> Back to Jobs

Penetration Tester

Posted on Jul 29, 2026

Title

Penetration Tester

Apply before

Aug 31, 2026

City

Lahore

Responsibilities

Summary of Job Profile:

The Penetration Tester is responsible for identifying and assessing security vulnerabilities across applications, networks, and systems by performing controlled security assessments and simulated attacks. The role involves using industry-standard tools and methodologies to identify weaknesses, validate vulnerabilities, prepare detailed reports, and support remediation activities. The ideal candidate should have a strong foundation in ethical hacking concepts, penetration testing techniques, and security best practices.

Essential Duties & Responsibilities:

  • Conduct penetration testing activities on web applications, networks, APIs, and systems under defined testing scopes.
  • Perform vulnerability assessments and security reviews to identify potential security risks.
  • Utilize manual and automated penetration testing tools to identify and validate vulnerabilities.
  • Perform reconnaissance, vulnerability analysis, exploitation, and post-exploitation activities as part of security assessments.
  • Identify common vulnerabilities including OWASP Top 10, misconfigurations, authentication issues, and security weaknesses.
  • Prepare clear and detailed penetration testing reports including findings, risk ratings, evidence, and remediation recommendations.
  • Communicate technical findings effectively with security teams, developers, and relevant stakeholders.
  • Assist development and infrastructure teams in validating security fixes and remediation efforts.
  • Maintain knowledge of current vulnerabilities, attack techniques, and penetration testing methodologies.
  • Assist in improving penetration testing processes, checklists, and documentation.
  • Support security assessments, vulnerability management activities, and compliance-related security testing.
  • Maintain confidentiality and follow ethical hacking guidelines during all testing activities. 
  • Document testing procedures, findings, and lessons learned

Requirements

Knowledge, Skills, Abilities (KSA’s) required to successfully perform the job:

Knowledge:

  • Good understanding of common vulnerabilities, attack vectors, and exploitation techniques.
  • Knowledge of OWASP Top 10 vulnerabilities and web application security concepts.
  • Understanding of network protocols, operating systems, and basic system architecture.
  • Familiarity with penetration testing methodologies such as PTES and OWASP Testing Guide.
  • Hands-on knowledge of penetration testing tools such as:
    • Burp Suite
    • Nmap
    • Metasploit
    • Kali Linux tools
    • Nessus/OpenVAS
    • Wireshark
  • Basic understanding of scripting/programming languages such as Python, Bash, or PowerShell.
  • Understanding of security concepts including authentication, authorization, encryption, and access controls.
  • Awareness of security best practices and system hardening techniques.

Skills:

  • Ability to perform penetration testing on web applications, networks, and APIs.
  • Good technical skills in vulnerability identification and exploitation.
  • Ability to use penetration testing tools effectively.
  • Ability to create professional vulnerability assessment and penetration testing reports.
  • Strong analytical and problem-solving skills.
  • Ability to work independently and collaborate with security and technical teams.
  • Good attention to detail when analyzing security weaknesses.
  • Ability to research and learn new vulnerabilities and attack techniques.

Abilities:

  • Ability to think from an attacker’s perspective to identify security weaknesses.
  • Ability to analyze systems and applications for potential vulnerabilities.
  • Ability to reproduce and validate security findings.
  • Ability to explain technical issues to both technical and non-technical stakeholders.
  • Ability to manage multiple testing tasks and meet deadlines.
  • Ability to maintain confidentiality and professional ethics.
  • Ability to continuously improve technical knowledge in cybersecurity. 

Education, Experience, Licensure, Certification required for the position:

  • Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field.
  • 1–2 years of experience in penetration testing, vulnerability assessment, or a related cybersecurity role.
  • Practical experience with web application, network, and API security testing. 
  • Relevant certifications are preferred, such as: CEH, eJPT, Security+, PNPT,OSCP (added advantage) 

Competencies required to successfully perform the job:

Technical Competencies

Behavioral/General Competencies

1. Web, network, and API penetration testing

2. Vulnerability Assessment & Reporting

3. Penetration Testing Tools (Burp Suite, Nmap, Metasploit, Kali Linux)

4. Security Testing Methodologies

5. Basic Scripting (Python/Bash/PowerShell)

1. Analytical Thinking

2. Problem Solving

3. Attention to Detail

4. Communication Skills

5. Learning & Adaptability

Benefits

  • Excellent Salary
  • Fuel Allowance
  • Medical Insurance
  • Annual Leaves
  • Provident Fund
  • EOBI