Enter a job title or keyword

VAPT Engineer – Enterprise & Scalable Platforms


Job Location:

Karachi - Pakistan

Monthly Salary: Not provided by the employer
Posted: 25 September 2026 (Yesterday)
Application Deadline: 23 December 2026
Vacancies: 1 Vacancy

Job Summary

Requirements:

  • 25 years of experience in VAPT application security cybersecurity or a related role with a hands-on understanding of the OWASP Top 10 and API security risks.
  • Experience with web API mobile and infrastructure security testing with familiarity with tools such as Burp Suite Nmap Nessus OWASP ZAP or equivalent.
  • Strong understanding of Linux networking HTTP authentication and common security controls.
  • Strong reporting documentation and communication skills.
  • Relevant certifications such as OSCP CEH eJPT Security or equivalent.
  • Cloud security experience particularly AWS.
  • Experience with OTT high-traffic platforms streaming ecosystems or enterprise SaaS.
  • Knowledge of threat modeling and secure code review.
  • Ability to ensure that all testing is authorized documented and conducted within the approved scope with strong ethical and confidentiality standards.
  • Ability to explain technical findings clearly to both technical and non-technical stakeholders.
  • Proactive approach to reducing security risks and validating remediation.

Responsibilities:

  • Plan and execute approved VAPT engagements for web applications APIs mobile applications and infrastructure.
  • Assess authentication authorization session management input validation and common application vulnerabilities.
  • Perform API security testing and review security controls for platform integrations.
  • Support mobile application security testing across iOS and Android.
  • Assess cloud and infrastructure configurations across AWS and related environments.
  • Document findings with clear severity business impact evidence and remediation guidance.
  • Collaborate with engineering DevOps QA and product teams to support remediation.
  • Conduct retesting and validate that identified vulnerabilities have been resolved.
  • Support secure SDLC practices security awareness and vulnerability management reporting.