Penetration Tester

Cyber Security 📍 Dubai Full-time Senior

Posted Jul 28, 2026 · Apply before Aug 16, 2026

Apply Now

About the Role

We're looking for a Senior Penetration Tester to join our security testing practice. You'll deliver manual-first penetration testing engagements on web, mobile, infrastructure, cloud, VoIP, and Wi-Fi  both internally and for clients across the UAE working within formal testing governance and producing high-quality, client-ready reporting.

Responsibilities

  • Run manual and tool-assisted penetration tests across web applications, web services, mobile apps (iOS/Android), infrastructure, cloud, VoIP, and Wi-Fi — both external and internal exposure
  • Test to Greybox/Whitebox and Blackbox
  • Operate within approved rules-of-engagement / exploit-authorisation processes before any exploitation activity
  • Escalate critical findings (RCE, SQLi, and similar) immediately, outside the standard reporting cycle
  • Produce detailed, client-ready reports: executive summary, business-level conclusions, and per-finding detail (ID, severity, affected assets, root cause, evidence, business impact, recommendations, mitigations)
  • Maintain vulnerability registers and log findings into vulnerability management platforms where integrations exist
  • Retest remediated vulnerabilities and issue closure/certification reports
  • Contribute to monthly status reporting and testing dashboards across active engagements
  • Lead findings walkthroughs and planning calls with client stakeholders, in English
  • Explain and reproduce reported vulnerabilities on request
  • QA your own and peers' work to eliminate false positives/negatives before delivery

Requirements

  • 4+ years of hands-on, proven penetration testing experience
  • Strong practical skills across at least two of: web/API testing, mobile (iOS/Android), network/infrastructure, cloud (AWS/Azure)
  • Comfortable with manual testing plus tooling such as Burp Suite, Acunetix, Nmap, and similar
  • Excellent spoken and written English; confident presenting findings to technical and executive audiences alike
  • Comfortable operating under formal engagement governance signed-off scopes, exploit authorisation, escalation protocols
  • Based in or willing to relocate to Dubai; able to travel to client sites as required

Qualifications

  • OSCP, OSCE, OSWE, GPEN, or an equivalent recognised offensive security certification are strongly preferred
  • Cloud or network certifications (AWS, Azure, or similar)  a plus
  • Bachelor's degree in Computer Science, Information Security, or a related field or equivalent practical experience
  • Clean background suitable for formal verification (identity, right to work, education, employment history)

Apply for this position

PDF or DOCX, max 5MB.