Security Tester

AGAPI

Dubai

On-site

AED 279,000 - 502,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive Compensation
Top-Tier Equipment
Growth & Oppotunity
Thriving Culture

Job summary

AGAPI is seeking a Security Tester to perform advanced, hands-on security testing across web, mobile, API, cloud, and internal systems. You will chain vulnerabilities into realistic attack paths and deliver detailed reports with actionable remediation guidance.

The role emphasizes evidence-driven demonstrations, practical exploitation scenarios, and clear communication to strengthen the organization’s security posture and defense strategies.

Qualifications

  • 4+ years of hands-on penetration testing experience.
  • Proficiency in web application security, OWASP Top 10 and advanced issues.
  • Strong mobile security skills (iOS/Android) with Frida and MobSF.
  • Cloud security knowledge in AWS/GCP, IAM misconfigurations and privilege escalation.
  • Burp Suite Pro proficiency; scripting in Python, Bash or PowerShell.

Responsibilities

  • Execute advanced, hands-on penetration testing across web, mobile, API, cloud, and internal systems.
  • Chain vulnerabilities into realistic attack paths with evidence-based demonstrations.
  • Deliver polished reports outlining methodologies, impact and remediation guidance.
  • Provide recommendations aligned with architecture and feasible for engineering teams.
  • Contribute to improving the organization’s overall security posture and defenses.
  • Perform additional security tasks as directed by the Line Manager.

Skills

Web application security
OWASP Top 10
Mobile security
Cloud security AWS/GCP
Burp Suite Pro
Frida
MobSF
Python
Bash
PowerShell
GraphQL
IAM misconfigurations

Tools

Burp Suite Pro
Frida
MobSF
Python
Bash
PowerShell

Job description

Role Summary:

The Security Tester is responsible for performing advanced, hands-on security testing across web, mobile, API, cloud, and internal systems. The role focuses on identifying high-impact vulnerabilities, chaining issues into realistic attack scenarios, and clearly communicating risks through strong evidence and reporting. You will provide practical remediation guidance and play a key part in strengthening the organization’s overall security posture.

Responsibilities:

  • Execute advanced, hands-on penetration testing across diverse environments, including web applications, mobile apps (iOS/Android), APIs, cloud platforms (AWS/GCP), and complex internal systems.
  • Focus on core application components (APIs, authentication flows, and IAM configurations) where high-impact vulnerabilities typically emerge.
  • Go beyond identifying standalone issues by chaining multiple vulnerabilities into realistic, high-severity attack paths.
  • Demonstrate how minor findings can evolve into major risks (e.g., XSS → token theft → privilege escalation → full system compromise).
  • Communicate risks clearly and convincingly through evidence-driven demonstrations and practical exploitation scenarios.
  • Deliver polished, detailed reports outlining attack methodologies, impact assessments, and clear, actionable remediation guidance.
  • Provide recommendations that are aligned with the system’s architecture and feasible for engineering teams to implement.
  • Contribute to enhancing the organization’s overall security posture and defense strategies.
  • Perform additional security-related tasks as directed by the Line Manager.

Requirements:

  • At least 4 years of hands-on experience in penetration testing.
  • Strong proficiency in Web Application Security, including OWASP Top 10 and advanced issues such as blind injections, insecure deserialization, business logic abuses, SSRF, and API/GraphQL vulnerabilities.
  • Solid experience in Mobile Security (iOS/Android), including static/dynamic analysis with tools like Frida and MobSF, and understanding mobile-specific risks such as insecure data storage and reverse-engineering defenses.
  • Strong knowledge of Cloud Security in AWS/GCP, particularly around misconfigurations, excessive IAM permissions, exposed storage, and cloud privilege escalation techniques.
  • Proficiency with Burp Suite Pro and the ability to develop custom scripts or tools using Python, Bash, or PowerShell.
  • A true hacker mindset, capable of correlating subtle weaknesses into impactful attack scenarios and thinking adversarially to uncover systemic risks.

What we offer:

  • Competitive Compensation: Enjoy a salary package tailored to your skills and experience, along with performance-based bonuses.
  • Top-Tier Equipment: Stay productive with the latest tools, including a MacBook and iPhone, to maximize productivity.
  • Growth & Oppotunity: Join a fast-growing, international environment with room to expand your expertise and take on new challenges.
  • Thriving Culture: Immerse yourself in a dynamic, inclusive work environment that values innovation, ownership, and continous learning.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

Tanqeeb • Dubai

On-site
AED 180,000 - 320,000
Penetration Tester
Penetration Tester

leading-edge • Dubai

On-site
AED 180,000 - 320,000
Penetration Tester (Web & API)
Penetration Tester (Web & API)

MHMarkets • Dubai

On-site
AED 180,000 - 300,000
Security Testing Engineer (m/f/d)
Security Testing Engineer (m/f/d)

Showcify, Inc. • Abu Dhabi

On-site
AED 250,000 - 450,000
Senior/ Lead Penetration Test Engineer
Senior/ Lead Penetration Test Engineer

Epergne Solutions • Dubai

On-site
AED 180,000 - 250,000
Senior/ Lead Penetration Test Engineer
Senior/ Lead Penetration Test Engineer

Epergne Solutions • Abu Dhabi

On-site
AED 293,793 - 440,690
Senior Security Pen Tester – Web, Mobile & Cloud
Senior Security Pen Tester – Web, Mobile & Cloud

AGAPI • Dubai

On-site
AED 279,000 - 502,000
Competitive Compensation
Top-Tier Equipment
Growth & Oppotunity
+1
Senior Penetration Tester - Threat Hunting & Secure Coding
Senior Penetration Tester - Threat Hunting & Secure Coding

leading-edge • Dubai

On-site
AED 180,000 - 320,000
Security Engineer
Security Engineer

Dicetek LLC • Dubai

On-site
AED 350,000 - 600,000
Penetration Testing Engineer
Penetration Testing Engineer

Tanqeeb • Dubai

On-site
AED 180,000 - 320,000