Based in Vietnam

Quality engineering,
tested with an offensive mindset.

QA Automation Engineer & Penetration Tester

I build reliable automation systems and perform authorized security testing across web, API, and mobile applications.

05Public engineering repositories
131Verification tests across public projects
03Automation surfaces: API, web, and mobile
CPTSCandidate — exam preparation in progress
01Experience

From product testing to quality and security engineering.

A concise career timeline focused on responsibilities, engineering contribution, and progression.

01

July 2024 — Present

GTEL OTS

QA Automation Engineer · Penetration Testing

Engineering quality and security across enterprise web, API, Android, and iOS systems.

  • Designed reusable automation foundations and product-level suites across API, browser, Android, and iOS.
  • Improved CI execution through parallel distribution, aggregated reporting, and actionable failure evidence.
  • Performed authorized web, API, and mobile security assessments with reproducible findings and remediation verification.
  • Automated specialized geospatial, GPS, route, map-rendering, and high-volume data validation workflows.
Automation ArchitectureEnterprise QAApplication SecurityCI/CD
02

March 2024 — May 2024

Nexon

Manual QA Tester

Built a practical foundation in product quality through hands-on manual testing and defect communication.

02Open source

Public projects, built to be inspected.

Five focused repositories demonstrate framework design, testability, safety controls, and technical documentation.

01Quality Engineering

API Framework

A reusable REST API automation foundation with secure configuration, request specifications, authentication lifecycle, validation, and reporting.

JavaREST AssuredTestNG
View repository
02Quality Engineering

Playwright Framework

A domain-neutral browser automation framework with logical locators, component scope, isolated contexts, and failure evidence.

JavaPlaywrightCucumber
View repository
03Quality Engineering

Appium Framework

A cross-platform mobile test architecture with Android and iOS adapters, dynamic selectors, device configuration, and lifecycle control.

JavaAppiumAndroid / iOS
View repository
04Security Engineering

Burp Safe Agent

A human-in-the-loop Burp Community assistant with dual-layer scope gates, mutation approval, secret redaction, audit logging, and mandatory manual verification.

PythonBurp SuiteMCP
View repository
05Security Engineering

VulnRadar

A local-first CLI that deduplicates NVD and CISA KEV records, applies explainable KEV/CVSS/EPSS scoring, and produces searchable SQLite digests.

PythonSQLiteCISA KEV
View repository
03Hands-on practice

Learning that leaves evidence.

Structured notes, repeatable labs, custom utilities, and engagement work support an ongoing HTB CPTS preparation path.

55

Structured topic notes

Substantive notes across six TryHackMe learning paths

28

Learning-lab scripts

Python artifacts for WebGoat and custom TryHackMe labs

08

HTB challenge write-ups

Five web, one reversing, one hardware, and one satellite

18

Substantive network notes

Packet flow, routing, TLS, hardening, and LAN attacks

View TryHackMe profile
04Credentials

Progress, backed by practice.

Formal training and an active security certification path that support the work shown above.

CertificateCompleted

Software Testing

FPT Software Academy

Foundational training in software testing, test design, execution, defect reporting, and quality assurance practices.

Issued15 January 2024

Certification journeyIn progress

HTB CPTS

Hack The Box Academy

Preparing for the Certified Penetration Testing Specialist exam through structured study, labs, methodology, and authorized assessment work.

View public profile

05Contact

Building quality—or testing its limits?

I am always interested in practical engineering conversations around automation architecture, application security, and the space where they meet.

[email protected]