We're looking for a Senior Penetration Tester to lead advanced offensive security engagements across applications, cloud, and infrastructure — while also shaping secure architecture and embedding security into DevSecOps practices. This isn't a checklist-scanning role: you'll run red team and adversary simulation exercises, think like an attacker to map real attack paths, and then turn those findings into architecture decisions and automated controls that prevent the next one. On-site presence in Abu Dhabi is required.
What You'll Do
Penetration Testing & Offensive Security
- Plan and execute penetration tests across applications, APIs, cloud platforms, and infrastructure
- Conduct red teaming and adversary emulation aligned to real-world threat scenarios
- Identify, exploit, and document vulnerabilities with clear risk articulation
- Perform post-exploitation analysis to assess blast radius and business impact
- Validate remediation effectiveness through re-testing
- Continuously improve testing methodologies, tooling, and attack coverage
Security Architecture & Solution Design
- Design and review secure architectures for cloud-native and on-premise solutions
- Provide security input into system design, aligned with enterprise standards
- Evaluate and recommend security controls and technologies
- Act as SME for application and cloud security design decisions
DevSecOps & Security Engineering
- Embed security controls into CI/CD pipelines (SAST, DAST, SCA, IaC scanning)
- Automate security testing and control validation processes
- Partner with engineering teams to integrate security into development workflows
- Develop scripts and tools to support scalable security testing and monitoring
What You Bring
- 7–10 years in cybersecurity with strong hands‑on penetration testing experience
- Proven experience in web, API, cloud, and infrastructure penetration testing
- Experience with red teaming, adversary simulation, or advanced attack techniques
- Strong understanding of application security and common vulnerability classes (OWASP Top 10, etc.)
- Hands‑on experience integrating security into DevOps/CI-CD pipelines
- Strong stakeholder communication skills, with the ability to explain technical risk in business terms
- Bachelor's degree required; Honours or Master's degree preferred
Nice to Have
- OSCP, OSWE, or CRTO certification (strongly preferred)
- CISSP or CCSP certification
- Cloud security certifications (AWS or Azure)
- DevSecOps-related certificationsExperience working in financial services or other regulated environments