Dunicot A cybersecurity consultancy and advisory firm.

Careers · Pakistan · United States · Remote

We hire for curiosity, then train the rest.

The best testers we have hired were not the ones with the longest CVs. They were the ones who could not leave a system alone until they understood why it behaved the way it did.

What we look for

There is no application form and no keyword filter. Send us something you have done, a disclosure, a writeup, a tool, a CTF result, a report you are proud of, and tell us what you want to work on. That gets read by a person.

What matters

Demonstrated work
Disclosures, CTF placings, bug bounty record, published tooling or writeups
Curiosity
Evidence that you take systems apart to understand them, not only to pass an exam
Writing
Findings are worthless if the engineer cannot act on them, clear writing is a core skill here
Honesty
Saying “I do not know” is a strength in this job. Every finding you report will be scrutinised
Degree
Not required
Certifications
Helpful, and funded once you are here if you do not have them

Roles we hire for

We keep applications open continuously rather than only when a role is posted, good testers do not appear on a schedule. Current areas of interest:

  • Penetration tester, web and API
  • Penetration tester, mobile
  • Cloud security specialist
  • Red team operator
  • Detection engineer
  • Threat hunter
  • Malware analyst
  • DFIR consultant
  • Security trainer
  • Technical report writer
  • Internships, Karachi
Send your work to [email protected]

Questions: from candidates

Do I need a degree?

No. We care what you can demonstrate: disclosed vulnerabilities, CTF results, a bug bounty record, tools you have written, writeups you have published. Several of the strongest testers in this industry have no formal computer science education, and a portfolio beats a transcript in every hiring conversation we have.

Do I need certifications to apply?

Not to apply. OSCP or equivalent helps, and if you do not have one we will fund it once you are here, certification budget and study time are part of the package, not a personal expense.

What does the hiring process look like?

A conversation about your background, then a practical assessment on a deliberately vulnerable environment, then a technical discussion of your approach with the Principal Consultant. No whiteboard algorithm puzzles. We want to see how you think about an unfamiliar system, because that is the actual job.

Can I work remotely?

Hybrid from Karachi or Sheridan, and fully remote for candidates whose experience justifies it. Some engagements require on-site presence, such as internal network testing and branch and terminal work, so complete remoteness is not possible for every role.

Is there time for research?

Yes, and it is protected rather than aspirational. Bug bounty work, tool development and writing for the research section are part of the role. The firm’s reputation is built on that output, so it is treated as work rather than as a hobby to fit around work.