Department: INFORMATION SECURITY Experience: 2 YearsDeadline: December 24, 2025Location: Rawalpindi, Pakistan
Job Summary
The VAPT Analyst will be responsible for conducting security testing of applications, systems, and networks to identify vulnerabilities, assess risks, and recommend remediation measures. This role requires strong technical expertise in penetration testing, vulnerability assessment tools, and knowledge of security frameworks and methodologies.
Key Responsibilities
- Conduct Vulnerability Assessment and Penetration Testing (VAPT) on websites, APIs, and mobile applications (Android/iOS).
- Identify, analyze, and document security vulnerabilities, threats, and risks.
- Prepare detailed technical and executive-level reports with findings, risk ratings, and remediation recommendations.
- Collaborate with IT, DevOps, and development teams to remediate vulnerabilities.
- Maintain knowledge of OWASP Top 10, NIST, ISO 27001, and other cybersecurity frameworks.
- Stay updated with the latest security tools, vulnerabilities, and penetration testing techniques.
- Assist in compliance audits and security policy implementation when required.
Requirements
- Bachelor’s degree in Computer Science, Information Technology, Cyber Security, or related discipline.
- 1–2 years of experience in vulnerability assessment, penetration testing, or related roles.
- Hands-on experience with tools such as Burp Suite, Nessus, Metasploit, Nmap, Kali Linux, etc.
- Strong knowledge of OWASP, NIST, ISO 27001, and secure coding practices.
- Excellent reporting and communication skills.
- Candidates with relevant certifications will be preferred.
Skills & Competencies
- Strong expertise in Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, mobile apps (Android/iOS), and networks.
- Hands-on experience with penetration testing tools and frameworks such as Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto, Kali Linux, and related toolsets.
- Solid understanding of OWASP Top 10, MITRE ATT&CK, NIST, ISO 27001, and secure coding practices.
- Ability to identify, analyze, exploit, and document security vulnerabilities with proper risk ratings and remediation guidance.
- Skilled in preparing detailed technical reports as well as executive summaries for management.
- Knowledge of scripting and automation (e.g., Python, Bash, PowerShell) to support custom testing.
- Strong analytical and problem-solving skills with attention to detail.
- Effective communication and collaboration skills to work with IT, DevOps, and development teams for vulnerability remediation.
- Continuous learning mindset to stay updated with the latest security exploits, attack vectors, and penetration testing methodologies.
- Preferred certifications: OSCP, CEH, eJPT, GPEN, or equivalent.
Total Position(s)
1 Positions
Minimum Education
Bachelors Degree
Degree Title
Bachelors Degree
Nature of Job
Work From Office