Software Engineer - Security Testing

Lahore, Punjab 2 Positions

Job Description

  • Conduct vulnerability assessments and penetration testing across web applications, mobile apps, APIs, and network infrastructure.
  • Perform manual and automated security testing using tools such as Burp Suite, OWASP ZAP, Nessus, Nmap, and Metasploit.
  • Execute security test cases aligned with OWASP Top 10, OWASP ASVS, API Security Top 10, and CWE/SANS Top 25.
  • Identify, document, and report vulnerabilities with severity ratings (CVSS), proof-of-concept evidence, and remediation guidance.
  • Conduct dynamic application security testing (DAST) and interactive testing (IAST) as part of CI/CD pipelines.
  • Identify, validate, and reproduce vulnerabilities such as XSS, SQL Injection, CSRF, authentication weaknesses, authorization flaws, SSRF, security misconfigurations, and sensitive data exposure.
  • Assess HTTP security headers, and TLS/SSL implementations.
  • Perform cloud security assessments covering misconfigurations, and exposed services.
  • Validate remediation efforts through retesting and track vulnerabilities to closure.
  • Maintain and improve internal security testing tools, scripts, and automation frameworks.
  • Stay current with emerging threats, zero-days, CVEs, and evolving attack techniques.
  • Improve security testing processes, research emerging vulnerabilities and threats, mentor junior team members, and share technical knowledge across the team.
  • Conduct secure design reviews, architecture reviews, and threat modeling activities during the software development lifecycle.

We are Looking For:

 

Education

Bachelor's Degree

 

Experience

1 Year

 

Skills

  • QA Testing

Tools

  • Hands on any Security Testing Tools

Learn more about i2c

Explore our latest press releases, media coverage, industry events and thought leadership content that reveal how we’re outpacing the competition and shaping what's next.

Ignite Your Curiosity