Specialist - Offensive Security
Dubai, United Arab Emirates · Full Time
Be the first to apply
- Experience
- 3+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
PureCS is looking for a seasoned Offensive Security Specialist to enhance and safeguard our cybersecurity defenses within national digital health platforms. The role will encompass penetration testing, adversarial simulations, vulnerability exploitation, and deep security evaluations across PureCS and PureNet environments. Close collaboration with DevSecOps, Cloud, Architecture, and Product teams is essential to uncover vulnerabilities, verify security controls, and uphold the highest security benchmarks.
Key Responsibilities
- Conduct regular penetration assessments on network, infrastructure, cloud, and application layers, including blackbox, greybox, and whitebox testing.
- Perform internal and external network penetration testing covering perimeter defenses, internal network segments, AD/EntraID environments, servers, endpoints, and cloud hyperscalers.
- Test security of web applications, mobile apps, thick-client software, and APIs, followed by timely remediation evaluation.
- Execute controlled post-exploitation activities such as privilege escalation and lateral movement to illustrate real-world business impact.
- Partner with development teams during sprints to test incremental security changes.
- Analyze static and dynamic application security testing (SAST/DAST) and software composition analysis (SCA) outputs to prioritize critical vulnerabilities and coordinate corrective actions.
- Drive integration and automation of SAST/SCA tools within DevOps pipelines and develop secure coding guidance aligned with organizational security frameworks.
- Align penetration testing efforts with OWASP Top 10, MITRE ATT&CK framework, and CVSS scoring methodologies.
- Review and validate automation-generated findings by reducing false positives and confirming exploitability; retest and track remediation status for vulnerabilities.
- Support and contribute to red and purple team efforts in validating detection and response capabilities alongside blue teams.
- Enhance offensive security tooling, automations, and internal processes.
- Develop custom scripts and tools to automate standard testing procedures and improve overall program agility.
Qualifications and Experience
- At least 3 years' practical experience in offensive security and penetration testing across network and application domains.
- A minimum of 6 years total IT industry experience.
- Profound expertise in Active Directory attack vectors, privilege escalation, lateral movement, and exploitation techniques.
- Competency in manual testing of web, mobile (iOS/Android), API, and thick-client applications.
- Strong foundational knowledge of operating system internals (Windows/Linux), networking protocols, services, and common misconfigurations.
- Deep understanding of authentication and authorization methods, plus common security weaknesses across networks, web, mobile, and API layers.
- Experienced user of offensive security tools like Burp Suite, Nmap, Metasploit, BloodHound, Impacket, and Command & Control (C2) frameworks.
- Proficiency scripting with Python, PowerShell, Bash, and capability to adapt public exploit codes.
- Knowledgeable about cloud-native architectures and cloud infrastructure security practices.
- Ability to convey complex technical security findings and business risks effectively to both technical and non-technical audiences.
- Excellent documentation and communication capabilities.
Certifications
- Mandatory or in progress: OSCP (Offensive Security Certified Professional) or PNPT (Practical Network Penetration Tester).
- Desirable: OSWE, OSWA, eWPTX, GWAPT certifications.
- Additional preferred qualifications: CRTP, CRTO (Active Directory and Red Team focused certifications).
Equal Employment Opportunity
PureCS embraces diversity and inclusivity, ensuring fair consideration to all qualified applicants regardless of race, color, religion, gender, nationality, disability, or other protected statuses.
Why Join PureCS
- Contribute to the UAE’s groundbreaking digital health transformation project.
- Engage with national-scale platforms impacting patient safety and data privacy.
- Collaborate with leading experts in cybersecurity, cloud, engineering, and health systems.
- Benefit from a performance-oriented and innovation-driven workplace culture.
- Enjoy competitive pay, career growth opportunities, and involvement in cutting-edge security initiatives.
Industry
Hospitals & Health Care