This job is no longer available
This job expired on 04/09/2026. It no longer accepts applications.
Security Engineer
Magnatec Systems Private Limited · Lahore
Job description
About the role
We are hiring a hands‑on penetration testing engineer to assess the security of our web applications, mobile platforms, and APIs. The role requires deep manual testing, a strong methodology, and clear reporting at every phase.
Key responsibilities
- Perform manual black‑box and grey‑box testing of web, mobile (Android & iOS) and API services following OWASP Top 10, MASVS and API Security Top 10.
- Identify and exploit vulnerabilities such as SQLi, XSS, CSRF, IDOR, SSRF, broken authentication, access‑control flaws, and JWT/OAuth issues.
- Assess session management, cookies, HTTP headers, client‑side JavaScript, and mobile app storage.
- Reverse‑engineer Android/iOS packages, detect hard‑coded secrets, bypass SSL pinning, and test biometric flows.
- Produce CVSS‑scored findings with reproducible steps, screenshots, and proof‑of‑concept code.
- Deliver executive summaries for management and detailed technical reports for developers, including remediation road‑maps and re‑testing.
Required profile
- 3+ years of hands‑on penetration testing with a focus on web and mobile applications.
- Strong knowledge of OWASP Top 10, OWASP MASVS, and OWASP API Security Top 10.
- Practical experience testing Android and iOS applications.
- Ability to write professional reports for both technical and non‑technical audiences.
Required skills
- Burp Suite Pro
- OWASP ZAP
- SQLMap
- Nikto
- Gobuster
- MobSF
- jadx
- apktool
- Frida
- Objection
- ADB
- Charles Proxy
- Postman
- jwt_tool
- InQL
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Pakistan.
Salary: Software Engineer - E-Commerce (Remote) Based on 30 job offers in PakistanSalaries by job title
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Magnatec Systems Private Limited
Lahore