HamburgerMenu
hirist

Job Description

Role & Responsibilities :

- Lead and manage penetration testing engagements across web applications, mobile applications, APIs, networks, cloud environments, and enterprise infrastructure.

- Plan, scope, execute, and deliver security assessments aligned with industry standards such as OWASP, PTES, NIST, and CREST methodologies.

- Perform advanced penetration testing activities including :

1. Web application security testing

2. API security assessments

3. Mobile application testing (Android/iOS)

4. Network and infrastructure penetration testing

5. Active Directory security assessments

6. Cloud security assessments (AWS/Azure/GCP)

7. Red team and adversary simulation exercises

- Lead vulnerability discovery, exploitation, post-exploitation analysis, and risk validation activities.

- Review and improve penetration testing methodologies, tools, and processes.

- Mentor and guide penetration testers, security analysts, and junior team members.

- Assign tasks, review testing quality, and ensure delivery timelines are met.

- Stay updated on emerging threats, vulnerabilities, exploits, and offensive security techniques.

- Contribute to security automation initiatives, scripting, and penetration testing tool development.

- Ensure compliance with regulatory and industry requirements relevant to UAE organizations (such as PCI DSS, ISO 27001, NESA/ECS-related controls, and sector-specific security requirements).

Preferred Candidate Profile :

Experience :

- 6 to 12 years of hands-on experience in penetration testing, ethical hacking, vulnerability assessment, or offensive security.

- Proven experience leading penetration testing engagements and managing security testing teams.

- Experience working with enterprise customers, financial institutions, government organizations, or large-scale environments preferred.

- Strong experience in preparing executive-level and technical security reports.

Technical Skills :

- Strong expertise in :

1. Web application penetration testing

2. API security testing

3. Network penetration testing

4. Active Directory exploitation

5. Cloud security testing

6. Vulnerability assessment and risk management

7. Red team operations and threat emulation

- Proficiency with security tools such as :

1. Burp Suite Professional

2. Metasploit

3. Nmap

4. Nessus / Qualys

5. BloodHound

6. Cobalt Strike / similar adversary simulation tools

7. Wireshark

8. Kali Linux toolset

- Strong scripting/programming skills in Python, Bash, PowerShell, or similar languages.

- Knowledge of vulnerability research, exploit development, and security automation is an advantage.

Education :

- Bachelors degree in Computer Science, Cybersecurity, Information Security, Engineering, or related field preferred.

- Equivalent professional experience and industry certifications may be considered.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...