Summary
We are seeking a Pen Tester for an engagement focused on advanced penetration testing and adversarial security assessments across applications, cloud, and infrastructure. The role also includes secure solution architecture and embedding security into DevSecOps practices.
General information
This role is responsible for delivering advanced penetration testing and adversarial security assessments across application, cloud, and infrastructure environments (50%), while contributing to secure solution architecture (25%) and embedding security into DevSecOps practices (25%). The role combines hands-on offensive security expertise with secure design and automation capabilities to proactively identify and mitigate risks.
Mandate: Manage Information Security risk in-line with the Information Security Policy by providing optimal controls that enable business activities, support business continuity, and provide a balanced user experience.
It requires on-site presence in the Abu Dhabi offices.
Key skills:
- Execute advanced penetration testing across web, API, cloud, and infrastructure environments
- Perform red team and adversary simulation exercises
- Conduct threat modelling to identify attack paths and control gaps
- Design secure architectures for applications and cloud-native solutions
Implement and validate zero trust and defence-in-depth security controls
Integrate automated security testing into CI/CD pipelines (SAST, DAST, SCA, IaC scanning)
Develop security tooling, scripts, and automation for testing and detection
Mature secure SDLC practices across development teams
Identify and track security metrics (KRIs, KPIs) aligned to risk reduction
Communicate vulnerabilities, exploitability, and remediation effectively to technical and business stakeholders
Responsibilities
Penetration Testing & Offensive Security (50%)
Plan and execute penetration tests across applications, APIs, cloud platforms, and infrastructure
Conduct red teaming and adversary emulation aligned to real-world threat scenarios
Identify, exploit, and document vulnerabilities with clear risk articulation
Perform post-exploitation analysis to assess blast radius and business impact
Validate remediation effectiveness through re-testing
Continuously improve testing methodologies, tooling, and attack coverage
Security Architecture & Solution Design (25%)
Design and review secure architectures for cloud-native and on-premise solutions
Provide security input into system design, ensuring alignment with enterprise standards
Evaluate and recommend security controls and technologies
Contribute to security reference architectures and patterns
Act as SME for application and cloud security design decisions
DevSecOps & Security Engineering (25%)
Embed security controls into CI/CD pipelines (SAST, DAST, SCA, IaC scanning)
Automate security testing and control validation processes
Partner with engineering teams to integrate security into development workflows
Improve SDLC maturity to reduce vulnerabilities pre-production
Develop scripts/tools to support scalable security testing and monitoring
Required Experience
Bachelor’s Degree is required, Honours or Master’s degree is preferred
7–10 years in cybersecurity with strong hands-on penetration testing experience
Proven experience in web, API, cloud, and infrastructure penetration testing
Experience with red teaming, adversary simulation, or advanced attack techniques
Strong understanding of application security and common vulnerability classes (OWASP Top 10, etc.)
Experience designing secure cloud architectures (AWS, Azure, GCP)
Hands-on experience integrating security into DevOps/CI-CD pipelines
Scripting or development experience (Python, PowerShell, etc.)
Experience working in financial services or regulated environments preferred
Strong stakeholder communication with ability to explain technical risks in business terms
Relevant Information Security certifications, education or training:
OSCP / OSWE / CRTO (strongly preferred)
CISSP / CCSP (nice to have)
Cloud certifications (Azure / AWS)
DevSecOps-related certifications (optional but beneficial)