Penetration Tester
- Hiring from
- Pakistan
- Work type
- Hybrid
- Posted
- Sep 27, 2026
CyberSecOrg is a cybersecurity company specializing in penetration testing, vulnerability assessment, security research, and cybersecurity consulting. We help organizations identify, validate, and remediate security weaknesses across web applications, APIs, mobile applications, cloud environments, networks, and enterprise infrastructure.
Our security professionals conduct authorized penetration tests, threat modeling, security assessments, and responsible vulnerability research using industry-standard methodologies and hands-on testing techniques. CyberSecOrg also develops cybersecurity tools and solutions designed to provide actionable security insights, monitoring capabilities, and improved protection for digital infrastructure.
Our mission is to strengthen cybersecurity through practical security testing, research, education, and responsible innovation while providing security professionals with an environment where they can continuously develop their technical expertise.
Role DescriptionPosition: Penetration Tester
Experience: 4+ years
Employment Type: Full-time
Location: Islamabad, Pakistan
Work Model: On-site / Flexible Remote
CyberSecOrg is seeking an experienced Penetration Tester to join our cybersecurity team. This is a flexible role that supports both on-site work in Islamabad and remote work, depending on project requirements, client engagements, assessment environments, and team collaboration needs.
The successful candidate will perform authorized, hands-on security assessments across web applications, APIs, mobile applications, cloud environments, and internal and external network infrastructure.
The role involves identifying, validating, and responsibly demonstrating security vulnerabilities through manual testing and established penetration testing methodologies. The Penetration Tester will also contribute to red team exercises, vulnerability research, threat modeling, security reviews, and the continuous improvement of CyberSecOrg's internal testing methodologies and security tools.
Key Responsibilities- Plan and execute authorized penetration tests against web, mobile, API, cloud, and network environments.
- Identify, validate, and safely demonstrate security vulnerabilities.
- Conduct manual testing alongside automated security assessments.
- Perform red team and adversary simulation activities within clearly defined scopes.
- Assess authentication, authorization, session management, access controls, business logic, and other application security controls.
- Conduct API security assessments and mobile application security testing.
- Perform internal and external network penetration testing.
- Support threat modeling and secure architecture reviews.
- Conduct vulnerability research and investigate emerging attack techniques.
- Document technical findings with clear reproduction steps, evidence, risk context, and remediation recommendations.
- Prepare professional penetration testing reports for technical and non-technical stakeholders.
- Work with development, infrastructure, and security teams to help validate remediation.
- Contribute to the development of internal security tools, scripts, testing methodologies, and research.
- Stay current with emerging vulnerabilities, exploits, attack techniques, and security research.
- Maintain strict confidentiality and operate only within authorized testing scopes.
- 4+ years of practical experience in penetration testing or offensive security.
- Strong understanding of cybersecurity concepts, common attack vectors, security controls, and secure application and network architectures.
- Hands-on experience with web application and API penetration testing.
- Practical experience with mobile application security testing.
- Strong understanding of OWASP methodologies and application security principles.
- Experience identifying and manually validating vulnerabilities rather than relying solely on automated scanners.
- Practical knowledge of network penetration testing and common enterprise security controls.
- Experience with tools such as Burp Suite, Nmap, Metasploit, Wireshark, Kali Linux, and related security tooling.
- Strong vulnerability analysis, exploitation, documentation, and reporting skills.
- Excellent analytical and problem-solving abilities.
- Strong written and verbal communication skills.
- Ability to work independently as well as collaboratively within a security team.
- Commitment to responsible disclosure, ethical security testing, confidentiality, and authorized testing practices.
Candidates with experience in the following areas will be considered:
- Red teaming and adversary simulation
- Active Directory security
- Lateral movement and privilege escalation
- Cloud security assessment
- Secure code review
- Reverse engineering and binary analysis
- Malware analysis and sandbox-based analysis
- Vulnerability research and exploit development
- Security automation and scripting
- Development of penetration testing tools and methodologies
Relevant certifications such as OSCP, OSCE, OSEP, GPEN, or equivalent industry certifications are valuable.
A Bachelor's degree in Computer Science, Cybersecurity, Information Security, Software Engineering, or a related discipline is preferred but not required. Equivalent professional experience and demonstrated technical capability may also be considered.
Professional ExpectationsThe successful candidate should demonstrate:
- Strong technical curiosity and continuous learning.
- The ability to think creatively when assessing security controls.
- Attention to detail and disciplined documentation.
- Professional communication with both technical and non-technical stakeholders.
- Respect for defined rules of engagement and authorization boundaries.
- A strong commitment to responsible and ethical security research.
- Willingness to contribute knowledge, research, tools, and methodologies to the CyberSecOrg team.
CyberSecOrg supports a flexible hybrid working model.
Depending on project and client requirements, team members may work:
🏢 On-site: Islamabad office and client project locations when required.
💻 Remote: Remote work is available for suitable projects and responsibilities, subject to team coordination, security requirements, and client agreements.
- Some engagements may require on-site presence, particularly for internal infrastructure assessments, client environments, team meetings, or projects involving restricted systems.