Back to search
EngineeringOn-site

Security Engineering Intern, Red Team

Coinhako · On-site

Apply
Last seen by MeritLog September 10, 2026Source: AshbySource version: ashby-public-job-posting-v1

MeritLog read this listing from Coinhako's Ashby job board and last checked it on September 10, 2026.

Source: the employer's Ashby job board. Open the original listing for current details.

Job details

Work model
On-site
Salary
Not listed by source
Location
Vietnam
Company website
www.coinhako.com

Hiring context

How this role compares at Coinhako

Coinhako has 9 live roles in MeritLog’s catalog across 3 job families, and 6 of them are in engineering. 0 of those listings publish a pay range, a disclosure rate of 0%.

Coinhako concentrates this hiring in:

Counted across the job boards MeritLog tracks, at the time this page was served. Pay comparisons use only listings that publish a complete range in the same currency and period.

What the role asks for

What you'd do

  • Offensive security engagements across our web, mobile, API, and microservice surfaces, as well as cloud infrastructure and internal systems.
  • Perform application security assessments and penetration tests, with a focus on the attack paths that matter most in a crypto/fintech context: authentication and session handling, wallet and key management flows, transaction integrity, withdrawal and KYC bypasses, business logic abuse, and privilege escalation.
  • Conduct manual secure code review on production codebases to find vulnerabilities that scanners miss, with particular attention to financial logic, race conditions, and trust-boundary violations.
  • Research emerging threats in Web3, mobile, and cloud - new exploitation techniques, smart contract attack patterns, DeFi exploits, supply chain attacks - and translate them into proactive testing methodologies before they hit production.
  • Write robust scripts, automate offensive workflows, and create frameworks that scale red team coverage across a fast-moving codebase.
  • Knowledges in offensive security, penetration testing, or red teaming, with demonstrated hands-on experience in web and mobile application security, through CTF competition or bug bounty engagement.
  • Final year at university with degree focusing on Computer Science, Information Systems, Engineering.
  • Strong fundamentals in offensive security, application security, and security engineering.
  • Strong familiarity with Linux and cloud ecosystems, especially AWS.
  • Proficiency with industry-standard tooling: Burp Suite, intercepting proxies, fuzzers, and the broader pentester's toolkit.
  • Working knowledge of OWASP (Top 10, ASVS, MASVS), CWE, and modern appsec frameworks.
  • A builder's mindset; comfortable scripting and automating in Python, Go, or similar to scale your own work.
  • Outstanding written and verbal communication in English, the ability to distill technical nuance into narratives that drive engineering and business change.
  • A collaborative spirit, eager to work alongside engineers, researchers, and product teams to embed security into every phase of development.
  • Advanced understanding and/or experience working in a Cryptocurrency/Blockchain/Fintech/Finance Trading domain preferred
  • Hands-on experience across multiple cybersecurity domains
  • Mentorship from experienced security professionals
  • Exposure to enterprise-grade security tools and technologies
  • Opportunity to participate in real security operations and projects
  • Potential pathway to full-time employment based on performance
  • Flexible schedule to accommodate academic commitments

Parsed by MeritLog from the employer’s own posting. The full description follows below.

Job description

Are you ready to be the first line of offense for one of the fastest-growing companies in the Cryptocurrency and Blockchain space? We're looking for a Security Engineering Intern (Red Team Sector) to think like an adversary, break things before attackers do, and help us build a platform our users can trust with their assets. In crypto, every vulnerability has an immediate, irreversible dollar value attached. That's the bar you'll be operating at. What you'll be doing: - Offensive security engagements across our web, mobile, API, and microservice surfaces, as well as cloud infrastructure and internal systems. - Perform application security assessments and penetration tests, with a focus on the attack paths that matter most in a crypto/fintech context: authentication and session handling, wallet and key management flows, transaction integrity, withdrawal and KYC bypasses, business logic abuse, and privilege escalation. - Conduct manual secure code review on production codebases to find vulnerabilities that scanners miss, with particular attention to financial logic, race conditions, and trust-boundary violations. - Research emerging threats in Web3, mobile, and cloud - new exploitation techniques, smart contract attack patterns, DeFi exploits, supply chain attacks - and translate them into proactive testing methodologies before they hit production. - Write robust scripts, automate offensive workflows, and create frameworks that scale red team coverage across a fast-moving codebase. What we're looking for: - Knowledges in offensive security, penetration testing, or red teaming, with demonstrated hands-on experience in web and mobile application security, through CTF competition or bug bounty engagement. - Final year at university with degree focusing on Computer Science, Information Systems, Engineering. - Strong fundamentals in offensive security, application security, and security engineering. - Strong familiarity with Linux and cloud ecosystems, especially AWS. - Proficiency with industry-standard tooling: Burp Suite, intercepting proxies, fuzzers, and the broader pentester's toolkit. - Working knowledge of OWASP (Top 10, ASVS, MASVS), CWE, and modern appsec frameworks. - A builder's mindset; comfortable scripting and automating in Python, Go, or similar to scale your own work. - Outstanding written and verbal communication in English, the ability to distill technical nuance into narratives that drive engineering and business change. - A collaborative spirit, eager to work alongside engineers, researchers, and product teams to embed security into every phase of development. - Advanced understanding and/or experience working in a Cryptocurrency/Blockchain/Fintech/Finance Trading domain preferred What’s in it for you: - Hands-on experience across multiple cybersecurity domains - Mentorship from experienced security professionals - Exposure to enterprise-grade security tools and technologies - Opportunity to participate in real security operations and projects - Potential pathway to full-time employment based on performance - Flexible schedule to accommodate academic commitments Duration 3-6 months, with possibility of extension based on performance and mutual agreement. Find out more about Coinhako here https://www.coinhako.com/ and don't forget to visit our Careers Page https://www.coinhako.com/join-us By submitting your application to us, you consent to the collection, use, disclosure and processing of your personal data in accordance with our privacy policy, which is accessible at https://www.coinhako.com/legal/sg-1/privacy_policy.

Privacy choices

Analytics and advertising stay off unless you allow them. Private data stays out.

Read the privacy notice