Senior OT/IT Penetration Tester

Job Category: Technical
Job Type: On-Site
Job Location: Lahore

The Senior OT/IT Penetration Tester will lead penetration testing engagements across enterprise IT networks and industrial OT environments for Catalyic Security’s clients. You will identify vulnerabilities in critical systems, ensure testing is carried out safely in sensitive operational settings, deliver clear remediation guidance, and guide junior testers on the team.

Key Responsibilities

  • Lead end-to-end IT and OT penetration testing engagements
  • Assess enterprise and industrial systems, including:
    • Active Directory and internal network infrastructure
    • ICS/SCADA systems, PLCs, HMIs, and historians
    • Industrial protocols such as Modbus, DNP3, and OPC
    • IT/OT network segmentation and remote access pathways
  • Plan and execute testing with safety controls to avoid disruption to live operations
  • Identify vulnerabilities, misconfigurations, and attack paths across converged environments
  • Document findings in clear, actionable technical reports
  • Recommend fixes and support client teams through remediation
  • Guide junior testers on methodology, tooling, and safe testing practices

Required Skills & Experience

  • 5+ years of experience in penetration testing, with demonstrated OT assessment experience
  • Strong knowledge of Windows, Linux, and Active Directory attack techniques
  • Hands-on experience with industrial control systems and OT network architectures
  • Familiarity with standards and frameworks such as IEC 62443, NIST SP 800-82, and MITRE ATT&CK for ICS
  • Proficiency with tools such as Burp Suite, Nmap, Metasploit, BloodHound, and Wireshark
  • Strong report writing and technical communication skills
  • Ability to lead engagements and manage multiple projects

Education & Certifications (Preferred)

  • Bachelor’s degree in Cyber Security, Computer Science, IT, or a related field
  • Relevant certifications preferred, with demonstrated OT assessment experience:
    • OSCP / OSCP+ (Offensive Security Certified Professional)
    • CRTP (Certified Red Team Professional)

Apply for this position

Drop files here or click to uploadMaximum allowed file size is 10 MB.
Allowed Type(s): .pdf, .doc, .docx