K
Penetration Tester | Vulnerability Analyst
Abu Dhabi Emirate, United Arab Emirates · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
We are looking for a dedicated and security-conscious Penetration Tester and Vulnerability Analyst to join our team. This mid to senior level position involves identifying, evaluating, and aiding in the mitigation of security weaknesses across applications, networks, systems, and digital infrastructure, thereby enhancing the organization's security posture.
Key Responsibilities
- Execute authorized penetration tests on web applications, APIs, networks, servers, cloud environments, and other designated systems.
- Conduct vulnerability assessments to uncover security flaws, improper configurations, outdated components, and potential exposure risks.
- Establish testing scope, goals, methodologies, engagement rules, and assessment criteria.
- Carry out reconnaissance and asset identification within authorized testing boundaries.
- Evaluate applications and infrastructure for prevalent security issues and configuration vulnerabilities.
- Utilize both manual and automated security testing approaches with standard industry tools.
- Validate detected vulnerabilities, differentiating real security threats from false alarms.
- Assess vulnerability severity factoring technical impact, exploitability, business implications, and overall risk.
- Analyze possible attack vectors and multi-weakness exploitation scenarios.
- Test critical security mechanisms including authentication, authorization, session management, input validation, and access control.
- Review APIs, web services, mobile applications, and cloud-based platforms where relevant.
- Perform network and infrastructure security evaluations across authorized internal and external environments.
- Inspect system configurations, security controls, network designs, and associated technical documentation.
- Complete vulnerability scans and prioritize results in alignment with organizational risk management protocols.
- Stay current on recently disclosed vulnerabilities, security alerts, exploits, and new attack methods.
- Monitor emerging vulnerability trends to determine organizational impact.
- Collaborate with system admins, developers, DevOps, and security engineers to analyze findings.
- Provide clear, technical remediation advice for identified issues.
- Conduct post-remediation validations to verify vulnerability resolution.
- Prepare in-depth penetration test and vulnerability assessment reports for both technical and managerial stakeholders.
- Document evidence, affected assets, security implications, risk levels, and recommended corrective actions.
- Present findings to stakeholders, translating technical risks into business-relevant language.
- Maintain detailed logs of vulnerabilities, remediation progress, and testing activities.
- Assist in maintaining and improving vulnerability management initiatives and security enhancement efforts.
- Contribute to improving security testing methodologies, procedures, automation tools, and reporting techniques.
- Ensure confidentiality and strict compliance with authorized test scopes and security protocols.
Candidate Requirements
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or related discipline.
- Experience in penetration testing, vulnerability evaluation, security assessments, or cybersecurity analysis.
- Solid knowledge of network security, operating systems, web applications, APIs, databases, and cloud environments.
- Familiarity with common web and app security risks, including OWASP principles.
- Proficiency in vulnerability scanners, penetration testing tools, network analyzers, and security frameworks.
- Experience with tools such as Burp Suite, Nmap, Nessus, OpenVAS, Wireshark, or similar platforms is beneficial.
- Understanding of TCP/IP, DNS, HTTP/HTTPS protocols, VPNs, firewalls, authentication systems, and network infrastructure.
- Comfort with both Linux and Windows security environments.
- Expertise in vulnerability management, risk evaluation, CVE/CVSS standards, and remediation workflows.
- Capability to validate vulnerabilities and conduct controlled security tests.
- Basic to advanced scripting skills in Python, PowerShell, Bash, or related languages are a plus.
- Knowledge of cloud security practices on platforms like AWS, Azure, or Google Cloud is desirable.
- Familiarity with identity and access management, endpoint security, application security, and infrastructure security concepts.
- Strong analytical reasoning and problem-solving capacity.
- Excellent skills in technical documentation and report writing.
- Effective communication skills, able to explain complex security findings to both technical and non-technical audiences.
- Meticulous attention to detail to identify subtle security vulnerabilities.
- Ability to work autonomously and collaboratively across security, development, infrastructure, and operations teams.
- High ethical standards and strict conformity to authorized testing procedures and security policies.
- Knowledge of security frameworks like NIST, ISO 27001, CIS Controls is beneficial.
- Certifications such as OSCP, CEH, GPEN, Security+, eJPT, or PNPT are advantageous.
Compensation and Benefits
- Competitive remuneration with comprehensive employee benefits.
- Engagement in diverse cybersecurity assessment and vulnerability management projects.
- Interaction with web applications, APIs, networks, cloud infrastructures, and enterprise security ecosystems.
- Access to professional training in penetration testing, vulnerability analysis, application, and cloud security.
- Utilization of up-to-date security testing platforms, assessment tools, and cybersecurity technologies.
- Collaboration opportunities with experienced security professionals, developers, infrastructure teams, and leadership.
- Support for obtaining industry-recognized cybersecurity certifications and ongoing professional growth.
- Participation in security improvement initiatives, risk management, and digital transformation efforts.
- Exposure to emerging vulnerabilities, attack strategies, defense technologies, and trending security topics.
- Recognition for high-quality evaluations, remediation guidance, and security enhancements.
- Potential career advancement towards roles such as Senior Penetration Tester, Vulnerability Management Lead, Security Consultant, Red Team Specialist, or Cybersecurity Manager.
Minimum education
Bachelor's Degree
Industry
CybersecuritySkills
How they work
Communication
Problem Solving
Attention to Detail
Independence
Integrity