Role &
Responsibilities :
- Lead and manage penetration testing engagements across web applications, mobile applications, APIs, networks, cloud environments, and enterprise infrastructure.
- Plan, scope, execute, and deliver security assessments aligned with industry standards such as OWASP, PTES, NIST, and CREST methodologies.
- Perform advanced penetration testing activities including :
- Web application security testing
- API security assessments
- Mobile application testing (Android/iOS)
- Network and infrastructure penetration testing
5.
Active
Directory security assessments
- Cloud security assessments (AWS/Azure/GCP)
- Red team and adversary simulation exercises
- Lead vulnerability discovery, exploitation, post-exploitation analysis, and risk validation activities.
- Review and improve penetration testing methodologies, tools, and processes.
- Mentor and guide penetration testers, security analysts, and junior team members.
- Assign tasks, review testing quality, and ensure delivery timelines are met.
- Stay updated on emerging threats, vulnerabilities, exploits, and offensive security techniques.
- Contribute to security automation initiatives, scripting, and penetration testing tool development.
- Ensure compliance with regulatory and industry requirements relevant to UAE organizations (such as PCI DSS, ISO 27001, NESA/ECS-related controls, and sector-specific security requirements).
Preferred Candidate Profile :
Experience :
- 6 to 12 years of hands-on experience in penetration testing, ethical hacking, vulnerability assessment, or offensive security.
- Proven experience leading penetration testing engagements and managing security testing teams.
- Experience working with enterprise customers, financial institutions, government organizations, or large-scale environments preferred.
- Strong experience in preparing executive-level and technical security reports.
Technical Skills :
- Strong expertise in :
- Web application penetration testing
- API security testing
- Network penetration testing
4.
Active
Directory exploitation
- Cloud security testing
- Vulnerability assessment and risk management
- Red team operations and threat emulation
- Proficiency with security tools such as :
1.
Burp Suite
Qualified
- Metasploit
- Nmap
- Nessus / Qualys
- BloodHound
6.
Cobalt
Strike / similar adversary simulation tools
- Wireshark
- Kali Linux toolset
- Strong scripting/programming skills in Python, Bash, PowerShell, or similar languages.
- Knowledge of vulnerability research, exploit development, and security automation is an advantage.
Education :
- Bachelors degree in Computer Science, Cybersecurity, Information Security, Engineering, or related field preferred.
- Equivalent professional experience and industry certifications may be considered.
📌 Penetration Testing Lead (India)
🏢 Good
📍 India