Back to search
Moro Hub Linkedin · Posted 3d ago

Sr. Penetration Tester

United Arab Emirates

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

We are seeking a highly skilled Penetration Testing Engineer to join our cybersecurity team. The ideal candidate will perform complex security assessments, across infrastructure, applications, and cloud environments for internal as well as external clients. The ideal candidate will simulate real-world cyber-attacks to identify exploits/vulnerabilities and generate a report with those findings to share with internal team as well external clients. This role requires deep technical expertise, strong communication skills, and the ability to mentor junior team members.


Responsibilities:

  • Support the organization’s cybersecurity strategy by identifying emerging threats, attack trends, and vulnerabilities across web, mobile, network, and cloud environments.
  • Contribute to the development and enhancement of penetration testing methodologies, frameworks, and security standards.
  • Provide strategic insights to leadership on improving the organization’s overall security posture.
  • Align penetration testing activities with risk-management priorities and business objectives.
  • Participate in security architecture discussions to ensure new systems and applications are designed securely.
  • Establish testing standards, methodologies, and quality frameworks mapped to NIST, OWASP, PTES, and ISO 27001.
  • Build and mature red teaming, adversary simulation, and purple teaming program..
  • Lead adoption of continuous and autonomous penetration testing capabilities to improve coverage and efficiency.
  • Define KPIs, SLAs, and ROI metrics for penetration testing within managed security services.
  • Contribute to SOC detection engineering improvement by validating controls through offensive simulations.
  • Perform penetration testing across multiple domains: Web applications, Mobile applications (Android/iOS), Internal and external networks, Wireless networks, APIs and cloud services, Source Code Review, Red Teaming / Purple Teaming, Table Top exercise, Conduct vulnerability assessments and exploit validation using industry-standard tools and manual techniques.
  • Identify security weaknesses, misconfigurations, insecure coding practices, and potential attack paths.
  • Prepare detailed technical reports with findings, risk ratings, and actionable remediation recommendations.
  • Validate fixes and perform re-testing to ensure vulnerabilities are properly addressed.
  • Support incident response teams with exploitation insights and threat-actor simulation knowledge.
  • Plan, execute, and document penetration testing engagements in accordance with approved scopes and timelines.
  • Ensure all testing activities follow internal policies, legal guidelines, and ethical standards.
  • Coordinate with application owners, infrastructure teams, and project managers to schedule testing windows.
  • Maintain accurate logs, evidence, and documentation for audit and compliance purposes.
  • Assist in continuous improvement of security tools, processes, and automation for testing workflows.
  • Track remediation progress and collaborate with stakeholders to ensure timely closure of vulnerabilities.


Qualification, Experience and Job-Specific Skills:

  • Bachelor’s degree in computer science, Cybersecurity, Information Security, or a related field.
  • Should have 8 -10 years of hands-on penetration testing experience in enterprise environments.
  • Strong expertise in web, mobile, network, API, and cloud penetration testing
  • Advanced manual exploitation skills beyond automated tools
  • Deep understanding of OWASP, PTES, MITRE ATT&CK, and secure coding principles
  • Proficiency with tools such as Burp Suite, Metasploit, Nmap, Wireshark, Nessus, MobSF
  • Ability to write custom scripts (Python, Bash, PowerShell) for automation and exploitation
  • Strong vulnerability assessment, exploitation, and reporting capabilities
  • Experience conducting red team or adversary simulation exercises
  • Ability to review and assess security architecture and identify attack paths
  • Fluent in English (spoken and written) — essential for client communication and reporting.
  • Ability to lead engagements and mentor junior testers


Advanced certifications preferred:

  • OffSec - OSEP (Experienced Penetration tester)
  • OffSec - OSWE (Web Expert)
  • OffSec - OSCP (Offensive Security Certified Professional)
  • CREST- CCT INF (Infrastructure)
  • CREST- CCT APP (Applications)
  • CRT (CREST Registered Tester).
  • CEH (Practical) – Certified Ethical Hacker
  • EC-Council: LPT (Master) or
  • EC-Council: ECSA (Certified Security Analyst)
  • Additional cloud or security certifications are a plus (e.g., AWS Security, Azure Security, CISSP).
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search