Infrastructure Security Lead
1 week ago
We are looking for a highly skilled and versatile Information Security Specialist who can perform the roles of a Penetration Tester and Cybersecurity Specialist across diverse environments, including cloud platforms,
backend APIs, web applications, mobile (Android & iOS), and enterprise systems. This role is crucial in ensuring the security of our digital ecosystem by identifying vulnerabilities, implementing security measures, and safeguarding sensitive data against cyber threats.
Key Responsibilities:
● Security Assessments & Penetration Testing:
o Conduct detailed penetration testing across multiple platforms, including web, mobile (iOS/Android), cloud environments (AWS, Azure, GCP), and APIs.
o Perform vulnerability assessments using automated tools and manual testing to uncover security risks.
o Simulate cyber-attacks and exploit discovered vulnerabilities to assess the overall security posture.
o Develop threat models and provide mitigation strategies to minimize risk exposure.
● Cloud Security:
o Perform cloud security audits and reviews for AWS, Azure, or GCP environments.
o Implement and monitor cloud security policies, ensuring alignment with industry standards (e.g., PCIDSS, NIST, ISO 27001, GDPR).
o Conduct regular security reviews and configuration assessments of cloud-native applications and infrastructure.
● Backend API Security:
o Analyze and secure backend APIs against attacks such as injection, cross-site scripting (XSS), cross-site request forgery (CSRF), and API endpoint misconfigurations.
o Review API authentication and authorization mechanisms (OAuth, JWT) for potential vulnerabilities.
o Implement secure coding practices in collaboration with development teams to minimize attack surfaces.
● Mobile Security (Android & iOS):
o Conduct penetration testing on Android and iOS applications using static and dynamic analysis techniques.
o Assess mobile app security for potential vulnerabilities like insecure data storage, improper SSL/TLS implementations, and weak encryption.
o Provide guidance to mobile app development teams on secure coding best practices.
● Web Security:
o Perform comprehensive security testing of web applications, including OWASP Top 10
vulnerabilities, security misconfigurations, and business logic flaws.
o Ensure secure configuration and hardening of web servers, firewalls, and application servers.
● Incident Response & Threat Management:
o Lead incident response efforts, including threat identification, mitigation, and forensic investigation.
o Conduct risk assessments, analyzing attack patterns, TTPs (Tactics, Techniques, and Procedures), and implement countermeasures.
o Participate in cybersecurity drills and prepare reports on the effectiveness of defenses.
● Security Compliance & Policy Development:
o Assist in developing, implementing, and maintaining security policies, procedures, and best practices across the organization.
o Ensure compliance with industry standards such as PCI-DSS, HIPAA, GDPR, and others.
o Work closely with legal and compliance teams to ensure data protection regulations are met across all environments.
● Collaboration & Training:
o Provide security training and awareness sessions to development and operations teams.
o Collaborate with DevOps teams to implement DevSecOps methodologies and ensure continuous security integration within the CI/CD pipeline.
o Conduct red team exercises and penetration testing scenarios, briefing teams on the outcomes and helping them implement improvements.
Required Skills and Qualifications:
● Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a
related field. A master's degree is a plus.
● Certifications (Preferred but not required):
o CEH (Certified Ethical Hacker)
o OSCP (Offensive Security Certified Professional)
o CISSP (Certified Information Systems Security Professional)
o CISM (Certified Information Security Manager)
o GPEN (GIAC Penetration Tester)
o CompTIA Security+
● Technical Skills:
o Penetration Testing Tools: Proficient with tools like Metasploit, Burp Suite, Wireshark, Nmap, Nessus, or OpenVAS.
o Cloud Security: In-depth knowledge of cloud security frameworks and tools for AWS, GCP, and Azure.
o Mobile Security: Experience with mobile security frameworks, and tools like Drozer, MobSF, FRIDA or similar.
o API Security: Understanding of API security testing, OAuth, JWT, and encryption techniques.
o Web Security: Experience with SAST/DAST tools like ZAP, Veracode, or SonarQube for web security assessments and code reviews.
o Network Security: Knowledge of network security monitoring and firewall management.
● Experience:
o 7-8 years of experience in information security, penetration testing, or vulnerability management.
o Extensive experience with cloud platforms (AWS, Azure, GCP), securing APIs, and mobile application security.
o Extensive experience in Mobile (iOS & Android) Pen testing, Web & Apis Pen testing.
o Experience in Securing the CI/CD Pipelines.
o Must have experience working with PCI-DSS Compliance.
o Strong knowledge of security protocols, cryptography, authentication mechanisms, and data protection.
-
Infrastructure Security
1 week ago
Lahore, Punjab, Pakistan People Junction Full time 1,500,000 - 3,000,000 per yearJob Summary:We are looking for a highly skilled and versatile Information Security Specialist who can perform the roles of a Penetration Tester and Cybersecurity Specialist across diverse environments, including cloud platforms, backend APIs, web applications, mobile (Android & iOS), and enterprise systems. This role is crucial in ensuring the security of...
-
Infrastructure Engineer
1 week ago
Lahore, Punjab, Pakistan Topdot Full time $90,000 - $120,000 per yearCompany DescriptionTopdot delivers dynamic website solutions to clients around the world. Our vision is to provide creative and user-friendly solutions while bringing innovation to everyday business processes. We are a one-stop-shop for our clients, offering a variety of IT services including website development, mobile apps, and online marketing.Role...
-
IT Security
1 week ago
Lahore, Punjab, Pakistan yieldWerx Semiconductor Full time 800,000 - 1,280,000 per yearCompany DescriptionyieldWerx offers comprehensive semiconductor test data analytics solutions that enhance decision-making, root cause analysis, and process improvement. Our products serve semiconductor engineers from device characterization to yield and quality management and RMA analysis. yieldWerx Automotive Solutions ensure compliance with AEC...
-
Application Security Engineer
1 week ago
Lahore, Punjab, Pakistan Simplex Technology Solutions Full time 80,000 - 1,200,000 per yearPosition ImpactAs an Application Security Engineer, you will be at the forefront of securing our applications and infrastructure. You will work with cross-functional teams to embed security into the software development life cycle (SDLC), reduce risk exposure, and ensure compliance with industry standards. Your expertise will directly safeguard sensitive...
-
Cloud Infrastructure Engineer
7 days ago
Lahore, Punjab, Pakistan Vantic Ventures Full time $40,000 - $80,000 per yearCompany DescriptionVantic Ventures is a UK-registered venture builder studio under Bin Yasser Group Ltd., focused on building and launching high-impact digital ventures. One of its core initiatives is UFAQ Cloud, a next-generation hosting platform offering VPS, Dedicated Servers, and Game Server hosting.This role is for a technical founding member who will...
-
IT Security Officer
13 hours ago
Lahore, Punjab, Pakistan Aqovia Full timeAbout Aqovia:At the Intersection of Innovation and Impact, introducing Aqovia. Aqovia is an international technology firm dedicated to creating tangible value through the power of AI, data-driven, and bespoke software solutions and services.Our unique approach extends beyond traditional service and solutions delivery, we strategically invest in and nurture a...
-
Information Security
14 hours ago
Lahore, Punjab, Pakistan ORBIN Full timeInternship OpportunityLocation: Lahore, PakistanPosition: Information Security / Network Security InternDuration: 3 Months (Initial Internship Period)Stipend: PKR 15,000 per monthAbout Orbin:At Orbin, perfect security is priceless We are leaders in Cyber Security & IT Solutions, providing innovative network and IT services to businesses.Key...
-
IT Security
5 days ago
Lahore, Punjab, Pakistan yieldWerx Semiconductor Full time $60,000 - $120,000 per yearCompany Description:yieldWerx is an end-to-end Semiconductor Test data analytics solutions company. A global company with headquarters in Texas, USA and offices in Pakistan, and the Philippines. yieldWerx enables semiconductor companies, Offshore Assembly & Test (OSATS) as well as Independent Device Manufacturers (IDM)'s the ability to analyze test data...
-
IT Networking and Security
1 week ago
Lahore, Punjab, Pakistan Xcentric Services | Web & App Development Company | Software Development | React App Development Full time $20,000 - $40,000 per yearCompany DescriptionXcentric Services is a leading boutique technology agency specializing in ERP, digital marketing, and e-commerce enablement. Headquartered in Lahore and Chicago, Xcentric caters to mid-market clients, offering tailored solutions in ERP deployment, web and app development, e-commerce platforms, digital marketing, CRM, and analytics. Our...
-
IT Infrastructure Development
1 week ago
Lahore, Punjab, Pakistan 360 TECHNOLOGIES Full time 1,200,000 - 3,600,000 per yearSkills and Competencies:Strong analytical and problem-solving skills.Knowledge of IT governance and security compliance frameworks.Ability to manage multiple priorities under pressure.Strong teamwork, interpersonal, and communication skills.Proactive approach with attention to detail and documentation.Technical Expertise:System administration (Windows/Linux...