VAPT Engineer – Enterprise & Scalable Platforms (Onsite, Karachi, PKR Salary)
Hr Pod Hiring Talent Globally
·Today
- Location
- Karachi
- Type
- Full-time
- Department
- Engineering
- Experience
- 2+ years
- Closing date
- Today
- Source
- CareersPage
Description
Requirements:
- 2–5 years of experience in VAPT, application security, cybersecurity, or a related role, with a hands-on understanding of the OWASP Top 10 and API security risks.
- Experience with web, API, mobile, and infrastructure security testing, with familiarity with tools such as Burp Suite, Nmap, Nessus, OWASP ZAP, or equivalent.
- Strong understanding of Linux, networking, HTTP, authentication, and common security controls.
- Strong reporting, documentation, and communication skills.
- Relevant certifications such as OSCP, CEH, eJPT, Security+, or equivalent.
- Cloud security experience, particularly AWS.
- Experience with OTT, high-traffic platforms, streaming ecosystems, or enterprise SaaS.
- Knowledge of threat modeling and secure code review.
- Ability to ensure that all testing is authorized, documented, and conducted within the approved scope, with strong ethical and confidentiality standards.
- Ability to explain technical findings clearly to both technical and non-technical stakeholders.
- Proactive approach to reducing security risks and validating remediation.
Responsibilities:
- Plan and execute approved VAPT engagements for web applications, APIs, mobile applications, and infrastructure.
- Assess authentication, authorization, session management, input validation, and common application vulnerabilities.
- Perform API security testing and review security controls for platform integrations.
- Support mobile application security testing across iOS and Android.
- Assess cloud and infrastructure configurations across AWS and related environments.
- Document findings with clear severity, business impact, evidence, and remediation guidance.
- Collaborate with engineering, DevOps, QA, and product teams to support remediation.
- Conduct retesting and validate that identified vulnerabilities have been resolved.
- Support secure SDLC practices, security awareness, and vulnerability management reporting.
Skills
AWSLinuxiOSAndroidCybersecurityDevOps