Enable job alerts via email!
A cybersecurity firm based in Dubai is seeking a Penetration Tester to simulate cyberattacks, identify security vulnerabilities, and recommend remediation measures. The ideal candidate will conduct comprehensive security assessments across systems, applications, and networks while preparing detailed reports for clients and stakeholders. Experience in cloud security testing and knowledge of OWASP standards are essential.
The Penetration Tester is responsible for simulating cyberattacks to identify security vulnerabilities across systems, applications, networks, and devices. The role involves recommending remediation measures to strengthen security defenses and mitigate risks.
2. Key Responsibilities
System & Network Security Testing
• Perform vulnerability assessments on systems, including Windows, Linux, Cloud, and Kubernetes environments.
• Conduct internal network penetration tests targeting VPN, firewalls, IDS/IPS, and other network components.
• Assess and exploit security weaknesses in cloud infrastructure (AWS, Azure, GCP).
Application Security Testing (Web, Mobile, API, Thick Client)
• Test for vulnerabilities based on OWASP Top 10, API Security Top 10, and Mobile Top 10 standards.
• Evaluate application security across Android, iOS, Windows, macOS, and Linux platforms.
• Test RESTful APIs, GraphQL, and SOAP APIs using tools such as Burp Suite, Postman, ZAP, and mitmproxy.
Advanced Penetration Testing
• Perform Red Team operations and adversary simulations to emulate real-world attack scenarios.
• Leverage advanced attack techniques, including privilege escalation, lateral movement, and evasion tactics.
• Conduct Active Directory (AD) security assessments.
• Execute social engineering campaigns, including phishing, vishing, and smishing.
Analysis & Reporting
• Prepare detailed technical reports outlining vulnerabilities and recommended remediation actions.
• Present findings to clients, developers, and stakeholders.
• Support DevSecOps initiatives by integrating security testing into the CI/CD pipeline.