Coinhako is hiring a Security Engineering Intern, Red Team in Security — Vietnam. The overview below is synthesized from the employer posting on jobs.ashbyhq.com: factual requirements and scope are preserved, but prose is rewritten with editorial context. Verify details and apply via the employer link.
Are you ready to be the first line of offense for one of the fastest-growing companies in the Cryptocurrency and Blockchain space? We're looking for a Security Engineering Intern (Red Team Sector) to think like an adversary, break things before attackers do, and help us build a platform our users can trust with their assets.
In crypto, every vulnerability has an immediate, irreversible dollar value attached. That's the bar you'll be operating at.
What you'll be doing
- Offensive security engagements across our web, mobile, API, and microservice surfaces, as well as cloud infrastructure and internal systems.
- Perform application security assessments and penetration tests, with a focus on the attack paths that matter most in a crypto/fintech context: authentication and session handling, wallet and key management flows, transaction integrity, withdrawal and KYC bypasses, business logic abuse, and privilege escalation.
- Conduct manual secure code review on production codebases to find vulnerabilities that scanners miss, with particular attention to financial logic, race conditions, and trust-boundary violations.
- Research emerging threats in Web3, mobile, and cloud — new exploitation techniques, smart contract attack patterns, DeFi exploits, supply chain attacks — and translate them into proactive testing methodologies before they hit production.
- Write robust scripts, automate offensive workflows, and create frameworks that scale red team coverage across a fast-moving codebase.
What we're looking for
- Knowledges in offensive security, penetration testing, or red teaming, with demonstrated hands-on experience in web and mobile application security, through CTF competition or bug bounty engagement.
- Final year at university with degree focusing on Computer Science, Information Systems, Engineering.
- Strong fundamentals in offensive security, application security, and security engineering.
- Strong familiarity with Linux and cloud ecosystems, especially AWS.
- Proficiency with industry-standard tooling: Burp Suite, intercepting proxies, fuzzers, and the broader pentester's toolkit.
- Working knowledge of OWASP (Top 10, ASVS, MASVS), CWE, and modern appsec frameworks.
- A builder's mindset; comfortable scripting and automating in Python, Go, or similar to scale your own work.
- Outstanding written and verbal communication in English, the ability to distill technical nuance into narratives that drive engineering and business change.
- A collaborative spirit, eager to work alongside engineers, researchers, and product teams to embed security into every phase of development.
- Advanced understanding and/or experience working in a Cryptocurrency/Blockchain/Fintech/Finance Trading domain preferred
What’s in it for you
- Hands-on experience across multiple cybersecurity domains
- Mentorship from experienced security professionals
- Exposure to enterprise-grade security tools and technologies
- Opportunity to participate in real security operations and projects
- Potential pathway to full-time employment based on performance
- Flexible schedule to accommodate academic commitments
Duration 3-6 months, with possibility of extension based on performance and mutual agreement.
Find out more about Coinhako here https://www.coinhako.com/ and don't forget to visit our Careers Page https://www.coinhako.com/join-us
By submitting your application to us, you consent to the collection, use, disclosure and processing of your personal data in accordance with our privacy policy, which is accessible at https://www.coinhako.com/legal/sg-1/privacy_policy.
Build a standout application
For the Security Engineering Intern, Red Team at Coinhako, reviewers look for concise evidence over buzzwords. Mirror the language of the posting sparingly, quantify support or delivery outcomes, and show how you handled ambiguity, time-zone collaboration and user empathy. Keep your resume to impact, keep your cover note to one page, and link to artifacts — tickets resolved, docs shipped, dashboards owned — that prove you can operate in a fast-moving Web3 team. Prepare to discuss a time you turned a confusing user report into a clear fix and how you measure quality in support and operations.
Web3 hiring values reliability: on-time follow-through, clear writing, and a track record of improving runbooks and tooling. Treat the application as a work sample. For interviews, be ready to walk through how you prioritize across time zones, handle a difficult user, and decide when to escalate versus resolve directly. Show how you document decisions so the next teammate benefits.
In a distributed Web3 org, trust builds through written clarity. Use the cover note to demonstrate it.
