Vulnerability Assessment and Penetration Testing

5 days ago


Islamabad, Islamabad, Pakistan Lendo Full time

We are seeking a hands-on and detail-oriented Vulnerability Assessment and Penetration Testing (VAPT) Specialist to lead our offensive security efforts through penetration testing and vulnerability assessments across web applications, networks, and mobile apps.

The primary responsibility of this role is to identify and validate security weaknesses through structured offensive testing, manage and interpret vulnerability scan data (e.g., Qualys), and coordinate remediation with internal teams. The role will also support our broader threat management function by staying aware of emerging threats and vulnerabilities that may impact our systems.

This is a great opportunity to join a fast-paced, security-focused FinTech organization operating under regulatory frameworks such as SAMA CSF and PDPL.

Penetration Testing

  1. Plan, execute, and document penetration tests on web applications, APIs, mobile apps, and networks.

  2. Perform manual and automated testing to uncover real-world security weaknesses (OWASP Top 10, Mobile Top 10, etc.).

  3. Deliver detailed reports with impact analysis, reproduction steps, and mitigation recommendations.

Vulnerability Management

  1. Conduct vulnerability scans using Qualys (or similar tools) on a scheduled and ad-hoc basis.

  2. Analyze and prioritize findings based on risk, business impact, and exploitability.

  3. Collaborate with IT, DevOps, and Engineering teams to ensure timely and effective remediation.

  4. Maintain metrics and dashboards to track remediation progress and vulnerability trends.

Threat Monitoring & Risk Awareness

  1. Stay up to date with zero-day vulnerabilities, CVEs, and emerging threats.

  2. Assess organizational exposure to global threat intelligence and advise relevant teams when needed.

  3. Work alongside the SOC team or MSSP to support incident investigation or escalation when testing reveals high-risk scenarios.

Collaboration & Governance

  1. Coordinate with internal teams to ensure timely patching and resolution of vulnerabilities.

  2. Provide advisory support during new infrastructure deployments or application launches.

  3. Contribute to compliance initiatives aligned with SAMA CSF, PDPL, and NCA frameworks.

Qualifications and Skills:

Required Education & Experience:

  1. Bachelor's degree in Cybersecurity, Information Security, Computer Science, or a related field.

  2. Minimum 7 years of hands-on experience in penetration testing and vulnerability management.

  3. Demonstrated experience with tools such as (but not limited to): Burp Suite, Qualys, Nessus, Nmap, MobSF, Frida, Metasploit, Wireshark, etc.

Skills & Knowledge:

  1. Deep understanding of OWASP Top 10, and secure coding flaws.

  2. Strong grasp of network architecture, web protocols, mobile platforms, and cloud environments.

  3. Familiarity with SAMA CSF, PDPL, or similar regulatory/compliance frameworks is a must.

  4. Understanding of threat modeling and attacker TTPs (MITRE ATT&CK) is a plus.

Education and Certifications:

  1. Practical certifications such as (OSCP / OSWE / CRTO / OSCE … etc.)

  2. Bonus: Any cloud security or mobile testing certifications

Personal Attributes:

  1. Excellent verbal and written communication skills in English and Arabic.

  2. Ability to convey technical findings to non-technical stakeholders.

  3. Strong analytical mindset and attention to detail.

  4. Proactive, collaborative, and passionate about continuous learning and security excellence.

#J-18808-Ljbffr

  • Islamabad, Islamabad, Pakistan Risk Associates Bahrain Full time

    Job DescriptionWe are looking for a Vulnerability Assessment Expert to join our team at Risk Associates Bahrain. In this role, you will conduct penetration testing, vulnerability assessment, and risk analysis to identify potential security threats.Key ResponsibilitiesConduct vulnerability assessments to identify security weaknesses in web/mobile applications...


  • Islamabad, Islamabad, Pakistan Lendo Full time

    Required Skills and QualificationsBachelor's degree in Cybersecurity, Information Security, Computer Science, or a related field.Minimum 7 years of hands-on experience in penetration testing and vulnerability management.Demonstrated experience with tools such as (but not limited to): Burp Suite, Qualys, Nessus, Nmap, MobSF, Frida, Metasploit, Wireshark,...


  • Islamabad, Islamabad, Pakistan AXA Business Technologies Full time

    WE ARE HIRINGPosition: Sr. Penetration Tester Work Experience: 3 - 4 Years Qualification Required: BS in CS / SE / IT No. of Position(s): 01 Location: IslamabadRequirements:Conduct penetration testing for mobile applications (iOS & Android) and web applications.Identify vulnerabilities, exploit weaknesses, and provide documentation.Perform both static and...


  • Islamabad, Islamabad, Pakistan NADRA Technologies Ltd Full time

    Job DescriptionWe are seeking an experienced Senior Penetration Tester to join our team at NADRA Technologies Ltd.About the RoleThe successful candidate will be responsible for conducting penetration testing, vulnerability assessments, and providing security expertise to application development teams. This is a challenging role that requires strong technical...


  • Islamabad, Islamabad, Pakistan ZZ Technologies Islamabad Full time

    We are seeking a skilled and motivated Penetration Tester/Reverse Engineer (mobile apps) with 2+ years of experience to join our dynamic cybersecurity team. The ideal candidate will have a solid understanding of penetration testing methodologies, reverse engineering techniques, and cybersecurity best practices.ResponsibilitiesConduct penetration testing...


  • Islamabad, Islamabad, Pakistan Risk Associates Bahrain Full time

    Job ResponsibilitiesAbility to exploit recognized vulnerabilities and discover new vulnerabilitiesAnalyzing and auditing the source code of web/mobile applications and APIsProficiency in scripting, Unix operating systems, and WindowsProficient in Linux operating system configuration, utilities, and programmingConduct manual external and internal penetration...


  • Islamabad, Islamabad, Pakistan Risk Associates Bahrain Full time

    About the RoleIn this challenging role as a Penetration Tester Professional, you will conduct penetration testing for web, desktop, and mobile apps and APIs to identify potential security risks.Key RequirementsBachelor's degree in Electrical, Telecom, Computer Science, Software Engineering, or related area with an equivalent combination of education and...


  • Islamabad, Islamabad, Pakistan Lendo Full time

    About the RoleThis is a great opportunity to join a fast-paced, security-focused FinTech organization operating under regulatory frameworks such as SAMA CSF and PDPL. The successful candidate will be responsible for identifying and validating security weaknesses through structured offensive testing, managing and interpreting vulnerability scan data, and...


  • Islamabad, Islamabad, Pakistan Lendo Full time

    Job OverviewLendo is seeking a highly skilled Cybersecurity Expert Lead to lead our offensive security efforts through penetration testing and vulnerability assessments across web applications, networks, and mobile apps.


  • Islamabad, Islamabad, Pakistan IT Butler Pvt Ltd. Full time

    Job OverviewAt IT Butler Pvt Ltd., we are seeking a highly skilled Information Security Analyst to join our team. As an Information Security Analyst, you will be responsible for monitoring computer networks for security issues and investigating potential breaches.You will also be required to install security measures and operate software to protect systems...


  • Islamabad, Islamabad, Pakistan NADRA Technologies Ltd Full time

    NADRA Technologies Ltd is seeking a skilled Cloud Security Penetration Tester to join our team.Job DescriptionThe ideal candidate will have a strong background in DevSecOps, DevOps, and cloud security with a minimum of 3 years of technical hands-on experience. They should be proficient in analysis tools such as SAST, SCA, DAST, and able to integrate these...


  • Islamabad, Islamabad, Pakistan IT Butler Pvt Ltd. Full time

    Monitor computer networks for security issues.Investigate security breaches and other cybersecurity incidents.Install security measures and operate software to protect systems and information infrastructure, including firewalls and data encryption programs.Document security breaches and assess the damage they cause.Work with the security team to perform...


  • Islamabad, Islamabad, Pakistan CyberSec Consulting Full time

    CyberSec Consulting is a professional services company specializing in Cyber Security and Consulting. We are seeking a highly skilled professional to fill the position of Cybersecurity Governance and Compliance Officer. In this role, you will be responsible for ensuring that our organization's cybersecurity governance and compliance framework is robust and...


  • Islamabad, Islamabad, Pakistan CyberSec Consulting Full time

    CyberSec Consulting is a global provider of Cyber Security Professional Services, Remote Support, Certified Trainings, Outsourcing, Assessment and Consulting Services, as well as solutions for Security Operations Center (SOC) and Managed Security Services (MSS). We are looking for a qualified professional to fill the position of Threat Detection and Response...


  • Islamabad, Islamabad, Pakistan CyberSec Consulting Full time

    CyberSec Consulting is a leading provider of Cyber Security Professional Services, Remote Support, Certified Trainings, Outsourcing, Assessment and Consulting Services, as well as solutions for Security Operations Center (SOC) and Managed Security Services (MSS). We are seeking a skilled professional to fill the position of Information Security Framework...


  • Islamabad, Islamabad, Pakistan PTCLal Full time

    ARE YOU READY TO RISE WITH PTCL GROUPWith our unwavering #ReadyToRise mindset, we have been recognized as an award-winning BEST PLACE TO WORK in the Telecom and Technology sector in Pakistan.We are not just industry leaders; we are redefining excellence with groundbreaking solutions. PTCL Group stands out in the technology industry with its commitment to...


  • Islamabad, Islamabad, Pakistan HyperNym Full time

    Direct message the job poster from HyperNymHyperNym | Hyperfuture | GKHair | AbacusAbout the Role:We are looking for an Information Security Analyst to assess, evaluate, and ensure the security of developed and under-development solutions. The ideal candidate will be responsible for identifying risks, preventing information leaks, ensuring compliance with...


  • Islamabad, Islamabad, Pakistan Risk Associates Bahrain Full time

    About the Role:In this position as Test Analyst, you will be responsible for overseeing day-to-day project activities and executing key tasks.Key Responsibilities:Oversee daily project management and execute associated responsibilities.Analyze system specifications to identify potential vulnerabilities.Run test scripts, assess results, and report any...


  • Islamabad, Islamabad, Pakistan IT Butler Pvt Ltd. Full time

    About the RoleWe are seeking a skilled Information Security Analyst to join our team at IT Butler Pvt Ltd. The successful candidate will be responsible for ensuring the confidentiality, integrity, and availability of our systems and data.This is a challenging role that requires a high level of technical expertise, as well as strong communication and...


  • Islamabad, Islamabad, Pakistan IT Butler Pvt Ltd. Full time

    About the JobWe are seeking a skilled Information Security Analyst to join our team at IT Butler Pvt Ltd. This is an exciting opportunity for someone who is passionate about IT security and wants to make a real difference in the industry.As an Information Security Analyst, you will be responsible for a wide range of tasks, including monitoring computer...