Senior Penetration Testing Specialist
Dubai, UAE (Onsite) | 1-Year Contract (Renewable)
Are you a hands-on pentester who enjoys finding real attack paths, not just running scanners?
We're looking for a Senior Penetration Testing Specialist to join a high-impact security team in a government-regulated environment.
- Plan and run end-to-end assessments across infrastructure, Active Directory, cloud (Azure/AWS/M365), web, APIs and mobile (iOS/Android)
- Demonstrate realistic attack paths covering privilege escalation, lateral movement and segmentation bypass
- Validate findings manually and eliminate false positives
- Deliver clear executive and technical reports with practical remediation guidance
- Retest fixes and support knowledge-transfer sessions
What you'll bring
- 5+ years in security assessment, including 3+ years in infrastructure and web app pentesting
- At least one of OSCP, CREST CRT/CCT, GPEN or equivalent
- Hands-on with Burp Suite Pro, Nmap, Metasploit, BloodHound, Impacket and MobSF
- Strong knowledge of AD/Entra ID, APIs, and CVSS, OWASP and ISO 27001
- DESC Cyber Force member or eligible (mandatory)
- Experience in government or regulated environments
- Strong English reporting skills (Arabic is a plus)
Nice to have
OSEP, CRTP/CRTE, CREST CCT INF, GCPN, eMAPT/GMOB, cloud security certifications