Mid-Level Penetration Tester
Views: 47
Posted: 2026-05-21
Expires: 2026-06-04
ExpiredJob Vacancy: Mid-Level Penetration Tester
RedSecLabs | Islamabad | Hybrid
The Role
We need someone who can actually do the work โ mobile apps, APIs, network infrastructure. You'll be running assessments end-to-end, writing reports that clients can act on, and sitting in on debriefs. This is a hands-on role. If you're looking to grow your offensive security skills on real client engagements, this is it.
What You'll Be Doing
- Mobile pentests on Android & iOS โ static/dynamic analysis, reverse engineering, SSL unpinning
- API security assessments โ REST, GraphQL, SOAP โ auth flaws, injection, business logic issues
- Network infrastructure testing โ internal/external assessments, firewall reviews, AD/domain security
- Writing clear, actionable reports for technical teams and non-technical stakeholders
- Working with the red team on scoping, methodology, and client debriefs
- Keeping up with new CVEs, attack techniques, and tooling
What We're Looking For
- 2โ4 years of real penetration testing experience
Comfortable with OWASP Mobile Top 10 and OWASP API Security Top 10
- Experience bypassing cert pinning, analyzing APKs/IPAs, testing API auth flows
- Solid scripting โ Python, Bash, or similar
Strong written and verbal English for client-facing work
Good to Have
Certs: OSCP, eWPTX, eMAPT, CEH, or equivalent
Cloud experience โ AWS, Azure, GCP
Background in a consultancy or MSSP setting
What We Offer
Competitive, market-aligned salary
Hybrid setup โ Islamabad office
Real-world client work, not lab exercises
Clear growth path within a specialist firm
Send your resumes to:
๐ฉ hafsa@redseclabs.com
๐ Islamabad@RedSecLabs#Mid-Level Penetration Tester๐งณ Experienced Required