📢 New: get today's jobs on our WhatsApp Channel
Jobiglo

No results.

This job is no longer available

This job expired on 01/08/2026. It no longer accepts applications.

Junior Offensive Security Consultant

NKU Technologies · Lahore

Junior 🇬🇧 English
Burp Suite OWASP ZAP Postman Nmap Nuclei ffuf sqlmap dirsearch HTTP REST APIs authentication authorization session management cookies JWT role-based access control OWASP WSTG OWASP Top 10 OWASP API Security Top 10 Python Bash JavaScript SQL CVSS CWE MITRE ATT&CK

Job description

About the role

We are looking for a Junior Offensive Security Consultant to join our security team and perform hands‑on web application and API penetration testing. The role focuses on authorized testing, vulnerability validation, evidence collection and remediation verification, working under senior security professionals.

Key responsibilities

  • Execute web application and API penetration tests, including mapping, scope definition, testing, evidence collection and retesting.
  • Assess authentication, authorization, session management, access controls, input validation, JWT/token handling, and business logic.
  • Validate vulnerabilities such as IDOR/BOLA, broken access control, injection flaws, SSRF, privilege escalation and misconfigurations.
  • Document findings with clear technical reports, remediation guidance and retest observations.
  • Collaborate with developers, security leads and stakeholders to support remediation efforts while adhering to scope and ethical testing rules.

Required profile

  • 1–3 years of hands‑on experience in web application security, API security, vulnerability assessment or penetration testing.
  • Bachelor’s degree in Cybersecurity, Computer Science or related field (or equivalent practical experience).
  • Relevant certifications such as eJPT, PJPT, PNPT, CEH, OSCP or similar.
  • Strong documentation and communication skills.

Required skills

  • Proficiency with Burp Suite, OWASP ZAP, Postman, Nmap, Nuclei, ffuf, sqlmap, dirsearch and Linux‑based security tools.
  • Deep understanding of HTTP, REST APIs, authentication, authorization, sessions, cookies, JWTs and role‑based access control.
  • Knowledge of OWASP WSTG, OWASP Top 10 and OWASP API Security Top 10.
  • Familiarity with Python, Bash, JavaScript or SQL (preferred).
  • Awareness of CVSS, CWE, MITRE ATT&CK and remediation tracking processes.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec NKU Technologies.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 4 months ago

23 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

NKU Technologies

Lahore