Siam Thanat Hack Co., Ltd.

STH Careers

Full-time (Hybrid) Operational (Junior and Mid-level)

Penetration Tester

Join the offensive security team assessing web, mobile, and API systems for enterprise clients.

Illustration of an ethical hacker testing web and mobile applications

Conduct manual penetration testing and source code reviews to identify vulnerabilities across web applications, mobile apps, and APIs for leading organizations under recognized standards.

Key Responsibilities

  • Perform authorized penetration testing on web applications, mobile apps (iOS and Android), and API endpoints.
  • Conduct secure code reviews to discover logic and implementation flaws.
  • Continuously research emerging security vulnerabilities and best-practice mitigations to advise clients.
  • Produce comprehensive technical penetration test reports in English.

Qualifications and Skills

  • At least 1 year of hands-on penetration testing experience.
  • Proficiency in Linux, Burp Suite, and at least one programming language (Python, Go, Bash, JavaScript, or PHP).
  • Solid understanding of OWASP Top 10 principles for web or mobile systems.
  • Passionate about offensive security, ethical hacking, and continuous technical growth.
  • Good written English skills for technical report authoring (e.g. TOEIC score 500+ or equivalent).
  • Possess at least one recognized security certification (OSCP, BSCP, PenTest+, or equivalent).
  • Prior participation in competitive programming or CTF challenges (ACM ICPC, Olympiad in Informatics, Thailand Cyber Top Talent) is an advantage.

Growth Opportunities

  • Hands-on exposure to diverse scopes including fintech, e-KYC, and mission-critical cloud infrastructure.
  • Full exam sponsorship for advanced offensive security certifications.
  • Opportunity to participate in vulnerability research covering firmware, drivers, and binary exploitation.