Penetration Tester (Web & API)

MHMarkets

Dubai

On-site

AED 180,000 - 300,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

MHMarkets is seeking an experienced penetration tester to conduct manual testing of web apps, REST, GraphQL APIs and WebSockets in a trading environment. You will identify OWASP Top 10 and API security vulnerabilities and develop custom scripts to uncover issues missed by automation.

You will produce detailed reports with steps, risk ratings, business impact, and remediation guidance, and coordinate with DevSecOps and Infrastructure teams for remediation validation and retesting.

Qualifications

  • 3+ years of hands-on experience in web application and API penetration testing.
  • Strong practical knowledge of web application security and penetration testing methodologies.
  • Experience testing REST APIs, GraphQL, WebSockets, and modern web applications.
  • Strong scripting/programming skills in Python, JavaScript, Bash, or similar languages.
  • Understanding of AWS and/or Microsoft Azure environments and cloud-based web service architectures.
  • Ability to independently manage penetration testing engagements from scoping and testing through reporting and remediation validation.

Responsibilities

  • Conduct manual penetration testing of web applications, REST, GraphQL APIs, and WebSockets.
  • Identify vulnerabilities aligned with OWASP Top 10 and OWASP API Security Top 10.
  • Test financial and trading-specific business logic for vulnerabilities.
  • Develop custom scripts and techniques to identify issues not caught by automated scanners.
  • Produce detailed penetration testing reports with reproducible steps, risk ratings, and remediation recommendations.
  • Work with Development, DevSecOps and Infrastructure teams to validate remediation and perform retesting.

Skills

Penetration testing
Web security
API security
Python
JavaScript
Bash
Burp Suite
Cloud platforms (AWS/Azure)
Reporting & remediation validation

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field

Tools

Burp Suite

Job description

Conduct manual penetration testing of web applications, REST, GraphQL APIs, and WebSockets identify vulnerabilities aligned with OWASP Top 10 and OWASP API Security Top 10. Test financial and trading-specific business logic, including transaction manipulation, race conditions, authorization flaws, price manipulation and session-related vulnerabilities. Perform vulnerability exploitation and validation using Burp Suite and other offensive security tools. Develop custom scripts and techniques to identify vulnerabilities that automated scanners may miss. Assess authentication, authorization, session management, input validation, API security and transaction flows. Produce detailed penetration testing reports with reproducible steps, risk ratings, business impact and practical remediation recommendations. Work closely with Development, DevSecOps and Infrastructure teams to validate vulnerability remediation. Conduct retesting to ensure identified vulnerabilities have been properly resolved. Support continuous improvement of application security testing methodologies and security controls. Ensure security testing activities are conducted with minimal impact on trading systems and business operations.

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • 3+ years of hands-on experience in web application and API penetration testing.
  • Strong practical knowledge of web application security and penetration testing methodologies.
  • Advanced hands-on experience with Burp Suite and common offensive security tools.
  • Strong understanding of OWASP Top 10, OWASP API Security Top 10, authentication, authorization, session management, and business logic vulnerabilities.
  • Experience testing REST APIs, GraphQL, WebSockets, and modern web applications.
  • Strong scripting/programming skills in Python, JavaScript, Bash, or similar languages.
  • Understanding of AWS and/or Microsoft Azure environments and cloud-based web service architectures.
  • Ability to independently manage penetration testing engagements from scoping and testing through reporting and remediation validation.
  • Strong analytical, problem-solving, and reporting skills.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Web & API Penetration Tester
Senior Web & API Penetration Tester

MHMarkets • Dubai

On-site
AED 180,000 - 300,000
Penetration Tester
Penetration Tester

leading-edge • Dubai

On-site
AED 180,000 - 320,000
Penetration Testing Engineer
Penetration Testing Engineer

Tanqeeb • Dubai

On-site
AED 180,000 - 320,000
Security Tester
Security Tester

AGAPI • Dubai

On-site
AED 279,000 - 502,000
Competitive Compensation
Top-Tier Equipment
Growth & Oppotunity
+1
Senior/ Lead Penetration Test Engineer
Senior/ Lead Penetration Test Engineer

Epergne Solutions • Dubai

On-site
AED 180,000 - 250,000
Senior/ Lead Penetration Test Engineer
Senior/ Lead Penetration Test Engineer

Epergne Solutions • Abu Dhabi

On-site
AED 293,793 - 440,690
Senior Penetration Tester - Threat Hunting & Secure Coding
Senior Penetration Tester - Threat Hunting & Secure Coding

leading-edge • Dubai

On-site
AED 180,000 - 320,000
Penetration Tester
Penetration Tester

Tanqeeb • Dubai

On-site
AED 180,000 - 320,000
Security Testing Engineer (m/f/d)
Security Testing Engineer (m/f/d)

Showcify, Inc. • Abu Dhabi

On-site
AED 250,000 - 450,000
Senior Security Pen Tester – Web, Mobile & Cloud
Senior Security Pen Tester – Web, Mobile & Cloud

AGAPI • Dubai

On-site
AED 279,000 - 502,000
Competitive Compensation
Top-Tier Equipment
Growth & Oppotunity
+1