Security & Vulnerability Engineer

NextGENi - A DotZero Company

Karachi Division

Hybrid

PKR 3,000,000 - 5,200,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

NextGENi is seeking a hands-on Security & Vulnerability Engineer to own the security assessment function across customer environments. Reporting to the CTO, you will identify, assess, and communicate security risks across applications, infrastructure, cloud environments, and networks.

You will manage the vulnerability lifecycle from discovery to remediation and verification. The ideal candidate thrives on offensive security, automation, and improving security posture in customer deployments,

Qualifications

  • 5+ years hands-on cybersecurity experience.
  • Experience in vulnerability assessment, pen testing, and secure SDLC.
  • Familiar with OWASP Top 10 and modern security testing.
  • Experience with automation and scripting.
  • Ability to communicate risk to stakeholders.
  • Experience with AI-assisted security tooling.

Responsibilities

  • Own end-to-end vulnerability assessment across apps, infra, cloud, and networks.
  • Perform hands-on security assessments using automated and manual techniques.
  • Communicate findings and remediation recommendations to engineering, customers, and leadership.
  • Develop automation to improve efficiency of security assessments.
  • Collaborate with Engineering, DevOps, and Cloud teams to validate remediation.
  • Enhance methodologies by adopting industry best practices and new tooling.

Skills

Security
Vulnerability assessment
Penetration testing
SAST/DAST
Cloud platforms (AWS/Azure/GCP)
Bash scripting
Linux
Communication skills
AI-assisted tooling

Tools

Network scanners
Container security tools
CI/CD security integration
Terraform
CloudFormation

Job description

About NextGENi

NextGENi (Next Generation Innovations) is transforming how regional startups build their technology teams. We help ambitious founders build and manage their offshore technology teams at twice the speed and fraction of the cost. We have built tech teams for some of the leading startups in the region including Careem, Dubizzle, and Kavak. Our mission is to create exceptional tech teams while maintaining an unparalleled culture and the highest regard for professional principles.

Job Details
  • Role: Security & Vulnerability Engineer
  • Location: Karachi (Hybrid)
  • Type: Full-Time
  • Experience Range: 5+ Years
About NextGENi

NextGENi (Next Generation Innovations) is transforming how regional startups build their technology teams. We help ambitious founders build and manage their offshore technology teams at twice the speed and fraction of the cost. We have built tech teams for some of the leading startups in the region including Careem, Dubizzle, and Kavak. Our mission is to create exceptional tech teams while maintaining an unparalleled culture and the highest regard for professional principles.

About The Role

We are seeking a hands-on Security & Vulnerability Engineer to own the security assessment function across customer environments. Reporting directly to the CTO, you will be responsible for identifying, assessing, and communicating security risks across applications, infrastructure, cloud environments, and networks. This role combines technical execution with ownership of the vulnerability management lifecycle from discovery and risk assessment through remediation tracking and verification. The ideal candidate is passionate about offensive security, automation, and continuously improving the security posture of customer deployments.

Responsibilities
  • Own the end-to-end vulnerability assessment process across customer applications, infrastructure, cloud environments, and networks.
  • Perform hands-on security assessments using automated and manual techniques, including code reviews, network scanning, and infrastructure analysis.
  • Communicate security findings, risk ratings, and remediation recommendations to engineering teams, customers, and executive stakeholders.
  • Develop scripts and automation to improve the efficiency, consistency, and coverage of security assessments.
  • Collaborate with Engineering, DevOps, and Cloud teams to validate remediation efforts and improve overall security posture.
  • Continuously enhance security assessment methodologies by adopting industry best practices, emerging threats, and modern security tooling.
Key Requirements
  • 5+ years of hands-on experience in cybersecurity, application security, vulnerability assessment, penetration testing, or a related security engineering role.
  • Strong knowledge of secure software development, OWASP Top 10, common vulnerability types, and modern security testing methodologies.
  • Hands-on experience with automated security tools, including network scanners, SAST, DAST, dependency scanning, and container security tools.
  • Proficiency in Bash scripting and hands-on experience with Linux environments and at least one major cloud platform (AWS, Azure, or GCP).
  • Excellent communication skills with the ability to translate technical findings into clear, actionable recommendations for both technical and business stakeholders.
  • Demonstrated ability to leverage AI-assisted engineering tools to accelerate security analysis, automation, documentation, and vulnerability research.
Nice To Have
  • Professional security certifications such as Security+, CEH, PNPT, OSCP, CISSP, or equivalent.
  • Experience integrating security testing into CI/CD pipelines and DevSecOps workflows.
  • Experience securing containerized and Kubernetes-based environments.
  • Familiarity with Infrastructure as Code (Terraform, CloudFormation, or similar).
  • Knowledge of security frameworks and standards such as OWASP ASVS, CIS Benchmarks, ISO 27001, SOC 2, or PCI DSS.
Interview Process
  • Round 1: A technical interview to assess the candidate’s expertise and practical experience.
  • Round 2: A discussion with the PMO/CTO to evaluate strategic thinking and technical alignment.
  • Round 3: An HR interview to assess cultural fit, communication skills, and overall suitability for the role.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security & Vulnerability Engineer – Cloud & Automation
Senior Security & Vulnerability Engineer – Cloud & Automation

NextGENi - A DotZero Company • Karachi Division

Hybrid
PKR 3,000,000 - 5,200,000
Head of Quality Assurance
Head of Quality Assurance

NextGENi - A DotZero Company • Karachi Division

Hybrid
PKR 1,800,000 - 2,400,000
Cyber Security Engineer - Islamabad
Cyber Security Engineer - Islamabad

Yeah! Global • Islamabad

On-site
Head of Quality Assurance Position closed
Head of Quality Assurance Position closed

NextgenI • Karachi Division

Hybrid
PKR 1,800,000 - 2,800,000
Health Insurance
Takaful Life
Fuel Benefits
+3
Cyber & Information Security Specialist
Cyber & Information Security Specialist

Oxiliry • Hyderabad City Taluka, Karachi Division

On-site
PKR 13,939,000 - 19,515,000
DevSecOps
DevSecOps

NETSOL Technologies Inc. • Lahore

On-site
PKR 1,800,000 - 3,000,000
Cyber Security Research Specialist
Cyber Security Research Specialist

HBL • Karachi Division

On-site
PKR 1,800,000 - 2,800,000
Penetration Tester
Penetration Tester

Alykas • Karachi Division

On-site
PKR 1,200,000 - 1,800,000
Cyber Security Engineer
Cyber Security Engineer

Code Ninety • Islamabad

On-site
Competitive salary
Security certifications training
Flexible working hours
Assistant Manager Cyber Security (App Security & Data Protection)
Assistant Manager Cyber Security (App Security & Data Protection)

K-Electric • Karachi Division

On-site
PKR 1,200,000 - 2,400,000