Red Team Penetration Tester
ACE Money Transfer
Date: 2 weeks ago
City: Lahore
Contract type: Full time
About Us:
ACE Money Transfer is a UK-based company headquartered in Manchester, United Kingdom. The company is an online remittance service provider for customers in the UK, Canada, Australia, and the European Union, including Switzerland. The company is a parent company in a group of companies with a diversified portfolio, including digital wallet services in the UK and real estate, advertising businesses, and software solutions in Pakistan.
Role Overview
Responsible for conducting structured adversarial simulations and technical penetration tests across ACE Money Transfer's application, infrastructure, cloud, and identity environments. Operating under a PTES-aligned methodology, the role identifies security weaknesses before threat actors can exploit them and produces high-quality findings that directly inform ACE's remediation priorities and security roadmap.
Key Responsibilities
Powered by JazzHR
KNYercz5os
ACE Money Transfer is a UK-based company headquartered in Manchester, United Kingdom. The company is an online remittance service provider for customers in the UK, Canada, Australia, and the European Union, including Switzerland. The company is a parent company in a group of companies with a diversified portfolio, including digital wallet services in the UK and real estate, advertising businesses, and software solutions in Pakistan.
Role Overview
Responsible for conducting structured adversarial simulations and technical penetration tests across ACE Money Transfer's application, infrastructure, cloud, and identity environments. Operating under a PTES-aligned methodology, the role identifies security weaknesses before threat actors can exploit them and produces high-quality findings that directly inform ACE's remediation priorities and security roadmap.
Key Responsibilities
- Plan and execute penetration tests across web applications, internal/external infrastructure, cloud (cloud platform), M365, and identity (Identity platform) environments
- Conduct adversarial simulations following the PTES methodology: Pre-Engagement, OSINT, Threat Modelling, Exploitation, Post-Exploitation, and Reporting
- Perform application security testing covering OWASP Top 10, business logic abuse, API security, and authentication/authorisation bypass
- Execute network-layer assessments: port scanning, service enumeration, lateral movement, privilege escalation, and credential harvesting
- Conduct cloud security assessments targeting cloud platform IAM misconfiguration, S3 exposure, Lambda abuse, and cross-account pivot scenarios
- Perform phishing simulations and social engineering exercises as part of approved red team campaigns
- Produce CVSS-scored penetration test reports with executive summaries, finding narratives, proof-of-concept evidence, and prioritised remediation guidance
- Validate remediation of previously identified findings through structured retest engagements
- Collaborate with the Blue Team and SIEM/Detection Engineer to improve detection coverage based on red team TTPs
- Mentor Red Team interns: set scoped exercises, review deliverables, and provide structured technical feedback
- 2 to 3 years of hands-on penetration testing across web application, network, and/or cloud environments
- Proficiency in offensive tooling: web application testing tool, exploitation framework, network scanner, vulnerability scanner, AD enumeration tool, network protocol toolkit, or equivalents
- Strong understanding of OWASP Top 10, CWE classifications, and CVSS scoring
- Experience with Active Directory / Identity platform attack paths , Kerberoasting, Pass-the-Hash, Golden Ticket
- Ability to write or adapt exploit code in Python, Bash, or PowerShell
- Experience producing professional pentest reports for both technical and executive audiences
- One or more certifications: OSCP, CRTO, CPTS, CEH (Practical), or eWPT
- Cloud penetration testing experience cloud platform IAM privilege escalation and misconfig exploitation
- Familiarity with C2 frameworks: C2 framework, C2 framework, or C2 framework
- Experience with assumed breach or purple team exercises with active Blue Team collaboration
- Familiarity with TIBER-EU or threat-intelligence-led red team frameworks
- Knowledge of DORA or PCI DSS v4.0.1 as applied to security testing scope
Powered by JazzHR
KNYercz5os
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Cheif Technology Officer (CTO) - Hightech Solutions
Taraki,
Lahore
9 hours ago
Our client Hightech Solutions is hiring a Cheif Technology Officer (CTO) in Lahore.The Chief Technology Officer (CTO) is responsible for defining and executing the company's technology vision, digital transformation, and AI strategy. The CTO will lead software engineering, IT infrastructure, cybersecurity, cloud technologies and automation initiatives while ensuring scalable, secure, and innovative technology solutions that support business growth.Key ResponsibilitiesOwn and...
Senior Java Engineer
CoorB,
Lahore
2 days ago
ABOUT CoorBWe build full-fledged innovative solutions with a focus on process automation, user experience enhancement, and advanced data analytics. With our extensive industry expertise, we help achieve operational excellence, future-proof your IT investments, and ensure a competitive edge in the ever-evolving finance industry. OUR OPPORTUNITYAs Java Senior Software Engineer with backbase certification, you will be responsible for developing and testing...
Business Development Executive
Accelerec Ltd.,
Lahore
3 days ago
Are you a driven and ambitious professional looking to make a significant impact in business development? We are seeking a talented and results-oriented Business Development Executive to join our growing team on a permanent basis. This is an exciting opportunity to contribute to our strategic growth and build strong client relationships within the Pakistani market.Key ResponsibilitiesIdentify and prospect new business...