Cybersecurity Offensive Security Specialist

International Turnkey Systems - ITS

Kuwait City

On-site

KWD 28,000 - 45,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

International Turnkey Systems (ITS) is seeking a Cybersecurity Offensive Security Specialist to conduct advanced security assessments across web apps, APIs, mobile apps, networks, cloud, IoT and OT. You will simulate real-world cyberattacks and provide actionable remediation to improve our security posture.

You will lead red team exercises, perform external/internal penetration testing, and deliver high-quality reports to technical and business stakeholders, guiding remediation and validation

Qualifications

  • 4+ years of hands-on penetration testing experience.
  • Experience in Red Teaming, Web Application Security, API Security Testing, Mobile Security Assessments, IoT/OT Security Assessments.
  • Bachelor's degree in a cybersecurity-related field.

Responsibilities

  • Conduct advanced red team exercises simulating real-world threat actors.
  • Perform external and internal penetration testing across networks and systems.
  • Assess web applications and APIs for OWASP/secure coding weaknesses.
  • Evaluate mobile app security (Android/iOS) and IoT/OT device security.
  • Produce high-quality security assessment reports and present findings to stakeholders.

Skills

Red Teaming
Threat Emulation
Penetration Testing Methodologies
MITRE ATT&CK
Cyber Kill Chain
Scripting & Automation

Education

Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering, or related field

Tools

Burp Suite Professional
Postman
JWT, OAuth2, OpenID Connect
MobSF
Frida
Objection
APKTool
JADX
Burp Suite Mobile Testing

Job description

The Cybersecurity Offensive Security Specialist is responsible for conducting advanced security assessments, penetration testing, red team operations, and security reviews across web applications, APIs, mobile applications, networks, cloud environments, IoT devices, and Operational Technology (OT) systems. The role focuses on identifying vulnerabilities, validating security controls, simulating real-world cyberattacks, and providing actionable remediation recommendations to improve the organization’s security posture.

Key Responsibilities
Red Teaming & Adversary Emulation
  • Conduct advanced red team exercises simulating real-world threat actors.
  • Execute attack scenarios aligned with MITRE ATT&CK framework.
  • Perform phishing campaigns, credential attacks, social engineering simulations, and lateral movement exercises.
  • Assess cyber defense effectiveness including SOC, SIEM, EDR
  • Develop custom attack techniques and proof-of-concept exploits.
  • Conduct Purple Team exercises with security monitoring teams.
Penetration Testing
External & Internal Infrastructure
  • Perform black-box, gray-box, and white-box penetration testing.
  • Assess internal and external network environments.
  • Identify vulnerabilities in:
  • Active Directory
  • Windows and Linux systems
  • Databases
  • Virtualization environments
  • Cloud platforms
  • Validate remediation effectiveness through re-testing activities.
Web Application Security Assessments
  • Conduct security assessments against web applications using OWASP Testing Methodology.
  • Identify vulnerabilities including:
  • SQL Injection
  • Cross-Site Scripting (XSS)
  • Authentication flaws
  • Session management weaknesses
  • CSRF
  • Access control issues
  • File upload vulnerabilities
  • Business logic flaws
  • Perform manual exploitation and validation of findings.
  • Review security architecture and secure coding controls.
API Security Assessments
  • Conduct security testing of REST, SOAP, GraphQL, and Microservices APIs.
  • Identify:
  • Broken Object Level Authorization (BOLA)
  • Broken Authentication
  • Excessive Data Exposure
  • SSRF Vulnerabilities
  • Insecure Direct Object References
  • JWT Security Weaknesses
  • API Abuse Scenarios
  • Assess API Gateway implementations and security controls.
  • Review API documentation and specifications.
Mobile Application Security Assessments
Android
  • Perform static and dynamic security assessments.
  • Analyze APK packages and mobile application architecture.
  • Evaluate local storage security, cryptography implementation, and backend integrations.
iOS
  • Assess iOS application security controls.
  • Perform runtime security analysis.
  • Test jailbreak protections and application hardening mechanisms.
Mobile Security Areas
  • Reverse engineering
  • SSL Pinning bypass testing
  • Data leakage assessments
  • Secure storage validation
  • Root/Jailbreak detection testing
  • Mobile API security testing
IoT Security Assessments
  • Conduct security assessments of Internet of Things (IoT) devices.
  • Evaluate:
  • Device firmware security
  • Wireless communication protocols
  • Authentication mechanisms
  • Device hardening controls
  • Embedded operating systems
  • Perform firmware extraction and analysis.
  • Identify insecure configurations and exposed services.
Security Reporting & Stakeholder Engagement
  • Produce high-quality technical and executive security assessment reports.
  • Present findings to technical and business stakeholders.
  • Provide practical remediation recommendations.
  • Assist asset owners with vulnerability remediation planning.
  • Track remediation progress and perform validation testing.
Required Technical Skills
Offensive Security
  • Red Team Operations
  • Threat Emulation
  • Penetration Testing Methodologies
  • MITRE ATT&CK
  • Cyber Kill Chain
Web & API Security
  • OWASP Top 10
  • OWASP API Security Top 10
  • Burp Suite Professional
  • Postman
  • JWT, OAuth2, OpenID Connect
Mobile Security
  • MobSF
  • Frida
  • Objection
  • APKTool
  • JADX
  • Burp Suite Mobile Testing
Infrastructure Security
  • Active Directory Security
  • Windows Security
  • Linux Security
  • Network Security
  • Wireless Security
IoT & OT Security
  • Embedded Device Security
  • Firmware Analysis
Scripting & Automation
  • Python
  • PowerShell
  • Bash
  • API Automation
Education
  • Bachelor\'s Degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering, or related field.
Experience
  • 4+ years of hands‑on penetration testing experience.
  • Proven experience in:
  • Red Teaming
  • Web Application Security
  • API Security Testing
  • Mobile Security Assessments
  • IoT/OT Security Assessments
Preferred Certifications
Essential (One or More)
  • OSCP
  • PNPT
  • CRTO
  • OSEP
  • OSWE
  • eWPTX
  • eMAPT
  • GMOB
  • GICSP
  • GRID
  • GPEN
  • GWAPT
  • CARTP
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Threat Analyst
Cyber Threat Analyst

V2X • Kuwait City

On-site
KWD 8,000 - 16,000
Company-paid housing
Transportation provided
Completion bonus and tuition reimburse
Cyber Security Engineer / Cyber Security Specialist
Cyber Security Engineer / Cyber Security Specialist

Explore more jobs • Ahmadi

On-site
KWD 13,000 - 27,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Epergne Solutions • Kuwait

On-site
KWD 21,000 - 31,000
Cyber Threat Analyst - TS/SCI Clearance
Cyber Threat Analyst - TS/SCI Clearance

Vectrus, Inc • Kuwait City

On-site
KWD 28,000 - 40,000
Company-paid housing
Transportation
Completion bonus
+1
Service Desk Admin I (NOSC)
Service Desk Admin I (NOSC)

V2X • Kuwait

On-site
KWD 7,000 - 13,000
company-paid housing and transport
a completion bonus
tuition reimbursement program
+1
ARC Sight Management Analyst
ARC Sight Management Analyst

V2X • Kuwait

On-site
KWD 9,000 - 15,000
Company-paid housing
Transportation
Completion bonus
+1
Cyber Threat Analyst-Top Secret/SCI Clearance
Cyber Threat Analyst-Top Secret/SCI Clearance

V2X Inc • Kuwait City

On-site
KWD 26,000 - 38,000
Housing provided
Transportation provided
Completion bonus
+1
Cyber Threat Analyst-Top Secret/SCI Clearance
Cyber Threat Analyst-Top Secret/SCI Clearance

Vectrus, Inc • Kuwait City

On-site
KWD 29,000 - 40,000
Housing provided
Transportation provided
Completion bonus
+1
Senior Presales Cybersecurity Solutions Consultant
Senior Presales Cybersecurity Solutions Consultant

stc Kuwait • Kuwait

On-site
KWD 40,000 - 60,000
Senior Presales Cybersecurity Solutions Consultant
Senior Presales Cybersecurity Solutions Consultant

stc Group • Kuwait

On-site
KWD 24,000 - 37,000