Senior VAPT Engineer

Arwentech

Islamabad

On-site

PKR 1,800,000 - 3,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Excellent Salary
Fuel Allowance
Internet Allowance
Medical Insurance
Annual Leaves
Provident Fund
EOBI
Annual Bonus

Job summary

Arwentech is seeking a Senior VAPT Engineer to lead end-to-end penetration testing across web, mobile, APIs, networks, and cloud environments from Islamabad. You will plan engagements, execute tests, and deliver detailed reports with remediation guidance.

You will apply manual and automated testing against OWASP Top 10 and related standards, develop testing scripts, and mentor junior team members while collaborating with clients and internal stakeholders to improve security posture.

Qualifications

  • Bachelor's or Master's degree in Computer Science, Information Security, Cyber Security, or a related field.
  • Minimum of 5 years hands-on experience in VAPT and security testing across web, API, network, and cloud environments.
  • Professional certifications such as OSCP, OSWE, OSEP, CEH, PNPT, GPEN, or equivalent are preferred.
  • Experience with cloud security assessments (AWS, Azure, or GCP) is an advantage.

Responsibilities

  • Plan, scope, and lead VAPT engagements for diverse environments.
  • Perform manual and automated testing to identify vulnerabilities and validate findings.
  • Prepare detailed technical reports, risk ratings, and remediation guidance.
  • Present findings to clients and stakeholders with clear mitigation strategies.
  • Develop scripts and tooling to improve testing efficiency and repeatability.
  • Mentor junior engineers and contribute to team knowledge sharing.

Skills

Penetration testing
Vulnerability assessment
Security tooling
Report writing
Communication skills
Scripting (Python)

Education

Bachelor's or Master's in CS/InfoSec

Tools

Nmap
Burp Suite
OWASP ZAP
Nessus
Metasploit
OpenVAS
Wireshark

Job description

The Senior VAPT Engineer will be responsible for planning, leading, and executing vulnerability assessments and penetration testing engagements across web applications, mobile applications, APIs, networks, cloud environments, and infrastructure. The role requires conducting both automated and manual security assessments, identifying security vulnerabilities, validating risks through exploitation, and delivering comprehensive reports with practical remediation recommendations.

Key responsibilities include:

  • Plan, scope, and execute VAPT engagements for web applications, mobile applications, APIs, internal and external networks, cloud infrastructure, and other technology environments.
  • Work closely with clients to understand testing objectives, scope, business requirements, and engagement expectations.
  • Perform manual and automated penetration testing to identify, validate, and exploit security vulnerabilities while assessing their business impact.
  • Conduct vulnerability assessments using industry‑standard security tools and validate findings through manual verification to eliminate false positives.
  • Perform security testing against recognized standards such as the OWASP Top 10, OWASP API Security Top 10, and other industry best practices.
  • Analyze penetration testing results and prepare detailed technical reports, executive summaries, risk ratings, proof‑of‑concept evidence, and actionable remediation recommendations.
  • Present technical findings, security risks, and mitigation strategies to clients and internal stakeholders.
  • Collaborate with development, infrastructure, and security teams to support vulnerability remediation and perform retesting to validate fixes.
  • Develop, maintain, and improve penetration testing methodologies, checklists, scripts, and automation tools to enhance testing efficiency.
  • Stay current with emerging cyber‑threats, attack techniques, vulnerabilities, and security research to continuously improve assessment capabilities.
  • Mentor and provide technical guidance to junior VAPT engineers and assist in knowledge sharing within the security team.
  • Support pre‑sales activities, technical discussions, and client consultations when required.
Responsibilities

The Senior VAPT Engineer will lead end‑to‑end penetration testing engagements, ensuring compliance with organizational policies, client requirements, and industry security standards.

Requirements
Knowledge
  • Strong knowledge of penetration testing methodologies and vulnerability assessment processes.
  • In‑depth understanding of common security vulnerabilities, exploitation techniques, and remediation strategies.
  • Solid understanding of network protocols, operating systems, web technologies, APIs, cloud environments, and security architecture.
  • Familiarity with industry standards and frameworks including OWASP Top 10, OWASP API Security Top 10, NIST, ISO 27001, PCI‑DSS, and CIS Benchmarks.
  • Knowledge of secure development practices and common attack vectors across modern applications.
Skills
  • Hands‑on experience with penetration testing and vulnerability assessment tools including Nmap, Zmap, Burp Suite Professional, OWASP ZAP, SQLMap, Metasploit Framework, Nessus, OpenVAS, Wireshark, and related security tools.
  • Experience performing manual web application, API, network, and infrastructure penetration testing.
  • Strong analytical, troubleshooting, and problem‑solving skills.
  • Excellent technical report writing and documentation skills.
  • Strong verbal communication and presentation skills.
  • Ability to develop scripts for automating security testing using Python, Bash, or PowerShell (advantage).
Abilities
  • Lead penetration testing engagements independently from planning through reporting.
  • Manage multiple projects while meeting deadlines.
  • Mentor junior engineers and review technical deliverables.
  • Maintain confidentiality and handle sensitive client information professionally.
  • Work independently and collaboratively within cross‑functional teams.
Education, Experience, Licensure, Certification
  • Bachelor's or Master's degree in Computer Science, Information Security, Cyber Security, or a related field.
  • Minimum of 5 years of hands‑on experience in VAPT.
  • Demonstrated experience conducting web application, API, network, and infrastructure penetration testing.
  • Professional certifications such as OSCP, OSWE, OSEP, CRTO, CEH, PNPT, GPEN, eWPT, or equivalent are preferred.
  • Experience with cloud security assessments (AWS, Azure, or GCP) is an advantage.
Competencies
  • Vulnerability Assessment & Penetration Testing
  • Web Application Security
  • API Security Testing
  • Network Penetration Testing
  • Operating Systems (Windows/Linux)
  • Networking Protocols
  • Security Tools (Nmap, Burp Suite, OWASP ZAP)
  • Security Frameworks (OWASP, NIST, ISO 27001, PCI‑DSS)
  • Cloud Security Assessment
  • Analytical Thinking
  • Problem Solving
  • Communication (Written & Verbal)
  • Leadership & Mentoring
  • Teamwork & Collaboration
  • Client Management
  • Reporting & Documentation
  • Time Management
  • Attention to Detail
  • Continuous Learning
Benefits
  • Excellent Salary
  • Fuel Allowance
  • Internet Allowance
  • Medical Insurance
  • Annual Leaves
  • Provident Fund
  • EOBI
  • Annual Bonus
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

Arwentech • Lahore

On-site
PKR 900,000 - 1,300,000
Senior Application Security Engineer
Senior Application Security Engineer

SwipBox • Islamabad

On-site
PKR 400,000 - 700,000
Assistant Manager (Penetration Testing)
Assistant Manager (Penetration Testing)

Risk Associates Pvt. Ltd. • Karachi Division

On-site
PKR 1,800,000 - 3,000,000
Cyber Security Consultant
Cyber Security Consultant

Catalyic Security • Lahore

On-site
VAPT Engineer
VAPT Engineer

VIDIZMO LLC • Karachi Division

On-site
PKR 1,200,000 - 2,000,000
Health Insurance (OPD/IPD)
Separate Maternity Cover
Leave encashment
+7
Penetration Testing Senior Associate
Penetration Testing Senior Associate

A. F. Ferguson & Co. (a member firm of the PwC network) • Karachi Division

On-site
PKR 1,200,000 - 1,800,000
Penetration Testing Senior Associate
Penetration Testing Senior Associate

PwC South Africa • Karachi Division

On-site
Confidential
Senior Vulnerability & Penetration Tester
Senior Vulnerability & Penetration Tester

Arwentech • Islamabad

On-site
PKR 1,800,000 - 3,200,000
Excellent Salary
Fuel Allowance
Internet Allowance
+5
Software Engineer - Security Testing
Software Engineer - Security Testing

i2c Inc • Lahore

On-site
PKR 5,575,000 - 11,152,000
Senior Security Consultant- Afternoon Shift
Senior Security Consultant- Afternoon Shift

10Pearls, LLC • Lahore, Karachi Division, Islamabad

On-site
PKR 1,200,000 - 1,600,000