Senior Consultant - Digital Trust (Cyber Defense)

Remotedxb

Dubai

On-site

AED 300,000 - 540,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

KPMG in Dubai is seeking an experienced Senior Penetration Tester to lead offensive security engagements across web, mobile, API, and cloud environments. You will plan, execute, and report on VAPT activities, working closely with client teams to understand risk and deliver actionable results.

You will participate in red team exercises, social engineering, and adversary emulation using MITRE ATT&CK, while mentoring junior staff and contributing to business development efforts.

Qualifications

  • Minimum 5+ years of offensive security and VAPT experience.
  • Solid knowledge of OWASP, PTES, and NIST methodologies.
  • Hands-on experience across Web, Mobile, API, LLM, cloud, and network VAPT assessments.
  • Secure source code reviews in JavaScript, C#, Python, Swift, Java, or SQL.
  • Consulting background (Big Four experience a plus).

Responsibilities

  • Execute penetration tests across web, mobile, APIs, and network infrastructure.
  • Participate in red team and social engineering engagements, including phishing.
  • Set up and operate C2 infrastructure using tools like Cobalt Strike or Sliver.
  • Contribute to adversary emulation exercises based on MITRE ATT&CK.
  • Prepare detailed, risk-based reports and present findings to clients.
  • Develop internal tooling, scripts, and documentation for offensive testing.
  • Collaborate with blue/purple teams to improve client defenses.
  • Support business development through proposals and budgeting.
  • Foster constructive client relationships and maintain professional network.

Skills

Red team
Purple team
Client engagement
Cyber security strategy
VAPT methodologies

Education

Bachelor's degree in Computer Science, Information Security, or a related field

Tools

Burp Suite
Nmap
Metasploit
BloodHound

Job description

Responsibilities
  • Executing penetration tests of web applications, mobile applications, APIs, and network infrastructure
  • Participating in red team and social engineering engagements, including phishing and physical intrusion scenarios
  • Setting up, maintaining, and operating C2 infrastructure using tools such as Cobalt Strike or Sliver
  • Assisting in adversary emulation exercises based on frameworks like MITRE ATT&CK
  • Preparing detailed, risk-based reports and presenting technical findings to internal and client teams
  • Developing and maintaining internal tools, scripts, and documentation for offensive testing
  • Collaborating with blue/purple teams to improve client defenses
  • Supporting business development activities including proposal development and budgeting
  • Developing constructive client relationships and maintaining a professional network
Requirements
  • At least 5+ years of experience in cyber security with a focus on offensive security and VAPT
  • Strong understanding of penetration testing methodologies such as OWASP, PTES, or NIST
  • Practical experience in Web, Mobile, API, LLM, cloud, and network-based VAPT assessments
  • Experience conducting secure source code reviews in languages like JavaScript, C#, Python, Swift, Java, or SQL
  • Practical experience with red teaming and purple teaming concepts
  • Experience in a consulting environment (Big Four experience is a plus)
  • Bachelor's degree in Computer Science, Information Security, or a related field
  • Mandatory OSCP certification plus at least one of: OSEP, OSWE, CCT INF, or CCT APP
  • Proficiency with tools like Burp Suite, Nmap, Metasploit, and BloodHound
  • Proficiency in at least one scripting language (Python, PowerShell, or Bash) and one programming language (Java, C#, or JavaScript)
About the Company

KPMG is a global leader in professional services, providing expertise in digital trust, cyber defense, and risk management to clients across various sectors.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Senior Red Team & Offensive Security Consultant
Remote Senior Red Team & Offensive Security Consultant

KPMG Middle East • United Arab Emirates

On-site
AED 250,000 - 450,000
Principal / Senior Red Team Services Consultant
Principal / Senior Red Team Services Consultant

Crowdstrike • United Arab Emirates

On-site
AED 240,000 - 480,000
Market-leading compensation and equity
Wellness programs
Generous vacation and holidays
+5
Security Consultant
Security Consultant

Epergne Solutions • Dubai

On-site
Security Consultant
Security Consultant

Epergne Solutions • Abu Dhabi

On-site
Senior/ Lead Penetration Test Engineer
Senior/ Lead Penetration Test Engineer

Epergne Solutions • Ras Al Khaimah

On-site
AED 250,000 - 400,000
Specialist - Offensive Security
Specialist - Offensive Security

PureCS • Dubai

On-site
AED 180,000 - 300,000
Senior/ Lead Penetration Test Engineer
Senior/ Lead Penetration Test Engineer

Epergne Solutions • Al Ain

On-site
AED 280,000 - 520,000
CRTP
OSTP
OSWE
+2
Senior Security Engineer
Senior Security Engineer

Confidential • Sharjah

On-site
AED 350,000 - 550,000
Principal / Senior Red Team Services Consultant (Remote, UAE/KSA)
Principal / Senior Red Team Services Consultant (Remote, UAE/KSA)

CrowdStrike • Khor Fakkan

On-site
AED 300,000 - 600,000
Equity incentives
Wellness programs
Paid leaves
+1
Senior Penetration Tester
Senior Penetration Tester

Equinox Technologies • United Arab Emirates

On-site
AED 70,000 - 110,000