Specialist - Offensive Security

PureCS

Dubai

On-site

AED 180,000 - 300,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

PureCS is seeking a Specialist - Offensive Security to strengthen our cybersecurity posture across national health platforms. You will conduct penetration testing, adversarial simulations, vulnerability exploitation, and advanced security assessments across PureCS and PureNet systems.

You will collaborate with DevSecOps, Cloud, Architecture, and Product teams to identify weaknesses, validate controls, and ensure our platforms meet the highest security standards while communicating risk to

Qualifications

  • Minimum 3 years of hands‑on Offensive Security / Penetration Testing (network + application).
  • Minimum 6 years total IT experience.
  • Strong experience with AD attack paths, privilege escalation, lateral movement, and exploitation.
  • Working knowledge of manual testing for web apps, mobile apps (iOS/Android), APIs, and thick‑client apps.
  • Solid understanding of OS internals (Windows/Linux), network protocols, services, and misconfigurations.
  • Strong understanding of authentication/authorization techniques and security issues across network, web, mobile, and API layers.
  • Proficiency with offensive tooling: Burp Suite, Nmap, Metasploit, BloodHound, Impacket, C2 frameworks.
  • Comfortable with scripting (Python, PowerShell, Bash) and adapting public exploits.
  • Knowledge of cloud‑native app architecture and cloud security.

Responsibilities

  • Execute periodic penetration testing across network, infrastructure, cloud, and application layers (blackbox, greybox, whitebox).
  • Perform internal/external network penetration testing including perimeter, internal segments, AD/EntraID, servers, endpoints, and hyperscaler cloud environments.
  • Conduct web, mobile, thick‑client, and API penetration testing with timely remediation follow‑ups.
  • Carry out controlled post‑exploitation, privilege escalation, and lateral movement to demonstrate business impact.
  • Collaborate with development teams to test incremental changes during sprints.
  • Review SAST/DAST/SCA outputs, prioritize issues, and coordinate fixes.
  • Drive integration and usage of SAST/SCA tooling within DevOps pipelines.
  • Prepare secure coding practice documents tailored to organizational frameworks.
  • Map engagements to OWASP Top 10, MITRE ATT&CK, and CVSS scoring.
  • Validate automation outputs, eliminate false positives, confirm exploitability.
  • Retest remediated findings and maintain tracking of closure and coverage.
  • Support red and purple team exercises, validate detection and response capabilities with blue team.
  • Contribute to enhancements in offensive security tooling, automation, and processes.
  • Develop scripts and tooling to automate standardized testing use cases.
  • Improve program agility through tooling upgrades and process refinement.

Skills

Penetration testing
Adversarial thinking
Scripting
Communication

Tools

Burp Suite
Nmap
Metasploit
BloodHound
Impacket
C2 frameworks

Job description

Role: Offensive Security – Specialist

Location: Dubai (transitioning to Abu Dhabi)

Department: Cybersecurity

Reporting to: Head of Cybersecurity

PureCS is seeking a Specialist - Offensive Security to strengthen our cybersecurity posture across national‑scale digital health platforms. This role will conduct penetration testing, adversarial simulations, vulnerability exploitation, and advanced security assessments across PureCS and PureNet systems. You will work closely with DevSecOps, Cloud, Architecture, and Product teams to identify weaknesses, validate controls, and ensure our platforms meet the highest security standards.

Key Responsibilities:
Penetration Testing & Exploitation
  • Execute periodic penetration testing across network, infrastructure, cloud, and application layers (blackbox, greybox, whitebox).
  • Perform internal/external network penetration testing including perimeter, internal segments, AD/EntraID, servers, endpoints, and hyperscaler cloud environments.
  • Conduct web, mobile, thick‑client, and API penetration testing with timely follow‑up on remediation.
  • Carry out controlled post‑exploitation, privilege escalation, and lateral movement to demonstrate realistic business impact.
Application & DevSecOps Security
  • Collaborate with development teams to test incremental changes during sprints.
  • Review SAST/DAST/SCA outputs, prioritize critical issues, and coordinate fixes.
  • Drive integration and usage of SAST/SCA tooling within DevOps pipelines.
  • Prepare secure coding practice documents tailored to organizational frameworks.
Threat & Vulnerability Management
  • Map engagements to OWASP Top 10, MITRE ATT&CK, and CVSS scoring.
  • Validate and triage automation outputs, eliminating false positives and confirming exploitability.
  • Retest remediated findings and maintain accurate tracking of closure and coverage.
Red/Purple Team Collaboration
  • Support red and purple team exercises, validating detection and response capabilities with the blue team.
  • Contribute to enhancements in offensive security tooling, automation, and processes.
Tooling & Automation
  • Develop scripts and tooling to automate standardized testing use cases.
  • Assist in improving offensive security program agility through tooling upgrades and process refinement.
Qualifications & Experience
  • Minimum 3 years of hands‑on experience in Offensive Security / Penetration Testing (network + application).
  • Minimum 6 years total experience in IT.
  • Strong experience with AD attack paths, privilege escalation, lateral movement, and exploitation.
  • Working knowledge of manual testing for web apps, mobile apps (iOS/Android), APIs, and thick‑client applications.
  • Solid understanding of OS internals (Windows/Linux), network protocols, services, and common misconfigurations.
  • Strong understanding of authentication/authorization techniques and security issues across network, web, mobile, and API layers.
  • Proficiency with offensive tooling: Burp Suite, Nmap, Metasploit, BloodHound, Impacket, C2 frameworks.
  • Comfortable with scripting (Python, PowerShell, Bash) and adapting public exploits.
  • Knowledge of cloud‑native application architecture and cloud infrastructure security.
  • Ability to articulate technical findings as business risk to technical and non‑technical stakeholders.
  • Strong documentation and communication skills.
Certifications
  • Required / In Progress: OSCP or PNPT
  • Preferred: OSWE, OSWA, eWPTX, GWAPT
  • Plus: CRTP, CRTO (Active Directory / Red Team certifications)
Equal Employment Opportunity

PureCS is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability, or any other protected characteristic.

Why Work With Us
  • Secure the UAE’s largest and most ambitious digital health transformation.
  • Work on national‑scale platforms with real impact on patient safety and data protection.
  • Collaborate with industry‑leading experts across cybersecurity, cloud, engineering, and health systems.
  • Grow within a high‑performance, innovation‑driven environment.
  • Competitive compensation, career development pathways, and opportunities to work on cutting‑edge security initiatives.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Offensive Security Engineer: PenTesting & Red Team
Offensive Security Engineer: PenTesting & Red Team

PureCS • Dubai

On-site
AED 180,000 - 300,000
Cyber Security Specialist
Cyber Security Specialist

جامعة حمدان بن محمد الذكية • Dubai

On-site
AED 180,000 - 240,000
Senior/ Lead Penetration Test Engineer
Senior/ Lead Penetration Test Engineer

Epergne Solutions • Dubai

On-site
AED 180,000 - 250,000
Senior/ Lead Penetration Test Engineer
Senior/ Lead Penetration Test Engineer

Epergne Solutions • Abu Dhabi

On-site
AED 293,000 - 441,000
Security Engineer I UAE Based
Security Engineer I UAE Based

Pixel Chain • Dubai

On-site
AED 300,000 - 460,000
Flight ticket and full working visa
Full sponsorship and visa support
MacBook and iPhone
+3
Penetration Tester- Vulnerability Assessment & Penetration Testing
Penetration Tester- Vulnerability Assessment & Penetration Testing

TAT IT Technolgies • Dubai

On-site
AED 140,000 - 220,000
Senior Offensive Security Engineer
Senior Offensive Security Engineer

Deriv.com • Dubai

Hybrid
AED 400,000 - 720,000
Specialist - Information Security
Specialist - Information Security

Core42 • Abu Dhabi

On-site
AED 520,000 - 760,000
Competitive salary
Yearly bonus
Discount cards
Security Engineer with experience in Banking Domain
Security Engineer with experience in Banking Domain

TAT IT Technolgies • Dubai

On-site
AED 300,000 - 540,000
Security Engineer I UAE Based
Security Engineer I UAE Based

PixelChain • Dubai

On-site
AED 120,000 - 180,000
Flight ticket/visa sponsorship
Visa sponsorship for work permit
MacBook
+4