FK

Senior Security Testing Specialist

Hiring from
United Arab Emirates
Work type
Remote
Posted
Is this job info correct?

507,475 remote jobs, straight from company career pages

100% free ยท New jobs every hour

Show job description
๐Ÿ— We're Hiring: Senior Security Testing Specialist

๐Ÿ“ Location: United Arab Emirates (Remote)

๐Ÿ’ผ Employment Type: Full-Time

๐ŸŽฏ Experience Level: Mid-Level to Senior

๐ŸŒ Work Arrangement: Fully Remote

About Us

We are a construction-focused organization committed to delivering complex projects through disciplined contract management, commercial excellence, risk control, and collaborative project delivery. Our distributed teams collaborate across Project Management, Construction, Engineering, Procurement, Commercial, Legal, Finance, Human Resources, Design, Quality, HSE, Consultants, Contractors, Suppliers, Logistics, Administration, Information Technology, and Executive Leadership to maintain secure, resilient, compliant, and reliable business operations across the organization.

The Role

We are seeking an experienced Senior Security Testing Specialist to lead and support security testing activities across the organization's applications, infrastructure, networks, cloud platforms, and technology services. The ideal candidate will provide strong technical expertise throughout the security testing lifecycle, from test planning and requirements analysis through test execution, vulnerability validation, defect management, remediation verification, and continuous improvement. This role will work closely with Cybersecurity, Software Development, Quality Assurance, Network, Infrastructure, Cloud, IT Support, Project Management, vendors, consultants, and business stakeholders to identify security weaknesses, validate protective controls, and ensure that systems meet established security requirements before and after deployment.

Key Responsibilities
  • Lead and coordinate security testing activities across enterprise applications, infrastructure, networks, cloud environments, and digital services.
  • Develop and maintain security testing strategies, methodologies, procedures, standards, and assessment frameworks.
  • Define security testing scope, objectives, acceptance criteria, test scenarios, schedules, and required resources.
  • Review functional requirements, technical specifications, system architecture, and design documentation to identify security testing needs.
  • Translate security requirements into test cases, test scripts, validation procedures, and measurable acceptance criteria.
  • Conduct security testing throughout the software development lifecycle, including development, integration, staging, pre-production, and production-readiness phases.
  • Perform application security testing to identify weaknesses in authentication, authorization, session management, input validation, data handling, and business logic.
  • Assess web applications, APIs, mobile applications, enterprise platforms, and other software components where applicable.
  • Conduct infrastructure security testing across servers, endpoints, databases, network devices, operating systems, and supporting services.
  • Evaluate network security controls, segmentation, remote access, firewall configurations, and exposure of critical services.
  • Support cloud security testing across approved cloud platforms, virtual infrastructure, storage, identity services, and cloud-native applications.
  • Assess identity and access management controls, including user provisioning, authentication, authorization, role assignments, and privileged access.
  • Validate the effectiveness of multi-factor authentication, single sign-on, session controls, and other identity security mechanisms.
  • Conduct security configuration testing against approved baselines and recognized industry benchmarks.
  • Identify insecure configurations, outdated components, unnecessary services, weak protocols, and deviations from security standards.
  • Execute manual and automated security tests using appropriate tools, frameworks, and testing techniques.
  • Configure and maintain security testing tools, scanners, test environments, and supporting utilities.
  • Evaluate automated test results and manually validate findings to determine their accuracy, severity, and practical impact.
  • Identify and document security defects, vulnerabilities, control gaps, and deviations from established requirements.
  • Assess security weaknesses based on exploitability, business impact, asset criticality, exposure, and potential consequences.
  • Prioritize security findings and recommend appropriate remediation timelines according to organizational risk criteria.
  • Develop detailed security test reports containing findings, technical evidence, affected components, risk ratings, and remediation recommendations.
  • Maintain traceability between security requirements, test cases, execution results, defects, and final acceptance decisions.
  • Record and manage security defects within approved issue tracking and defect management systems.
  • Coordinate with developers, infrastructure engineers, system administrators, and security teams to investigate reported issues.
  • Provide clear technical guidance to support root cause analysis and effective resolution of security defects.
  • Perform regression security testing following application changes, patches, configuration updates, and remediation activities.
  • Retest resolved findings to confirm that corrective actions adequately address the identified weaknesses.
  • Verify that security fixes do not introduce new vulnerabilities, functionality issues, or unintended access paths.
  • Support security sign-off and release readiness assessments for new systems, applications, and major technology changes.
  • Establish security testing entry and exit criteria for projects and system releases.
  • Review release candidates for unresolved critical findings, security exceptions, and outstanding remediation requirements.
  • Participate in secure design reviews and architecture assessments to identify security risks before implementation.
  • Collaborate with development teams to incorporate security testing into CI/CD pipelines and automated build processes.
  • Support DevSecOps practices by integrating appropriate static, dynamic, dependency, and configuration security testing into delivery workflows.
  • Conduct static application security testing and review source-code findings where appropriate to the role and available tooling.
  • Conduct dynamic application security testing against authorized test environments and approved application endpoints.
  • Evaluate third-party libraries, software dependencies, container images, and software components for known vulnerabilities.
  • Support software composition analysis and open-source dependency security reviews.
  • Assess API security, including access control, input validation, rate limiting, data exposure, and authentication mechanisms.
  • Validate data protection controls, including encryption in transit, secure storage, sensitive data handling, and appropriate access restrictions.
  • Test logging, monitoring, alerting, and audit-trail capabilities to ensure security-relevant activities are captured appropriately.
  • Validate security controls designed to prevent unauthorized access, privilege escalation, data leakage, and service disruption.
  • Conduct controlled security validation exercises to assess defensive technologies and incident detection capabilities where authorized.
  • Coordinate with penetration testing teams and vulnerability management specialists to incorporate assessment findings into testing plans.
  • Support threat modeling activities by translating identified threats and attack scenarios into practical security test cases.
  • Review vulnerability assessment results and determine which findings require additional manual testing or contextual validation.
  • Evaluate security controls for remote access, distributed work environments, project management systems, and third-party integrations.
  • Ensure security testing activities follow approved rules of engagement, test boundaries, change controls, and operational constraints.
  • Minimize disruption to business-critical services by coordinating test schedules and obtaining required approvals before execution.
  • Maintain confidentiality and protect sensitive test data, credentials, application information, technical evidence, and discovered vulnerabilities.
  • Ensure test data is appropriately managed, masked, stored, and disposed of in accordance with organizational requirements.
  • Support security audits, compliance assessments, internal control reviews, and technical assurance activities.
  • Ensure security testing practices align with applicable United Arab Emirates cybersecurity, privacy, regulatory, contractual, and organizational requirements.
  • Maintain accurate documentation of testing procedures, results, evidence, approvals, exceptions, and remediation outcomes.
  • Develop dashboards and metrics to monitor test coverage, defect severity, remediation performance, recurring weaknesses, and security quality trends.
  • Analyze test results to identify common vulnerability patterns and recommend improvements to development practices and security controls.
  • Establish and monitor key performance indicators for security testing effectiveness, coverage, quality, and delivery efficiency.
  • Identify opportunities to automate test execution, evidence collection, reporting, defect tracking, and regression validation.
  • Evaluate emerging security testing tools, methodologies, and technologies to improve assessment effectiveness.
  • Provide technical guidance and mentoring to junior security testers, quality assurance engineers, developers, and cybersecurity personnel.
  • Collaborate with cross-functional teams to strengthen secure development practices and improve security awareness.
  • Recommend improvements to security testing coverage, tooling, workflows, acceptance criteria, and overall security assurance processes.
  • Promote a proactive security culture focused on early defect identification, measurable risk reduction, reliable validation, and continuous improvement.
  • Perform additional security testing, technical assessment, quality assurance, compliance, and cybersecurity support responsibilities as required by management.

Similar jobs

Apply on LinkedIn