Based in Vietnam
Quality engineering, tested with an offensive mindset. QA Automation Engineer & Penetration Tester
I build reliable automation systems and perform authorized security testing across web, API, and mobile applications.
Engineering focus 01 / 02
01 Quality Engineering Architecture · Automation · Evidence
shared context
02 Offensive Security Discovery · Validation · Reporting
Across web, API, Android, and iOS, I build repeatable checks, probe authorization and business logic, and report reproducible evidence.
05 Public engineering repositories
131 Verification tests across public projects
03 Automation surfaces: API, web, and mobile
CPTS Candidate — exam preparation in progress
01 Experience
From product testing to quality and security engineering. A concise career timeline focused on responsibilities, engineering contribution, and progression.
01
July 2024 — Present
GTEL OTS QA Automation Engineer · Penetration Testing Engineering quality and security across enterprise web, API, Android, and iOS systems.
Designed reusable automation foundations and product-level suites across API, browser, Android, and iOS. Improved CI execution through parallel distribution, aggregated reporting, and actionable failure evidence. Performed authorized web, API, and mobile security assessments with reproducible findings and remediation verification. Automated specialized geospatial, GPS, route, map-rendering, and high-volume data validation workflows. Automation Architecture Enterprise QA Application Security CI/CD
02
March 2024 — May 2024
Nexon Manual QA Tester Built a practical foundation in product quality through hands-on manual testing and defect communication.
02 Open source
Public projects, built to be inspected. Five focused repositories demonstrate framework design, testability, safety controls, and technical documentation.
01 Quality Engineering
API Framework A reusable REST API automation foundation with secure configuration, request specifications, authentication lifecycle, validation, and reporting.
Java REST Assured TestNG
View repository 02 Quality Engineering
Playwright Framework A domain-neutral browser automation framework with logical locators, component scope, isolated contexts, and failure evidence.
Java Playwright Cucumber
View repository 03 Quality Engineering
Appium Framework A cross-platform mobile test architecture with Android and iOS adapters, dynamic selectors, device configuration, and lifecycle control.
Java Appium Android / iOS
View repository 04 Security Engineering
Burp Safe Agent A human-in-the-loop Burp Community assistant with dual-layer scope gates, mutation approval, secret redaction, audit logging, and mandatory manual verification.
Python Burp Suite MCP
View repository 05 Security Engineering
VulnRadar A local-first CLI that deduplicates NVD and CISA KEV records, applies explainable KEV/CVSS/EPSS scoring, and produces searchable SQLite digests.
Python SQLite CISA KEV
View repository 03 Hands-on practice
Learning that leaves evidence. Structured notes, repeatable labs, custom utilities, and engagement work support an ongoing HTB CPTS preparation path.
55 Structured topic notes Substantive notes across six TryHackMe learning paths
28 Learning-lab scripts Python artifacts for WebGoat and custom TryHackMe labs
08 HTB challenge write-ups Five web, one reversing, one hardware, and one satellite
18 Substantive network notes Packet flow, routing, TLS, hardening, and LAN attacks
View TryHackMe profile 04 Credentials
Progress, backed by practice. Formal training and an active security certification path that support the work shown above.
Certificate Completed
Software Testing FPT Software Academy
Foundational training in software testing, test design, execution, defect reporting, and quality assurance practices.
Issued 15 January 2024
Certification journey In progress
HTB CPTS Hack The Box Academy
Preparing for the Certified Penetration Testing Specialist exam through structured study, labs, methodology, and authorized assessment work.
View public profile