Penetration Tester

JOB DESCRIPTION

Role Overview

Division Information Security
Reporting Line Information Security Officer (CISO)
Functional Coordination Software Engineering, Infrastructure Operations, and QA Teams
Location Karachi (with frequent travel to Government of Sindh departments across Sindh)
Employment Type Full-time

The Penetration Tester is a core, highly specialized technical role within the Information Security division. The role is responsible for identifying, evaluating, and demonstrating security vulnerabilities across SITC’s proprietary applications, hosting infrastructures, and integrated public-sector platforms. By conducting structured, aggressive, and ethical security testing, this professional ensures that critical systems deployed for the Government of Sindh are heavily fortified against external and internal cyber threats.

Unlike generalist IT roles, this position demands an offensive cybersecurity mindset. The Penetration Tester will simulate real-world cyberattacks, analyze complex digital architectures, perform deep-dive source code reviews, and clearly articulate technical findings to both developers and senior leadership. The objective is to proactively manage risk and build robust security barriers before deployment.

Key Responsibilities

  • Perform end-to-end vulnerability assessments and penetration testing (VAPT) across web applications, mobile platforms, APIs, cloud environments, and internal networks.
  • Conduct thorough, static and dynamic application security testing (SAST/DAST) alongside manual secure code reviews to detect logic flaws and structural security gaps.
  • Replicate advanced adversary tactics, techniques, and procedures (TTPs) in controlled scenarios to expose systemic vulnerabilities in state-hosted digital systems.
  • Author comprehensive, technical VAPT reports clearly outlining vulnerability details, severity classifications (using CVSS), proof-of-concept exploits, and prescriptive remediation guides.
  • Act as the primary technical advisor to software development and infrastructure teams, assisting them directly in the remediation and verification of identified security flaws.
  • Establish and maintain SITC’s internal penetration testing frameworks, toolkits, and secure baseline methodologies to ensure compliance with international security standards (e.g., OWASP Top 10, ISO 27001).
  • Evaluate third-party vendor applications, integrated APIs, and external software components to protect SITC’s technical ecosystem from supply chain risks.
  • Contribute technical insights during high-severity security incident investigations, leveraging digital forensics to analyze attack vectors and plug exploited gaps.

Qualification & Experience

  • Education: Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, or a related technical discipline from an HEC-recognized institution.
  • Experience: Minimum of 3–5 years of dedicated, professional experience in penetration testing, offensive security, or red teaming.
  • Certifications: Active professional certifications such as OSCP (Offensive Security Certified Professional), CEH (Certified Ethical Hacker), GPEN, or equivalent practical cybersecurity credentials are highly preferred.

Note:
Only PDF resumes are accepted.
Your CV must include an email ID, mobile number, LinkedIn URL, and current city.

Drop your file here or click here to upload You can upload up to 1 files.