Penetration Tester
Title
Penetration Tester
Apply before
Aug 31, 2026
City
Lahore
Responsibilities
Summary of Job Profile:
The Penetration Tester is responsible for identifying and assessing security vulnerabilities across applications, networks, and systems by performing controlled security assessments and simulated attacks. The role involves using industry-standard tools and methodologies to identify weaknesses, validate vulnerabilities, prepare detailed reports, and support remediation activities. The ideal candidate should have a strong foundation in ethical hacking concepts, penetration testing techniques, and security best practices.
Essential Duties & Responsibilities:
- Conduct
penetration testing activities on web applications, networks, APIs, and
systems under defined testing scopes.
- Perform
vulnerability assessments and security reviews to identify potential security
risks.
- Utilize
manual and automated penetration testing tools to identify and validate
vulnerabilities.
- Perform
reconnaissance, vulnerability analysis, exploitation, and
post-exploitation activities as part of security assessments.
- Identify
common vulnerabilities including OWASP Top 10, misconfigurations,
authentication issues, and security weaknesses.
- Prepare
clear and detailed penetration testing reports including findings, risk
ratings, evidence, and remediation recommendations.
- Communicate
technical findings effectively with security teams, developers, and
relevant stakeholders.
- Assist
development and infrastructure teams in validating security fixes and
remediation efforts.
- Maintain
knowledge of current vulnerabilities, attack techniques, and penetration
testing methodologies.
- Assist
in improving penetration testing processes, checklists, and documentation.
- Support
security assessments, vulnerability management activities, and
compliance-related security testing.
- Maintain confidentiality and follow ethical hacking guidelines during all testing activities.
- Document testing procedures, findings, and lessons learned
Requirements
Knowledge, Skills, Abilities (KSA’s) required to successfully perform the job:
Knowledge:
- Good understanding of common
vulnerabilities, attack vectors, and exploitation techniques.
- Knowledge of OWASP Top 10
vulnerabilities and web application security concepts.
- Understanding of network protocols,
operating systems, and basic system architecture.
- Familiarity with penetration testing
methodologies such as PTES and OWASP Testing Guide.
- Hands-on knowledge of penetration
testing tools such as:
- Burp Suite
- Nmap
- Metasploit
- Kali Linux
tools
- Nessus/OpenVAS
- Wireshark
- Basic understanding of
scripting/programming languages such as Python, Bash, or PowerShell.
- Understanding of security concepts
including authentication, authorization, encryption, and access controls.
- Awareness of security best practices and
system hardening techniques.
Skills:
- Ability to perform penetration testing
on web applications, networks, and APIs.
- Good technical skills in vulnerability
identification and exploitation.
- Ability to use penetration testing tools
effectively.
- Ability to create professional
vulnerability assessment and penetration testing reports.
- Strong analytical and problem-solving
skills.
- Ability to work independently and
collaborate with security and technical teams.
- Good attention to detail when analyzing
security weaknesses.
- Ability to research and learn new
vulnerabilities and attack techniques.
Abilities:
- Ability to think from an attacker’s
perspective to identify security weaknesses.
- Ability to analyze systems and
applications for potential vulnerabilities.
- Ability to reproduce and validate
security findings.
- Ability to explain technical issues to
both technical and non-technical stakeholders.
- Ability to manage multiple testing tasks
and meet deadlines.
- Ability to maintain confidentiality and professional ethics.
- Ability to continuously improve technical knowledge in cybersecurity.
Education, Experience, Licensure, Certification required for the position:
- Bachelor's degree in Computer
Science, Information Security, Cybersecurity, or a related field.
- 1–2 years of experience in
penetration testing, vulnerability assessment, or a related cybersecurity
role.
- Practical experience with web application, network, and API security testing.
- Relevant certifications are preferred, such as: CEH, eJPT, Security+, PNPT,OSCP (added advantage)
|
Competencies
required to successfully perform the job: |
|
|
Technical Competencies |
Behavioral/General Competencies |
|
1.
Web, network, and API penetration testing 2.
Vulnerability Assessment & Reporting 3.
Penetration Testing Tools (Burp Suite, Nmap, Metasploit, Kali Linux) 4.
Security Testing Methodologies 5.
Basic Scripting (Python/Bash/PowerShell) |
1.
Analytical Thinking 2.
Problem Solving 3.
Attention to Detail 4.
Communication Skills 5.
Learning & Adaptability |
Benefits
- Excellent Salary
- Fuel Allowance
- Medical Insurance
- Annual Leaves
- Provident Fund
- EOBI