Deputy Director (Vulnerability Assessment and Penetration Testing - VAPT)
National Database & Registration Authority
NADRA is hiring a Deputy Director (VAPT) on contract in Islamabad to lead application and network penetration testing. Apply online by 20 Sep 2026.
Apply before 20 September 2026. Full application steps and eligibility criteria are below.
About This Job
NADRA is recruiting a Deputy Director for Vulnerability Assessment and Penetration Testing (VAPT) on a contractual basis, based in Islamabad. This is a specialist cybersecurity role focused on proactively identifying weaknesses in NADRA's applications and network infrastructure before they can be exploited — the position is responsible for conducting desktop, web, and mobile application penetration testing, performing source-code reviews and both static and dynamic application security testing (SAST/DAST), and deploying industry-standard tools such as Metasploit, Burp Suite, Nessus, and Kali Linux. Given NADRA's role as custodian of Pakistan's national identity database, this position carries significant responsibility for safeguarding some of the country's most sensitive citizen data against evolving cyber threats.
Candidates need a four-year Bachelor's degree in Computer Science, Information Technology, Cyber Security, Information Security, or an equivalent related field, with a Master's degree in a relevant discipline preferred; a minimum of 16 years of HEC-verified education is mandatory and all degrees must carry HEC attestation. At least six years of post-qualification experience in application or network security and penetration testing is required, and candidates holding CEH or CHFI certification, along with familiarity in Gen AI-assisted penetration-testing tools, will be preferred. The maximum age limit is 44 years, inclusive of the standard five-year general age relaxation. The advertisement is open to both genders, with NADRA encouraging applications from female, minority, transgender, and differently-abled candidates, and government or semi-government employees must provide a No Objection Certificate at the interview stage.
Eligible applicants should apply online exclusively via NADRA's official careers portal at careers.nadra.gov.pk; the advertisement does not specify any application fee. The selected candidate will serve a six-month probationary period, extendable subject to performance, and only shortlisted candidates will be called for test and interview, where HEC-attested degrees, medical fitness, and character certificates must be presented. Applications close on 20 September 2026, so candidates with the relevant penetration-testing and application-security background are encouraged to apply promptly.
Job Information
- Commission / Board
- NADRA
- Place of posting
- Anywhere in Federal
- City
- Islamabad
- Postal Code
- 44000
- Domicile
- All Punjab Basis
- Age (Male)
- 18–44 years
- Age (Female)
- 18–44 years
- Age note
- Maximum age 44 years; 5-year general age relaxation already included in this figure.
- Salary / BPS
- Contract basis - Salary as per contract terms and experience
- Advt. date
- 6 September 2026
- Last date
- 20 September 2026
Qualification Required
- Qualification: Bachelor's (4 years) in Computer Science, Information Technology, Cyber Security, Information Security, or equivalent, with a Master's degree preferred; minimum 16 years of HEC-verified education, degrees must be HEC-attested.
- Experience: Minimum 6 years post-qualification experience in application/network security and penetration testing; CEH and CHFI certification preferred, with familiarity in Gen AI-assisted security testing tools.
Important Dates
- Advertisement date
- 6 September 2026
How to Apply
- Visit official website at www.nadra.gov.pk
- Create account or login with your CNIC number
- Fill online application form with CNIC, domicile and education details
- Upload required documents and submit before last date — 20 September 2026
Additional Details
- Terms Summary
- 6-month probation period, extendable subject to performance,5-year general age relaxation already included in the stated age limit,Government/semi-government employees must submit a No Objection Certificate (NOC) at interview,Only shortlisted candidates will be called for test/interview; no TA/DA admissible,Attested HEC/regulatory-body educational documents required at joining,Females, minorities, transgender and differently-abled candidates encouraged to apply,Electronic gadgets (mobile phones, smart watches) not allowed during test/interview
- Responsibilities
- Conduct desktop, web and mobile application penetration testing,Perform source code reviews and static/dynamic application security testing (SAST/DAST),Deploy and operate security tools including Metasploit, Burp Suite, Nessus, Kali Linux and mobile security testing tools,Work with application development teams on system, encryption, authentication and secure-code practices,Assess web applications, mobile applications and APIs, and produce technical reports and recommendations,Integrate security into the software development lifecycle (SDLC) in collaboration with infrastructure teams,Apply knowledge of Cloud Security, containerization and DevSecOps practices
Share This Job
More Jobs at National Database & Registration Authority
Assistant Director (Database Security)
ActiveAssistant Director (Legal)
ActiveDeputy Director (Governance, Risk Assessment & Compliance)
ActiveJunior Executive (Data Entry Operator)
Closing SoonOther NADRA Recruitments
See all NADRA jobs →Explore More Government Jobs
Not the right role? Browse more NADRA . You can also see today’s new listings or browse the full jobs index.
Comments
Ask a question or share information about this job. Be respectful — comments are public.
Loading comments…