Penetration Tester

3 weeks ago


Lahore, Punjab, Pakistan HR Ways Full time

Our client company is the top listed studio working in AR and VR.

Job Description:

We are seeking a highly skilled and motivated Penetration Tester to join our dynamic security team. The ideal candidate will possess deep expertise in exploit development, reverse engineering, or OPSEC and a wide range of penetration testing domains including Cloud, Web 2.0 and 3.0 Applications, Network, AI, and API security. This role involves identifying vulnerabilities, assessing risks, and providing actionable recommendations to enhance the security posture of our organization.

Responsibilities:

  • Develop and deploy custom exploits for identified vulnerabilities.
  • Research and stay updated with the latest exploit techniques and methodologies.
  • Contribute to the development of in-house tools for exploitation and vulnerability assessment.
  • Perform static and dynamic analysis of binaries and source code.
  • Develop tools and scripts to automate reverse engineering tasks.
  • Conduct security assessments of cloud infrastructure and services (AWS, Azure, GCP).
  • Identify misconfigurations and vulnerabilities in cloud environments.
  • Provide recommendations for securing cloud architectures and deployments.
  • Perform thorough security assessments of web and mobile applications.
  • Identify and exploit vulnerabilities such as SQL injection, XSS, CSRF, and authentication flaws.
  • Collaborate with development teams to remediate identified issues.
  • Conduct internal and external network penetration tests.
  • Identify and exploit vulnerabilities in network protocols, services, and configurations.
  • Assess the security of network devices such as routers, switches, and firewalls.
  • Perform detailed security assessments of web applications and services.
  • Identify common Web vulnerabilities (OWASP Top 10) and provide remediation guidance.
  • Utilize both automated tools and manual techniques for comprehensive testing.
  • Assess the security of RESTful and SOAP APIs.
  • Identify and exploit vulnerabilities in API endpoints and data handling processes.
  • Provide recommendations for secure API design and implementation.
  • Adhere to industry standards and methodologies such as OWASP, NIST, OSSTMM and ISO for penetration testing.
  • Develop and maintain comprehensive documentation and reports for security assessments.
  • Stay current with the latest trends, tools, and techniques in penetration testing and cybersecurity.

Requirements:

  • Critical Thinking and approach of thinking outside the box.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field.
  • Relevant certifications (e.g. OSCP, OSWE, CTRO, CTRP, CPTS, ASCP, or eCPPT) are highly desirable.
  • Proven experience in exploit development and reverse engineering or OPSEC.
  • Strong understanding of cloud security principles and practices.
  • Extensive knowledge of web technologies, network protocols, and application security.
  • Experience with penetration testing tools such as Metasploit, Burp Suite, Nmap, Wireshark, C2 frameworks and others.
  • Able to describe technical findings in a high-level summary and present it to stakeholders.
  • Excellent analytical and problem-solving skills.
  • Willing to learn new concepts of cybersecurity and adopt a cybersecurity mindset.

Good to Have:

  • Basic understanding of Secure SDLC and DevSecOps.
  • Experience in Web 3.0 security testing, including smart contract security assessments and decentralized application (dApp) penetration testing.
  • Strong understanding of Solidity security best practices and Ethereum Virtual Machine (EVM) vulnerabilities, such as reentrancy, integer overflow/underflow, and access control flaws.
  • Familiarity with blockchain security frameworks, auditing tools (e.g., Slither, Mythril, Echidna), and best practices for securing smart contracts and Layer 2 solutions.
  • Knowledge of AI/LLM security risks based on OWASP Top 10 for LLM Applications, including prompt injection, data leakage, model manipulation, and adversarial attacks.
  • Hands-on experience with LLM red teaming and securing AI-driven applications against evolving threats.

Other Details:

Working Timings: Monday to Friday 9:30 am - 6:30 pm
Location: DHA Phase 6 Lahore
Experience: 2-3 years

- Medical Insurance for the Employee and the family
- 22 Leaves
- Annual Increment
- Performance-based Bonus

#J-18808-Ljbffr

  • Lahore, Punjab, Pakistan beBee Careers Full time

    Are you looking for a challenging and rewarding career in cybersecurity?We have an exciting opportunity for a highly skilled Penetration Tester to join our team.About the RoleThis role involves identifying vulnerabilities, assessing risks, and providing actionable recommendations to enhance the security posture of our organization.The ideal candidate will...


  • Lahore, Punjab, Pakistan beBee Careers Full time

    We are seeking a highly skilled Penetration Tester to enhance the security posture of our organization. This role involves identifying vulnerabilities, assessing risks, and providing actionable recommendations.Key Responsibilities:Develop custom exploits for identified vulnerabilities using advanced techniques and methodologies.Research and stay updated with...


  • Lahore, Punjab, Pakistan beBee Careers Full time

    About the JobWe are seeking an experienced Red Team Cyber Security Expert to join our security team and play a crucial role in identifying, exploiting, and reporting vulnerabilities across our IT infrastructure.Key ResponsibilitiesConduct full-scope penetration testing of networks, applications, cloud environments, and physical security.Simulate Advanced...


  • Lahore, Punjab, Pakistan HR Ways Full time

    About the company we're hiring for Currently:The company is an AI fintech platform revolutionizing the music industry by providing private equity tools for music.About the RoleWe are looking for an experienced Red Team Cyber Security Expert to join our security team and play a crucial role in identifying, exploiting, and reporting vulnerabilities across our...


  • Lahore, Punjab, Pakistan beBee Careers Full time

    Secure Our Digital FutureWe are seeking a skilled Application Security Engineer to join our team. In this role, you will play a critical part in ensuring the security and integrity of our applications.About the RoleAs an Application Security Engineer, you will be responsible for improving our application security posture and maintaining a secure platform...


  • Lahore, Punjab, Pakistan beBee Careers Full time

    Secure Software Engineering RoleEon, a pioneer in patient management and incidental tracking, leverages AI to empower healthcare enterprises. Our mission is to enhance patient health and make healthcare more accessible.We drive adherence to care pathways, increasing patient care and survival, when patients succeed, healthcare systems benefit both clinically...


  • Lahore, Punjab, Pakistan Eon Full time

    Join to apply for the Application Security Engineer role at Eon23 hours ago Be among the first 25 applicantsJoin to apply for the Application Security Engineer role at EonGet AI-powered advice on this job and more exclusive features.Work with the industry leaderAt Eon, our mission is to make patients healthier and healthcare more affordable. Eon Patient...


  • Lahore, Punjab, Pakistan Eonhealth Full time

    Work with the industry leaderAt Eon, our mission is to make patients healthier and healthcare affordable. Eon Patient Management ("EPM") identifies patients with disease risk and streamlines clinical decision analysis so clinicians can work at the top of their licenses. With unique solutions across multiple disease states, we drive unprecedented adherence to...