Web Application Penetration Testers

Job Description

🚨 WE’RE HIRING | Web Application Penetration Testers

📍 Location: DHA Phase 8, Ex Parkview, Lahore – On-site

🕐 Time Zone: Pacific Standard Time (PST)

👥 Open Positions: 5

💼 Experience: 4–5 Years

🏢 Company: Bytei360

Bytei360 is looking for experienced Web Application Penetration Testers to join our security team. You’ll work on real-world security assessments while leveraging our internal penetration testing tools and AI agents to accelerate testing, investigation, and professional report generation.

🔐 What You’ll Do

Perform black-box web application penetration testing across insurance and financial services platforms.
Assess customer portals, claims systems, payment flows, APIs, and internal dashboards.
Operate and supervise our AI-powered penetration testing agent, manually taking over when deeper investigation or exploitation is required.
Test complex authentication and authorisation mechanisms including SSO, OAuth, SAML, JWT, and multi-tenant access controls.
Identify business logic vulnerabilities that automated scanners often miss.
Manually validate and exploit vulnerabilities such as SQL Injection, XSS, CSRF, SSRF, XXE, IDOR, privilege escalation, insecure deserialization, and API vulnerabilities.
Develop custom scripts and Proofs of Concept using Python, JavaScript, or Bash.
Produce clear, professional penetration testing reports with technical findings, actionable remediation guidance, and executive summaries.
Manage multiple concurrent security engagements across different customer environments.

🛡️ What We’re Looking For

4–5 years of full-time Web Application Penetration Testing experience as a primary responsibility.
At least one certification: OSCP, OSCE, CREST, or PCI.
Strong hands-on experience with Burp Suite Professional — Proxy, Repeater, Intruder, Extensions, etc.
Strong practical knowledge of the OWASP Top 10 with the ability to manually identify and exploit vulnerabilities.
Strong experience in web application and API security testing.
Proven ability to identify business logic, IDOR, privilege escalation, and access control vulnerabilities.

Strong scripting skills in Python, JavaScript, or Bash.
Excellent technical report writing and client/stakeholder communication.
Experience working with insurance or financial services platforms is highly preferred.
 

Job Summary

  • Published on:2026-09-26 6:37 am
  • Vacancy:1
  • Employment Status:Full Time
  • Experience:4 Years
  • Job Location:Lahore
  • Gender:No Preference
  • Application Deadline: 2026-11-10