Senior Penetration Testing Specialist
- Hiring from
- United Arab Emirates
- Work type
- Remote
- Posted
508,864 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
Location: United Arab Emirates (Remote)
Employment Type: Full-Time
Experience Level: Senior
Work Arrangement: Fully Remote
About UsWe are a globally focused organization committed to strengthening cybersecurity, technology resilience, and risk management across diverse digital environments. Our teams collaborate across Information Security, Technology, Engineering, Infrastructure, Cloud, Application Development, Risk, Compliance, and Operations to identify vulnerabilities and protect critical systems, applications, data, and services.
Our security teams combine offensive security expertise, advanced testing methodologies, threat intelligence, automation, and risk-based analysis to identify weaknesses before they can be exploited and to continuously improve the organization's security posture.
The RoleWe are seeking an experienced Senior Penetration Testing Specialist to lead penetration testing, vulnerability assessment, offensive security, red-team activities, security validation, and technical risk assessment across applications, infrastructure, networks, cloud environments, APIs, mobile platforms, and other technology assets.
The ideal candidate will combine strong hands-on offensive security expertise with analytical thinking, technical communication, and the ability to translate complex vulnerabilities into practical remediation priorities for engineering and security teams.
Key Responsibilities- Develop and execute risk-based penetration testing strategies, methodologies, standards, and procedures.
- Plan and lead penetration tests across applications, infrastructure, networks, APIs, cloud environments, mobile applications, and external attack surfaces.
- Conduct web application penetration testing and identify vulnerabilities across authentication, authorization, session management, input validation, business logic, and application security controls.
- Perform API security assessments covering authentication, authorization, access control, input validation, rate limiting, data exposure, and business logic.
- Conduct mobile application security testing across Android and iOS environments.
- Assess network infrastructure, servers, endpoints, firewalls, VPNs, remote-access technologies, and externally exposed services.
- Perform internal and external network penetration testing to identify exploitable security weaknesses.
- Conduct cloud security assessments across relevant infrastructure, services, identities, configurations, and exposed resources.
- Assess identity and access-management controls, privileged access, authentication mechanisms, and authorization models.
- Conduct security assessments of Active Directory and enterprise identity environments.
- Perform vulnerability validation and controlled exploitation to determine the real-world impact of identified weaknesses.
- Conduct manual security testing beyond automated vulnerability scanning.
- Develop tailored attack scenarios based on threat intelligence, business context, technology architecture, and likely adversary behavior.
- Conduct red-team and adversary-simulation activities where required.
- Assess detection and response capabilities during authorized offensive-security exercises.
- Evaluate security controls designed to prevent, detect, and respond to attack techniques.
- Identify attack paths involving combinations of vulnerabilities, misconfigurations, excessive privileges, and exposed services.
- Perform privilege-escalation testing within authorized environments.
- Assess segmentation, trust relationships, network controls, and lateral-movement risks.
- Test security controls against relevant attack techniques and industry-standard methodologies.
- Use established penetration-testing frameworks and methodologies such as OWASP, PTES, NIST, MITRE ATT&CK, and applicable industry standards.
- Develop detailed penetration-testing scopes, rules of engagement, test plans, and risk controls.
- Coordinate testing activities with system owners, application teams, infrastructure teams, and security stakeholders.
- Ensure all testing is conducted within approved authorization, scope, and rules of engagement.
- Minimize operational disruption and protect production systems during authorized security testing.
- Document technical findings with clear evidence, affected assets, attack paths, business impact, and remediation recommendations.
- Validate vulnerabilities through controlled proof-of-concept techniques where appropriate.
- Assess the exploitability and business impact of identified vulnerabilities.
- Prioritize findings according to severity, exploitability, asset criticality, business impact, and threat context.
- Produce executive-level and technical penetration-testing reports.
- Present findings and remediation recommendations to technical teams, security leadership, and senior management.
- Work with development and infrastructure teams to explain vulnerabilities and support effective remediation.
- Conduct remediation validation and follow-up testing to confirm that vulnerabilities have been adequately addressed.
- Track penetration-testing findings through remediation and closure.
- Maintain accurate testing records, evidence, reports, attack paths, and remediation status.
- Integrate penetration-testing activities with vulnerability-management and security-risk programs.
- Support security architecture reviews by identifying exploitable weaknesses in proposed or existing designs.
- Assess security controls within DevOps, CI/CD, container, and cloud-native environments.
- Evaluate application security controls throughout the software-development lifecycle.
- Support secure-development initiatives by providing developers with practical vulnerability guidance.
- Identify recurring vulnerability patterns and recommend systemic security improvements.
- Develop reusable testing methodologies, scripts, tooling, and automation to improve assessment efficiency.
- Maintain and enhance offensive-security tools, testing environments, and security research capabilities.
- Research emerging vulnerabilities, attack techniques, exploitation methods, and defensive technologies.
- Monitor threat intelligence and incorporate relevant adversary techniques into penetration-testing scenarios.
- Evaluate emerging technologies and their implications for offensive security and organizational risk.
- Support incident-response teams through controlled security validation, threat emulation, and post-incident security assessments.
- Conduct security testing following major system changes, acquisitions, migrations, and significant technology implementations.
- Support regulatory, compliance, audit, and customer security requirements related to penetration testing.
- Manage external penetration-testing providers and specialist security consultants where applicable.
- Review third-party penetration-testing reports for technical quality, completeness, evidence, and remediation recommendations.
- Establish penetration-testing standards, quality requirements, reporting templates, and assessment governance.
- Mentor junior penetration testers and security professionals.
- Conduct knowledge-sharing sessions on offensive security, vulnerability research, secure development, and emerging attack techniques.
- Maintain awareness of changes in cybersecurity standards, vulnerability disclosures, attack methodologies, and offensive-security practices.
- Provide management with regular reporting on testing coverage, critical findings, remediation progress, recurring weaknesses, and emerging security risks.
- Penetration testing plan completion
- Security assessment coverage
- Critical vulnerability identification rate
- High-risk vulnerability identification rate
- Validated vulnerability rate
- Vulnerability severity accuracy
- False-positive rate
- Penetration-testing report turnaround time
- Technical report quality
- Executive reporting quality
- Remediation recommendation effectiveness
- Remediation validation completion rate
- Critical finding remediation rate
- Repeat vulnerability rate
- Average vulnerability remediation time
- High-risk finding closure time
- Penetration-testing finding aging
- Testing scope compliance
- Rules-of-engagement compliance
- Testing-related operational incidents
- Application penetration-testing coverage
- API security testing coverage
- Mobile security testing coverage
- Network penetration-testing coverage
- Cloud security assessment coverage
- Identity and access-control testing coverage
- Red-team exercise completion
- Attack-path identification effectiveness
- Threat-scenario coverage
- Security-control validation coverage
- Automated testing efficiency
- Manual testing coverage
- Security testing automation adoption
- Vulnerability trend reduction
- Recurring weakness reduction
- Security risk reduction achieved
- Stakeholder satisfaction
- Developer remediation engagement
- Security awareness and knowledge-sharing completion
- Third-party testing quality
- Audit and compliance testing completion
- Penetration-testing budget adherence
- Testing productivity
- Security improvement initiatives completed
The successful candidate should have strong experience in penetration testing, offensive security, vulnerability assessment, application security, network security, red teaming, or cybersecurity assessment, preferably within complex enterprise, technology, financial-services, telecommunications, cloud, or digitally enabled environments.
The candidate should demonstrate:
- Strong hands-on experience conducting penetration tests across multiple technology environments.
- Advanced knowledge of web application and API security testing.
- Strong understanding of network, infrastructure, cloud, and identity security.
- Experience assessing Active Directory and enterprise authentication environments.
- Strong knowledge of common vulnerability classes and exploitation techniques.
- Experience with OWASP methodologies and application-security testing practices.