We are seeking a highly skilled and motivated Penetration Tester to join our dynamic team in Abu Dhabi. As a Penetration Tester, you will be responsible for assessing the security posture of infrastructure, applications, and cloud environments. Your goal will be to identify vulnerabilities and provide actionable insights to enhance security defenses.
Key Responsibilities:
Conduct comprehensive vulnerability assessments and penetration tests across infrastructure, network, web, and mobile applications.
Simulate real-world adversary attacks through Red Teaming exercises.
Develop and document test cases, exploits, and testing methodologies for internal use and future penetration testing scenarios.
Perform post-remediation verification testing to ensure vulnerabilities are resolved and that no new issues have been introduced.
Prepare detailed, clear, and actionable reports outlining vulnerabilities, associated risks, and recommended remediation actions.
Effectively communicate findings to both technical and non-technical stakeholders, ensuring all parties understand the implications and risks.
Provide technical mentorship and training to junior team members on penetration testing techniques, tools, and best practices.
Continuously research and stay up-to-date with the latest trends in cybersecurity, emerging vulnerabilities, and evolving attack tactics.
Assist clients with threat modeling to proactively identify and mitigate potential attack vectors.
Analyze and review code for security vulnerabilities to ensure applications are secure by design.
Required Qualifications:
2-3 years of hands-on experience in penetration testing or security assessments.
Proven expertise in conducting penetration tests across multiple domains (infrastructure, network, applications).
Strong understanding of cybersecurity frameworks such as MITRE ATT&CK, OWASP, and NIST.
Bachelor's degree in a relevant field with certifications such as OSCP, CRTP, eCPPT, CREST, or SANS/GIAC.
Proficiency with penetration testing tools like Burp Suite, Metasploit, Nessus, Nmap, Command & Control, etc.
Solid experience with scripting languages (Python, PowerShell, Bash) for automation and vulnerability analysis.
Strong programming or scripting skills for analyzing and exploiting vulnerabilities.
Excellent written and verbal communication skills with the ability to convey complex technical information to a wide audience.
A collaborative, team-oriented mindset and a passion for improving security practices.