as needed.
- Research the latest threats and recommend best practices to protect Gosoft's digital assets.
- Participate in red team exercises and support incident response activities.
- Ensure compliance with company policies and applicable security frameworks (e.g., OWASP, ISO 27001, NIST).
- Educate internal stakeholders on secure coding and vulnerability mitigation.
Job Qualification
- Bachelor's Degree or higher in Computer Engineering, Cybersecurity, Information Technology, or a related field.
- 0–5 years of hands-on experience in penetration testing, ethical hacking, or security assessments.
- Familiar with penetration testing tools such as Burp Suite, Metasploit, Nmap, Wireshark, and Nessus.
- Solid understanding of OWASP Top 10, CVE, CWE, and common web/mobile application vulnerabilities.
- Experience in secure coding practices and knowledge of DevSecOps principles.
- Certifications such as OSCP, CEH, or GPEN are a plus.
- Strong analytical, communication, and report-writing skills (both in Thai and English).