Based in Vietnam

Quality engineering,
tested with an offensive mindset.

QA Automation Engineer & Penetration Tester

I build reliable automation systems and perform authorized security testing across web, API, and mobile applications.

Tech stack$ ls stack/

Languages

JavaLanguageTypeScriptLanguagePythonLanguage

Frameworks & Tools

PlaywrightWeb AutomationAppiumMobile AutomationREST AssuredAPI TestingJMeterPerformance TestingTestNGTest FrameworkCucumberBDDCI/CDDelivery
05Public engineering repositories
131Verification tests across public projects
03Automation surfaces: API, web, and mobile
02HTB Academy paths completed
01Experience

From product testing to quality and security engineering.

A concise career timeline focused on responsibilities, engineering contribution, and progression.

01

July 2024 — Present

GTEL OTS

QA Automation Engineer · Penetration Testing

Engineering quality and security across enterprise web, API, Android, and iOS systems.

  • Designed reusable automation foundations and product-level suites across API, browser, Android, and iOS.
  • Improved CI execution through parallel distribution, aggregated reporting, and actionable failure evidence.
  • Performed authorized web, API, and mobile security assessments with reproducible findings and remediation verification.
  • Automated specialized geospatial, GPS, route, map-rendering, and high-volume data validation workflows.
  • Testing an internal chatbot that delivers regulatory and legal (decree) information for accuracy and response reliability.
  • Delivered QA and automation coverage across large-scale public-sector platforms and enterprise HR management systems.
Automation ArchitectureEnterprise QAApplication SecurityCI/CD
02

March 2024 — May 2024

Nexon

Manual QA Tester

Built a practical foundation in product quality through hands-on manual testing and defect communication.

02Open source

Public projects, built to be inspected.

Three focused repositories demonstrate framework design, testability, safety controls, and technical documentation.

api-framework.sh

$ ./run-tests.sh api-framework

# Quality Engineering

API Framework

A reusable REST API automation foundation with secure configuration, request specifications, authentication lifecycle, validation, and reporting.

JavaREST AssuredTestNG
View repository
playwright-framework.sh

$ ./run-tests.sh playwright-framework

# Quality Engineering

Playwright Framework

A domain-neutral browser automation framework with logical locators, component scope, isolated contexts, and failure evidence.

JavaPlaywrightCucumberTypeScript
View repository
appium-framework.sh

$ ./run-tests.sh appium-framework

# Quality Engineering

Appium Framework

A cross-platform mobile test architecture with Android and iOS adapters, dynamic selectors, device configuration, and lifecycle control.

JavaAppiumAndroid / iOS
View repository
03Hands-on practice

Learning that leaves evidence.

Structured notes, repeatable labs, custom utilities, and engagement work support completed HTB Academy training.

02

HTB Academy paths completed

Completed Hack The Box Academy's Certified Penetration Testing Specialist and Web Penetration Tester learning paths

12

Reusable pentest playbooks

Condensed methodology guides for recon, web exploitation, pivoting, password attacks, and supporting techniques

55

Structured topic notes

Substantive notes across six TryHackMe learning paths

28

Learning-lab scripts

Python artifacts for WebGoat and custom TryHackMe labs

08

HTB challenge write-ups

Five web, one reversing, one hardware, and one satellite

18

Substantive network notes

Packet flow, routing, TLS, hardening, and LAN attacks

04Credentials

Progress, backed by practice.

Formal training and completed security coursework support the work shown above.

Software Testing badge
01Quality Engineering

Software Testing

Foundational training in software testing, test design, execution, defect reporting, and quality assurance practices.

FPT Software AcademyCompleted2024
Completed15 January 2024
LFD121: Developing Secure Software badge
02Security Engineering

LFD121: Developing Secure Software

Completed foundational training in secure software development, covering secure design, vulnerability handling, risk management, and security verification.

The Linux FoundationCompleted
View credential
SKF100: Understanding the OWASP® Top 10 Security Threats badge
03Security Engineering

SKF100: Understanding the OWASP® Top 10 Security Threats

Practical knowledge of the OWASP Top 10 web application risks and secure coding practices to identify and mitigate them.

The Linux FoundationCompleted
View credential
LFEL1004: Authentication & Authorization for Web/API badge
04Security Engineering

LFEL1004: Authentication & Authorization for Web/API

Hands-on training securing identity and access for web/API apps: OAuth 2.0/OIDC, SSO, RBAC, and multi-factor authentication.

The Linux FoundationCompleted
View credential
LFEL1010: XSS Exploits and Defenses badge
05Security Engineering

LFEL1010: XSS Exploits and Defenses

Hands-on training in identifying, exploiting, and mitigating reflected, stored, and DOM-based XSS vulnerabilities.

The Linux FoundationCompleted
View credential

05Contact

Building quality—or testing its limits?

I am always interested in practical engineering conversations around automation architecture, application security, and the space where they meet.

[email protected]