CyberSecOrg, a leading cybersecurity firm specializing in penetration testing, vulnerability assessment, security research, and consulting, is seeking an experienced Penetration Tester to join its team. The company focuses on helping organizations identify, validate, and remediate security weaknesses across various environments including web applications, APIs, mobile apps, cloud platforms, networks, and enterprise infrastructure. The role offers a flexible work model with options for on-site presence in Islamabad or remote work, depending on project needs and client engagements. The successful candidate will conduct authorized, hands-on security assessments using industry-standard methodologies, contribute to red team exercises, vulnerability research, and help improve internal testing tools and processes.
Key Responsibilities
- Plan and execute authorized penetration tests on web, mobile, API, cloud, and network environments.
- Identify, validate, and safely demonstrate security vulnerabilities through manual and automated testing.
- Perform red team and adversary simulation activities within defined scopes.
- Assess authentication, authorization, session management, access controls, business logic, and other application security controls.
- Conduct API security assessments and mobile application security testing.
- Perform internal and external network penetration testing.
- Support threat modeling and secure architecture reviews.
- Conduct vulnerability research and investigate emerging attack techniques.
- Document technical findings with clear reproduction steps, evidence, risk context, and remediation recommendations.
- Prepare professional penetration testing reports tailored for both technical and non-technical stakeholders.
- Collaborate with development, infrastructure, and security teams to validate remediation efforts.
- Contribute to the development of internal security tools, scripts, testing methodologies, and research initiatives.
- Stay updated on emerging vulnerabilities, exploits, attack techniques, and security research.
- Maintain strict confidentiality and operate only within authorized testing scopes.
Required Qualifications
- Minimum of 4 years of practical experience in penetration testing or offensive security.
- Strong understanding of cybersecurity concepts, attack vectors, security controls, and secure application and network architectures.
- Hands-on experience with web application and API penetration testing.
- Practical experience in mobile application security testing.
- Solid knowledge of OWASP methodologies and application security principles.
- Ability to identify and manually validate vulnerabilities beyond automated scanning tools.
- Experience with network penetration testing and enterprise security controls.
- Proficiency with tools such as Burp Suite, Nmap, Metasploit, Wireshark, Kali Linux, and related security tooling.
- Strong skills in vulnerability analysis, exploitation, documentation, and reporting.
- Excellent analytical, problem-solving, and communication skills.
- Ability to work independently and collaboratively within a security team.
- Commitment to responsible disclosure, ethical security testing, confidentiality, and authorized testing practices.
Preferred Qualifications and Benefits
- Experience in red teaming and adversary simulation.
- Knowledge of Active Directory security, lateral movement, and privilege escalation techniques.
- Cloud security assessment expertise.
- Skills in secure code review, reverse engineering, binary analysis, malware analysis, and sandbox-based analysis.
- Background in vulnerability research and exploit development.
- Experience with security automation, scripting, and development of penetration testing tools and methodologies.
- Relevant certifications such as OSCP, OSCE, OSEP, GPEN, or equivalent industry credentials are highly valued.
- A Bachelor’s degree in Computer Science, Cybersecurity, Information Security, Software Engineering, or related fields is preferred but not mandatory; equivalent professional experience will be considered.
CyberSecOrg fosters a culture of continuous learning, creativity in security assessment, disciplined documentation, and professional communication. The company emphasizes respect for engagement rules, ethical research, and encourages team members to contribute knowledge, tools, and methodologies. The flexible hybrid work model supports both on-site presence in Islamabad and remote work, depending on project requirements, client agreements, and security considerations. Some assignments may necessitate on-site work, especially for internal infrastructure assessments, client environments, or projects involving restricted systems.