September 23, 2026
My Journey as a Penetration Tester
Author: Haroon Atieeq Role: Junior Penetration Tester, CSZone Pvt. Limited Location: Pakistan Focus Areas: Offensive Security…
By Haroon Attique
3 min read
Author: Haroon Atieeq Role: Junior Penetration Tester, CSZone Pvt. Limited Location: Pakistan Focus Areas: Offensive Security, Penetration Testing, VAPT, API Security
About Me
I am Haroon Atieeq, a Junior Penetration Tester based in Bahawalpur, Pakistan, currently working with CSZone Pvt. Limited. My work centers on Vulnerability Assessment and Penetration Testing (VAPT) for international clients, and this article is an honest look at how I got here, what I actually do, and where I am headed next.
Where It Started
My interest in security did not begin as an afterthought to a general computer science path. I pursued a BS in Cyber Security and Digital Forensics at Islamia University of Bahawalpur, a degree that gave me a structured foundation in how systems fail and how to find those failures before someone else does. My final year project, CyberMaze, won the Best Final Year Project Award and was published in IEEE, which remains one of the achievements I am most proud of from that stage of my career.
Getting there was not as straightforward as it might sound. Cyber security is a massive field with dozens of domains and sub-domains, and by the last semester of my degree, I still had not fully figured out where I fit. Network security, application security, digital forensics, malware analysis, GRC, red teaming, there were so many directions to consider, and just as many questions running through my mind about which one matched my interest, my skill set, and where I actually wanted my career to go. That period of uncertainty was genuinely one of the harder parts of my journey.
Before I settled into offensive security specifically, I spent time across a few different technical roles:
- Django backend development at Skill Evokers
- Technical support at Sybrid
- Cybersecurity instruction at Tech Hub NAVTAC
- Offensive security internship at ITSolera
It was actually my time in backend development that gave me clarity. Once I understood how a web application is built end to end, penetration testing started to make sense as the domain that fit me best. When you understand a website's complete workflow, it becomes far easier to test it properly and uncover the vulnerabilities hiding inside it.
Each of these roles taught me something that directly feeds into how I approach penetration testing today. Backend development gave me a clearer view of how applications are actually built, which makes it easier to spot where they break. Teaching forced me to explain security concepts clearly, a skill that matters as much in client reporting as it does in a classroom. The internship at ITSolera was where I got my first real exposure to structured, methodology-driven testing.
That clarity feels more relevant now than ever. In my experience, a large majority of the websites, web applications, and Android apps being built today are AI-assisted or "vibe-coded," often with little to no security consideration built in from the start. That shift is exactly why this work matters: regardless of how something gets built, someone still has to test it properly before it goes live.
What I Do Now
At CSZone, I conduct VAPT engagements for international clients, following industry-recognized methodologies:
- OWASP WSTG (Web Security Testing Guide)
- PTES (Penetration Testing Execution Standard)
- NIST SP 800–115
Findings are mapped against recognized frameworks depending on client requirements, including:
- OWASP Top 10
- ISO 27001
- NIST SP 800–53
- GDPR
I hold the Certified Ethical Hacker (CEH) certification, and I am continuously building toward more advanced, internationally recognized certifications as the next step in my technical growth.
Alongside my role at CSZone, I work remotely with international companies, including Microsoft, and other global clients, and I provide cybersecurity services to CSZone and other educational institutions in Pakistan. I also freelance on Upwork and Fiverr, where I have built out dedicated service catalogs for VAPT and API Penetration Testing.
Projects I Have Built
Beyond client engagements, I have worked on a few platforms that reflect how I think about security education and training.
CSZone CTFA: training range built to give learners a hands-on environment to practice real attack scenarios.
CSZone CyberGrid: An enterprise-grade CTF competition and training platform.
Master VAPT Testing PlaybookA structured reference tool built to document and standardize penetration testing methodology.
How I Approach the Work
I consider myself a junior penetration tester, not a senior or expert one, and I say that deliberately. The field moves fast, and pretending otherwise does not help anyone, least of all the clients whose systems I am testing.
What I bring instead is consistency:
- A methodology-first approach to every engagement
- A habit of mapping every finding back to a recognized standard
- A genuine, ongoing effort to keep learning past whatever certification I currently hold
What's Next
I am continuing to:
- Build toward internationally recognized offensive security certifications
- Deepen my work in API security testing
- Stay involved in both client-facing VAPT work and the training platforms I have built for the broader security community in Pakistan
Let's Connect
If you work in offensive security, VAPT, or are building something in this space and want to connect, I am always open to a conversation.
- LinkedIn: www.linkedin.com/in/haroon-atieeque-2b8867378
- Email: haroonatieeq6@gmail.com
- GitHub: github.com/haroonatieeq352