HimalayasHimalayas logo
ICE ConsultingIC

Penetration Tester

ICE Consulting offers comprehensive managed IT and cybersecurity services, specializing in solutions for small to medium-sized enterprises, particularly in the biotech and life sciences industries, since 1997.

ICE Consulting

Employee count: 51-200

Pakistan only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Job Overview
We are looking for a motivated and skilled Penetration Tester with hands-on experience in Active Directory, Network, and Web Application penetration testing. The ideal candidate should be able to identify security vulnerabilities, misconfigurations, and weaknesses across enterprise environments and provide actionable recommendations to improve the organization's security posture.
In addition to traditional penetration testing, the candidate will participate in purple-team exercises, collaborating with defensive teams to simulate real-world attack scenarios and strengthen detection and response capabilities. An interest in SOC operations, monitoring, and threat detection will be considered a strong advantage.

Key Responsibilities

  • Perform Active Directory penetration testing to identify privilege escalation paths, insecure configurations, and potential lateral movement opportunities.
  • Conduct internal and external network penetration tests to identify vulnerabilities and weaknesses within the enterprise infrastructure.
  • Perform web application penetration testing, including authentication testing, input validation, session management, and business logic testing.
  • Identify and analyze security misconfigurations across systems, services, and network infrastructure.
  • Conduct security audits and configuration reviews to identify gaps against security best practices and industry standards.
  • Perform risk assessments by evaluating vulnerabilities, misconfigurations, and their potential business impact.
  • Document security findings, misconfigurations, and vulnerabilities with clear risk ratings and remediation guidance.
  • Participate in purple team engagements by simulating attacker techniques and helping SOC teams improve detection and response capabilities.
  • Support threat simulation exercises based on real-world attack techniques and frameworks such as MITRE ATT&CK.
  • Work closely with SOC and defensive teams to improve alerting, monitoring, and threat detection use cases.
  • Assist in validating remediation efforts by performing retesting and verification of fixes.
  • Prepare technical and executive-level reports summarizing findings, risks, and recommended mitigation strategies.

Requirements

Required Skills & Experience
• Hands-on experience in Active Directory security assessments and penetration testing
• Strong knowledge of network penetration testing methodologies
• Experience in web application security testing (OWASP Top 10)
• Understanding of security configuration reviews and misconfiguration analysis
• Experience performing vulnerability validation and risk analysis
• Hands-on experience with tools such as:

  • Nmap
  • Burp Suite
  • Metasploit
  • BloodHound
  • Impacket
  • CrackMapExec

• Strong understanding of Windows security architecture and AD attack techniques
• Knowledge of network protocols, authentication mechanisms, and common attack vectors
Nice to Have

  • Experience with Purple Team exercises
  • Exposure to SOC operations, SIEM platforms, or security monitoring
  • Familiarity with MITRE ATT&CK framework
  • Scripting knowledge (Python, PowerShell, Bash)
  • Exposure to cloud security assessments (Azure / AWS)

Preferred Certifications (Optional)

  • PNPT
  • eCPPT
  • GPEN / GWAPT


Soft Skills

  • Strong analytical and problem-solving mindset
  • Ability to clearly communicate technical risks and remediation steps
  • Good documentation and reporting skills
  • Ability to collaborate with both offensive and defensive security teams
  • Strong curiosity and passion for continuous learning in cybersecurity

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Mid-level

Location requirements

Hiring timezones

Pakistan +/- 0 hours

About ICE Consulting

Learn more about ICE Consulting and their company culture.

View company profile

Through groundbreaking technology, we are revolutionizing IT management and cybersecurity at ICE Consulting, Inc. Founded in 1997 by Uzair Sattar, our company has dedicated over two decades to providing comprehensive managed IT services and managed security services tailored for small to medium-sized enterprise clients, with a particular emphasis on the biotech and life sciences sectors. We pride ourselves on delivering end-to-end, vendor-independent managed IT solutions and possess specialized expertise in cybersecurity monitoring and response, also known as Security Operations Center-as-a-Service (SOCaaS). Our innovative approach allows us to function as a standalone IT department for our clients or to provide expert IT consulting services that supplement and complement their internal IT teams. We are committed to taking care of our clients' IT infrastructure, whether on-cloud or on-premise, enabling them to focus on their core business operations. ICE Consulting is equipped to audit, design, configure, install, and maintain complex IT systems, positioning us as a single source for all IT needs.

Our operational philosophy centers on integrity, collaboration, and experience, ensuring that we provide the high level of service and expertise our clients require, while maintaining the personalized attention they deserve. Headquartered in Milpitas, in the heart of Silicon Valley, ICE Consulting has expanded its reach to serve clients from San Francisco to San Diego, and supports remote offices globally, including in Asia, Europe, and South America. Our international presence is further solidified by a fully owned and operated office in Asia. We are SOC 2 Certified, a testament to our commitment to the security, confidentiality, and privacy of our clients' data. This certification is crucial, especially as we help numerous companies navigate various compliance requirements such as ISO 27001, NIST, HIPAA, GDPR, and more. Our specialized team of engineering and support staff, coupled with our consultative approach to IT compliance, processes, procedures, and security, allows us to implement IT best practices effectively. We leverage partnerships with leading technology vendors like VMware, Okta, CarbonBlack, Microsoft, FortiGate, and Palo Alto Networks to design and execute robust cloud technology stacks and IT infrastructures for our clients. Our dedication to client satisfaction is reflected in our 97% client satisfaction score from over 5,000 reviews.

Employee benefits

Learn about the employee benefits and perks provided at ICE Consulting.

View benefits

Company Paid Holidays

Company Paid Holidays

401(k) with company match

401(k) with company match

Retirement Plan (401k, IRA)

Retirement Plan (401k, IRA)

Health Care Plan (Medical, Dental & Vision)

Health Care Plan (Medical, Dental & Vision)

View ICE Consulting's employee benefits
Claim this profileICE Consulting logoIC

ICE Consulting

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

2 remote jobs at ICE Consulting

Explore the variety of open remote roles at ICE Consulting, offering flexible work options across multiple disciplines and skill levels.

View all jobs at ICE Consulting

Remote companies like ICE Consulting

Find your next opportunity by exploring profiles of companies that are similar to ICE Consulting. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan