STH Careers
Careers at Siam Thanat Hack
We are looking for passionate individuals who love hands-on security testing and continuous learning, delivering world-class offensive security services to enterprise clients ethically and legally.
Open Positions
Penetration Tester
Join the offensive security team assessing web, mobile, and API systems for enterprise clients.
Conduct manual penetration testing and source code reviews to identify vulnerabilities across web applications, mobile apps, and APIs for leading organizations under recognized standards.
Key Responsibilities
- Perform authorized penetration testing on web applications, mobile apps (iOS and Android), and API endpoints.
- Conduct secure code reviews to discover logic and implementation flaws.
- Continuously research emerging security vulnerabilities and best-practice mitigations to advise clients.
- Produce comprehensive technical penetration test reports in English.
Qualifications and Skills
- At least 1 year of hands-on penetration testing experience.
- Proficiency in Linux, Burp Suite, and at least one programming language (Python, Go, Bash, JavaScript, or PHP).
- Solid understanding of OWASP Top 10 principles for web or mobile systems.
- Passionate about offensive security, ethical hacking, and continuous technical growth.
- Good written English skills for technical report authoring (e.g. TOEIC score 500+ or equivalent).
- Possess at least one recognized security certification (OSCP, BSCP, PenTest+, or equivalent).
- Prior participation in competitive programming or CTF challenges (ACM ICPC, Olympiad in Informatics, Thailand Cyber Top Talent) is an advantage.
Growth Opportunities
- Hands-on exposure to diverse scopes including fintech, e-KYC, and mission-critical cloud infrastructure.
- Full exam sponsorship for advanced offensive security certifications.
- Opportunity to participate in vulnerability research covering firmware, drivers, and binary exploitation.
Senior Penetration Tester
Lead complex penetration testing engagements, red team simulations, and technical mentorship.
Lead offensive security operations on complex environments, design realistic attack simulations, oversee technical report quality, and mentor team members across engagements.
Key Responsibilities
- Lead penetration testing engagements on complex microservices, cloud-native architectures, Active Directory, and AI systems.
- Design objective-based red teaming scenarios and adversary simulations aligned with the MITRE ATT&CK framework.
- Perform technical peer review of reports and ensure rigorous verification of proof-of-concept evidence.
- Develop custom tooling, exploits, and automation workflows to enhance team testing capabilities.
- Mentor team members and participate in technical debriefs with client executives and engineering leads.
Qualifications and Skills
- At least 3 to 5 years of in-depth offensive security and penetration testing experience.
- Deep technical mastery in web, mobile, cloud infrastructure, Active Directory, and advanced API security.
- Knowledge of adversary tactics, privilege escalation, binary exploitation, reverse engineering, or evasion techniques.
- Strong English communication and report authoring skills, capable of explaining complex findings clearly.
- Hold advanced certifications such as OSCP, OSEP, OSWE, CRTO, GXPN, or equivalent.
- Demonstrated track record in CTF competitions, CVE discovery, or security research publication is a significant plus.
Growth Opportunities
- Influence company-wide offensive testing methodologies and toolchains.
- Dedicated allocation for security research and custom tooling development.
- Full support for top-tier international certifications and cybersecurity conferences.
IT Security Manager
Lead specialized offensive security teams, manage engagements, and uphold ISMS governance.
Manage our offensive security team and testing engagements, oversee client relationships, and maintain rigorous compliance with ISO/IEC 27001, ISO 9001, and regulatory standards.
Key Responsibilities
- Manage penetration testing teams and client engagements to ensure timely, high-quality delivery.
- Lead capacity planning, talent development, resource allocation, and team expansion.
- Manage client relationships, resolve escalations, and support technical scoping and pre-sales.
- Govern operational workflows in compliance with ISO/IEC 27001:2022, ISO 9001:2015, and regulatory mandates (BOT, NCSA, SEC, PDPA).
- Oversee security assurance and quality control across major enterprise accounts.
Qualifications and Skills
- At least 1 to 3 years of management experience in IT or IT security teams.
- Hold at least one relevant management or security certification (CISSP, CISM, CISA, CRISC, ISO 27001, or OSCP).
- Demonstrated leadership, time management, and client communication capabilities.
- Excellent written and spoken English communication skills (TOEIC score 500+ or equivalent).
- Solid understanding of information security compliance frameworks and regulatory guidelines.
- Hands-on background in penetration testing or participation in CTF competitions is an advantage.
Growth Opportunities
- Lead an elite cybersecurity team protecting high-profile systems across Thailand.
- Collaborate directly with executive stakeholders and advance national cybersecurity standards.
- Competitive managerial compensation package with performance-based bonuses.
Benefits and Perks
We invest in career advancement, cutting-edge hardware, and the well-being of every team member.
-
Flexible Hybrid Work
Work in the office combined with 3 days of WFH per week. Convenient office near MRT Rama 9.
-
Dedicated Hardware
Dedicated company laptop and annual work-from-home electronic equipment allowance after 1 year.
-
Certifications and Training
Full sponsorship for recognized certifications (OSCP, PenTest+, CISSP) and skill development courses.
-
Research and CTF Team
Internal research projects, exploit knowledge base, and opportunities to compete in national CTF events.
-
Comprehensive Health Insurance
Group health insurance covering IPD, OPD, dental, specialist visits, life, accident, and annual health checkup.
-
Bonuses and Annual Outing
Performance bonus, annual salary review, provident fund, birthday leave, and annual overseas company outing.
How to Apply
Send your Resume, Portfolio, competition achievements, or certification records to our HR team. We will review your application and get in touch for an interview.
Apply via email: hr@sth.sh