Penetration Tester
Posted Jul 28, 2026 · Apply before Aug 16, 2026
About the Role
We're looking for a Senior Penetration Tester to join our security testing practice. You'll deliver manual-first penetration testing engagements on web, mobile, infrastructure, cloud, VoIP, and Wi-Fi both internally and for clients across the UAE working within formal testing governance and producing high-quality, client-ready reporting.
Responsibilities
- Run manual and tool-assisted penetration tests across web applications, web services, mobile apps (iOS/Android), infrastructure, cloud, VoIP, and Wi-Fi — both external and internal exposure
- Test to Greybox/Whitebox and Blackbox
- Operate within approved rules-of-engagement / exploit-authorisation processes before any exploitation activity
- Escalate critical findings (RCE, SQLi, and similar) immediately, outside the standard reporting cycle
- Produce detailed, client-ready reports: executive summary, business-level conclusions, and per-finding detail (ID, severity, affected assets, root cause, evidence, business impact, recommendations, mitigations)
- Maintain vulnerability registers and log findings into vulnerability management platforms where integrations exist
- Retest remediated vulnerabilities and issue closure/certification reports
- Contribute to monthly status reporting and testing dashboards across active engagements
- Lead findings walkthroughs and planning calls with client stakeholders, in English
- Explain and reproduce reported vulnerabilities on request
- QA your own and peers' work to eliminate false positives/negatives before delivery
Requirements
- 4+ years of hands-on, proven penetration testing experience
- Strong practical skills across at least two of: web/API testing, mobile (iOS/Android), network/infrastructure, cloud (AWS/Azure)
- Comfortable with manual testing plus tooling such as Burp Suite, Acunetix, Nmap, and similar
- Excellent spoken and written English; confident presenting findings to technical and executive audiences alike
- Comfortable operating under formal engagement governance signed-off scopes, exploit authorisation, escalation protocols
- Based in or willing to relocate to Dubai; able to travel to client sites as required
Qualifications
- OSCP, OSCE, OSWE, GPEN, or an equivalent recognised offensive security certification are strongly preferred
- Cloud or network certifications (AWS, Azure, or similar) a plus
- Bachelor's degree in Computer Science, Information Security, or a related field or equivalent practical experience
- Clean background suitable for formal verification (identity, right to work, education, employment history)