Based in Vietnam

Quality engineering,
tested with an offensive mindset.

QA Automation Engineer & Penetration Tester

I build reliable automation systems and perform authorized security testing across web, API, and mobile applications.

05Public engineering repositories
131Verification tests across public projects
03Automation surfaces: API, web, and mobile
CPTSCandidate — exam preparation in progress
01Experience

From product testing to quality and security engineering.

A concise career timeline focused on responsibilities, engineering contribution, and progression.

01

July 2024 — Present

GTEL OTS

QA Automation Engineer · Penetration Testing

Engineering quality and security across enterprise web, API, Android, and iOS systems.

  • Designed reusable automation foundations and product-level suites across API, browser, Android, and iOS.
  • Improved CI execution through parallel distribution, aggregated reporting, and actionable failure evidence.
  • Performed authorized web, API, and mobile security assessments with reproducible findings and remediation verification.
  • Automated specialized geospatial, GPS, route, map-rendering, and high-volume data validation workflows.
Automation ArchitectureEnterprise QAApplication SecurityCI/CD
02

March 2024 — May 2024

Nexon

Manual QA Tester

Built a practical foundation in product quality through hands-on manual testing and defect communication.

  • Executed functional, regression, and exploratory testing against product behavior and requirements.
  • Documented reproducible defects with clear steps, evidence, and expected-versus-actual results.
  • Collaborated with the delivery team to validate fixes and support release confidence.
Manual TestingRegression TestingExploratory TestingDefect Reporting
02Selected work

Evidence before adjectives.

A focused view of the systems, assessments, and specialized workflows that best represent how I work.

01Quality architecture

Reusable automation across three delivery surfaces

Designed domain-neutral foundations for API, browser, Android, and iOS testing without embedding product workflows in framework code.

  • Configuration-driven execution and environment validation
  • Dynamic locator strategies with clear diagnostic failures
  • Isolated parallel runs with evidence and report generation
REST AssuredPlaywrightAppiumJavaCI/CD
02Authorized security testing

Enterprise web, API, and mobile assessments

Mapped application attack surfaces, tested authorization and business logic, built focused validation scripts, and documented reproducible evidence for engineering teams.

  • Authentication, JWT, SSO, IDOR/BOLA, RBAC, and workflow testing
  • Client-side, API, mobile, MQTT, and infrastructure analysis
  • Technical reporting with impact, evidence, and remediation guidance
Burp SuiteOWASPPythonNmapMobile
03Specialized quality engineering

Geospatial and high-volume data validation

Automated route, coordinate, GPS, GeoJSON, map-rendering, and bulk dataset checks across APIs, browsers, and reporting workflows.

  • Cross-system comparison of location and route data
  • Browser rendering and network-response verification
  • Excel-driven processing with traceable result evidence
GeoJSONJTSPlaywrightApache POIMaps
03Capabilities

Two disciplines. One practical standard.

Automation verifies expected behavior at scale. Penetration testing examines what happens when the system is used in unexpected ways.

01

Quality Engineering

Reliable automation systems that stay reusable when products, environments, and teams change.

  • Automation framework architecture
  • API contract and workflow testing
  • Playwright browser automation
  • Appium for Android and iOS
  • Dynamic locator and component design
  • Parallel CI and failure diagnostics
  • Data and geospatial validation
02

Offensive Security

Authorized, evidence-led security testing focused on exploitable behavior and useful remediation.

  • Web and API penetration testing
  • Mobile application assessment
  • Authentication and authorization
  • Business-logic vulnerability testing
  • Network enumeration and traffic analysis
  • Source and client-side analysis
  • Finding validation and reporting
04Hands-on practice

Learning that leaves evidence.

Structured notes, repeatable labs, custom utilities, and engagement work support an ongoing HTB CPTS preparation path.

55

Structured topic notes

Across hands-on TryHackMe learning paths

26

Documented exercises

Custom tooling, Juice Shop, and privilege escalation

08

HTB challenges

Web, reversing, hardware, and satellite categories

54

Network documents

From packet flow and routing to TLS and LAN attacks

05Credentials & recognition

Progress, backed by practice.

Formal training, an active security certification path, and professional recognition that support the work shown above.

CertificateCompleted

Software Testing

FPT Software Academy

Foundational training in software testing, test design, execution, defect reporting, and quality assurance practices.

Certification journeyIn progress

HTB CPTS

Hack The Box Academy

Preparing for the Certified Penetration Testing Specialist exam through structured study, labs, methodology, and authorized assessment work.

View public profile
06Open source

Public projects, built to be inspected.

Five focused repositories demonstrate framework design, testability, safety controls, and technical documentation.

01Quality Engineering

API Framework

A reusable REST API automation foundation with secure configuration, request specifications, authentication lifecycle, validation, and reporting.

JavaREST AssuredTestNG
View repository
02Quality Engineering

Playwright Framework

A domain-neutral browser automation framework with logical locators, component scope, isolated contexts, and failure evidence.

JavaPlaywrightCucumber
View repository
03Quality Engineering

Appium Framework

A cross-platform mobile test architecture with Android and iOS adapters, dynamic selectors, device configuration, and lifecycle control.

JavaAppiumAndroid / iOS
View repository
04Security Engineering

Burp Safe Agent

Safety-aware automation for authorized Burp workflows with explicit scope gates, mutation controls, audit trails, and redaction.

PythonBurp SuiteMCP
View repository
05Security Engineering

VulnRadar

A local vulnerability intelligence workflow combining NVD, CISA KEV, CVSS, and EPSS signals for practical prioritization.

PythonSQLiteCISA KEV
View repository
07Working principles

What the work should do.

  1. 01Make failures explain themselves.
  2. 02Keep framework code independent from product code.
  3. 03Use automation to scale judgment, not replace it.
  4. 04Treat scope, evidence, and reporting as part of security testing.

08Contact

Building quality—or testing its limits?

I am always interested in practical engineering conversations around automation architecture, application security, and the space where they meet.