Security Engineering Intern, Red Team at CoinHako answer
Is this job still open?
GMI Jobs is currently showing this Security Engineering Intern, Red Team role at CoinHako as an active listing from employer-controlled hiring sources. Always confirm final availability on the employer application page before applying.
How do I apply for this role?
Use the application link on this page to apply directly with CoinHako. GMI Jobs keeps the canonical job page, company context, and market links together so candidates can compare before leaving the site.
What should I compare before applying?
Compare the role location Vietnam, any listed pay signal, company profile, related crypto jobs, and salary context before applying. Listed pay signals are not guaranteed offers; confirm compensation with the employer.
Job Description
<p style="min-height:1.5em">Are you ready to be the first line of offense for one of the fastest-growing companies in the Cryptocurrency and Blockchain space? We're looking for a <strong>Security Engineering Intern (Red Team Sector)</strong> to think like an adversary, break things before attackers do, and help us build a platform our users can trust with their assets.<br />In crypto, every vulnerability has an immediate, irreversible dollar value attached. That's the bar you'll be operating at.</p><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>What you'll be doing:</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Offensive security engagements across our web, mobile, API, and microservice surfaces, as well as cloud infrastructure and internal systems.</p></li><li><p style="min-height:1.5em">Perform application security assessments and penetration tests, with a focus on the attack paths that matter most in a crypto/fintech context: authentication and session handling, wallet and key management flows, transaction integrity, withdrawal and KYC bypasses, business logic abuse, and privilege escalation.</p></li><li><p style="min-height:1.5em">Conduct manual secure code review on production codebases to find vulnerabilities that scanners miss, with particular attention to financial logic, race conditions, and trust-boundary violations.</p></li><li><p style="min-height:1.5em">Research emerging threats in Web3, mobile, and cloud — new exploitation techniques, smart contract attack patterns, DeFi exploits, supply chain attacks — and translate them into proactive testing methodologies before they hit production.</p></li><li><p style="min-height:1.5em">Write robust scripts, automate offensive workflows, and create frameworks that scale red team coverage across a fast-moving codebase.</p></li></ul><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>What we're looking for:</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Knowledges in offensive security, penetration testing, or red teaming, with demonstrated hands-on experience in web and mobile application security, through CTF competition or bug bounty engagement.</p></li><li><p style="min-height:1.5em">Final year at university with degree focusing on Computer Science, Information Systems, Engineering.</p></li><li><p style="min-height:1.5em">Strong fundamentals in offensive security, application security, and security engineering.</p></li><li><p style="min-height:1.5em">Strong familiarity with Linux and cloud ecosystems, especially AWS.</p></li><li><p style="min-height:1.5em">Proficiency with industry-standard tooling: Burp Suite, intercepting proxies, fuzzers, and the broader pentester's toolkit.</p></li><li><p style="min-height:1.5em">Working knowledge of OWASP (Top 10, ASVS, MASVS), CWE, and modern appsec frameworks.</p></li><li><p style="min-height:1.5em">A builder's mindset; comfortable scripting and automating in Pyth