Offensive Security Engineer

noon

Gurugram District

On-site

INR 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

noon is seeking a highly-motivated security professional to join the Red Team and support offensive security operations, including penetration testing and adversary emulation. You will assess web services and APIs, validate findings, and help improve Noon’s cybersecurity resilience.

You’ll coordinate with the infosec and development teams to plan and execute assessments, tune scanners, and ensure timely remediation.

Qualifications

  • Experienced in red team operations and offensive security assessments.
  • Strong hands-on web and API penetration testing.
  • Deep understanding of advanced vulnerabilities (SSRF, injections, auth flaws, business-logic abuse).

Responsibilities

  • Conduct penetration testing for web services and APIs.
  • Perform security reviews on services and features.
  • Validate and prioritize findings from SAST/DAST and bug bounty programs.
  • Enhance pipeline detection by tuning scanners.
  • Collaborate with development teams to remediate vulnerabilities.
  • Verify issues are resolved and SLAs tracked.

Skills

Web & API pentesting
Offensive security
Attacker mindset
Vulnerability chaining
Dev collaboration

Tools

SAST/DAST tools
Penetration testing frameworks

Job description

noon, the region's leading consumer commerce platform. On December 12th, 2017, noon launched its consumer platform in Saudi Arabia and the UAE, expanding to Egypt in February 2019. The noon ecosystem of services now includes marketplaces for food delivery, quick-commerce, fintech, and fashion. noon is a work in progress; we’re six years in, but only 5% done. Noon’s mission: every door, every day.

What you'll do:

We are looking for a highly-motivated and dynamic candidate to join our Red Team and who will support our red teaming security program and offensive security operations. The candidate is expected to participate in Red Team/Purple team operations/penetration testing and adversary emulation assessments. Additionally, the candidate will assist Noon’s company in enhancing their cybersecurity resilience by providing an "attacker's approach" and identifying high-impact attack vectors that threat actors could use.

An ideal candidate should have a passion for red teaming, must demonstrate technically sound offensive security skills, and have an attacker mindset. The candidate is also expected to coordinate across the infosec department to plan and oversee the execution of assessments, as well as assist in helping improve Noon security defense.

  • Conduct thorough penetration testing for web services and APIs.
  • Perform comprehensive security reviews on services and features.
  • Validate and prioritize findings from various security pipelines, including but not limited to SAST and DAST integrations, and the bug bounty program, effectively distinguishing genuine issues from false positives.
  • Enhance our pipeline's detection capabilities working on tuning scanners and identifying systemic gaps.
  • Collaborate directly with development teams to ensure timely and effective remediation of vulnerabilities.
  • Verify all reported security issues are fully resolved and not merely marked as closed, tracking SLAs etc.

What you'll need

  • We are hiring for Med/Senior levels
  • Strong hands-on web & API pentesting with ability to move beyond common vuln classes into real attack paths
  • Deep understanding of advanced vulnerabilities (SSRF with pivoting, injections, auth flaws, business-logic abuse)
  • Ability to analyze systems across layers: code (backend logic), HTTP/protocol (request smuggling, caching issues), and architecture (trust boundaries, service interactions)
  • Solid understanding of HTTP internals (parsing inconsistencies, proxy/CDN behavior, header manipulation)
  • Capable of validating scanner findings, eliminating noise, and identifying detection gaps to improve coverage
  • Able to chain multiple weaknesses into realistic exploitation scenarios with clear impact

Who will excel?

‘noon isn’t for everyone. And that’s okay.’ This is one of our core operating principles.

We're looking for resourceful doers. Thinkers who are both creative and analytical. Problem solvers who are enthusiastic about delivering results. Our ideal candidate will be comfortable in a fast-paced, multi-tasked, high-energy and often ambiguous environment.

If the above values resonate with you, then noon might be the place for you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Red Team / Offensive Security Engineer (Hiring for all levels)
Red Team / Offensive Security Engineer (Hiring for all levels)

noon • Delhi

On-site
INR 1,000,000 - 1,500,000
Senior Manager - Security Operations (Detection and Response)
Senior Manager - Security Operations (Detection and Response)

noon • Gurugram District

On-site
INR 4,000,000 - 7,000,000
Backend Engineer
Backend Engineer

noon • Gurugram District

On-site
INR 2,500,000 - 4,000,000
Legal / Senior Legal Counsel
Legal / Senior Legal Counsel

noon • Gurugram District

On-site
INR 2,400,000 - 4,200,000
Business Analyst
Business Analyst

noon • Gurugram District

On-site
INR 900,000 - 1,300,000
Data Scientist
Data Scientist

noon • Gurugram District

On-site
INR 900,000 - 1,700,000
Senior Manager – Customer Service Analytics & Product Strategy
Senior Manager – Customer Service Analytics & Product Strategy

noon • Gurugram District

On-site
INR 1,500,000 - 2,500,000
Supply Planner
Supply Planner

noon • Delhi

On-site
INR 600,000 - 1,000,000
Brand Visual Designer - Noon Food - Send
Brand Visual Designer - Noon Food - Send

noon • Gurugram District

On-site
INR 600,000 - 900,000
Product Manager
Product Manager

noon • Gurugram District

On-site
INR 1,200,000 - 1,800,000