Penetration Tester

Arwen Tech


Date: 2 weeks ago
City: Lahore
Contract type: Full time
Posted on Jul 29, 2026

Title

Penetration Tester

Apply before

Aug 31, 2026

City

Lahore

Responsibilities

Summary of Job Profile:

The Penetration Tester is responsible for identifying and assessing security vulnerabilities across applications, networks, and systems by performing controlled security assessments and simulated attacks. The role involves using industry-standard tools and methodologies to identify weaknesses, validate vulnerabilities, prepare detailed reports, and support remediation activities. The ideal candidate should have a strong foundation in ethical hacking concepts, penetration testing techniques, and security best practices.

Essential Duties & Responsibilities

  • Conduct penetration testing activities on web applications, networks, APIs, and systems under defined testing scopes.
  • Perform vulnerability assessments and security reviews to identify potential security risks.
  • Utilize manual and automated penetration testing tools to identify and validate vulnerabilities.
  • Perform reconnaissance, vulnerability analysis, exploitation, and post-exploitation activities as part of security assessments.
  • Identify common vulnerabilities including OWASP Top 10, misconfigurations, authentication issues, and security weaknesses.
  • Prepare clear and detailed penetration testing reports including findings, risk ratings, evidence, and remediation recommendations.
  • Communicate technical findings effectively with security teams, developers, and relevant stakeholders.
  • Assist development and infrastructure teams in validating security fixes and remediation efforts.
  • Maintain knowledge of current vulnerabilities, attack techniques, and penetration testing methodologies.
  • Assist in improving penetration testing processes, checklists, and documentation.
  • Support security assessments, vulnerability management activities, and compliance-related security testing.
  • Maintain confidentiality and follow ethical hacking guidelines during all testing activities.
  • Document testing procedures, findings, and lessons learned

Requirements

Knowledge, Skills, Abilities (KSA’s) required to successfully perform the job:

Knowledge

  • Good understanding of common vulnerabilities, attack vectors, and exploitation techniques.
  • Knowledge of OWASP Top 10 vulnerabilities and web application security concepts.
  • Understanding of network protocols, operating systems, and basic system architecture.
  • Familiarity with penetration testing methodologies such as PTES and OWASP Testing Guide.
  • Hands-on knowledge of penetration testing tools such as:
    • Burp Suite
    • Nmap
    • Metasploit
    • Kali Linux tools
    • Nessus/OpenVAS
    • Wireshark
  • Basic understanding of scripting/programming languages such as Python, Bash, or PowerShell.
  • Understanding of security concepts including authentication, authorization, encryption, and access controls.
  • Awareness of security best practices and system hardening techniques.
Skills

  • Ability to perform penetration testing on web applications, networks, and APIs.
  • Good technical skills in vulnerability identification and exploitation.
  • Ability to use penetration testing tools effectively.
  • Ability to create professional vulnerability assessment and penetration testing reports.
  • Strong analytical and problem-solving skills.
  • Ability to work independently and collaborate with security and technical teams.
  • Good attention to detail when analyzing security weaknesses.
  • Ability to research and learn new vulnerabilities and attack techniques.

Abilities

  • Ability to think from an attacker’s perspective to identify security weaknesses.
  • Ability to analyze systems and applications for potential vulnerabilities.
  • Ability to reproduce and validate security findings.
  • Ability to explain technical issues to both technical and non-technical stakeholders.
  • Ability to manage multiple testing tasks and meet deadlines.
  • Ability to maintain confidentiality and professional ethics.
  • Ability to continuously improve technical knowledge in cybersecurity.

Education, Experience, Licensure, Certification Required For The Position

  • Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field.
  • 1–2 years of experience in penetration testing, vulnerability assessment, or a related cybersecurity role.
  • Practical experience with web application, network, and API security testing.
  • Relevant certifications are preferred, such as: CEH, eJPT, Security+, PNPT,OSCP (added advantage)

Required

Competencies required to successfully perform the job:

Technical Competencies

Behavioral/General Competencies

  • Web, network, and API penetration testing
  • Vulnerability Assessment & Reporting
  • Penetration Testing Tools (Burp Suite, Nmap, Metasploit, Kali Linux)
  • Security Testing Methodologies
  • Basic Scripting (Python/Bash/PowerShell)
  • Analytical Thinking
  • Problem Solving
  • Attention to Detail
  • Communication Skills
  • Learning & Adaptability

Benefits

  • Excellent Salary
  • Fuel Allowance
  • Medical Insurance
  • Annual Leaves
  • Provident Fund
  • EOBI

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.

Post a resume

Similar jobs

Customer Success Specialist (US & UK Region)

ibex. Pakistan, Lahore
7 hours ago
ibex. Pakistan is hiring Customer Success Specialist in Lahore for a leading international eCommerce client (US & UK region).This opportunity is ideal for individuals looking to build a career in call center jobs in Lahore, customer service, and international support roles. You will be responsible for assisting global customers with their queries related to orders, deliveries, returns, refunds, and account...

Lead Systems & DevOps Engineer (Bare-Metal, Cloud, Linux)

Aqovia, Lahore
6 days ago
About The RoleLead the technical direction of Aqovia's hybrid infrastructure by balancing self-hosted, bare-metal environments with strategic cloud deployments. You will manage the full operational lifecycle of physical and virtual assets, taking ownership of container orchestration, network configuration, and storage. By championing Infrastructure as Code (IaC) and modern observability, you will automate routine tasks and ensure a highly secure, resilient,...

SC / AM - Technology Risk, Rapid Innovations, Pakistan

EY, Lahore
6 days ago
At EY, we’re all in to shape your future with confidence.We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.Join EY and help to build a better working world.The opportunity To support the significant growth of our Technology Risk service in MENA, EY is looking to hire highly...