أبلاي إيدج ابدأ البحث عن عمل

Specialist - Offensive Security

PureCS · Dubai, United Arab Emirates

قدّم وتابع مع أبلاي إيدج
Role: Offensive Security – SpecialistLocation: Dubai (transitioning to Abu Dhabi)Department: CybersecurityReporting to: Head of CybersecurityPureCS is seeking a Specialist - Offensive Security to strengthen our cybersecurity posture across national‑scale digital health platforms. This role will conduct penetration testing, adversarial simulations, vulnerability exploitation, and advanced security assessments across PureCS and PureNet systems. You will work closely with DevSecOps, Cloud, Architecture, and Product teams to identify weaknesses, validate controls, and ensure our platforms meet the highest security standards.Key Responsibilities:Penetration Testing & ExploitationExecute periodic penetration testing across network, infrastructure, cloud, and application layers (blackbox, greybox, whitebox).Perform internal/external network penetration testing including perimeter, internal segments, AD/EntraID, servers, endpoints, and hyperscaler cloud environments.Conduct web, mobile, thick‑client, and API penetration testing with timely follow‑up on remediation.Carry out controlled post‑exploitation, privilege escalation, and lateral movement to demonstrate realistic business impact.Application & DevSecOps SecurityCollaborate with development teams to test incremental changes during sprints.Review SAST/DAST/SCA outputs, prioritize critical issues, and coordinate fixes.Drive integration and usage of SAST/SCA tooling within DevOps pipelines.Prepare secure coding practice documents tailored to organizational frameworks.Threat & Vulnerability ManagementMap engagements to OWASP Top 10, MITRE ATT&CK, and CVSS scoring.Validate and triage automation outputs, eliminating false positives and confirming exploitability.Retest remediated findings and maintain accurate tracking of closure and coverage.Red/Purple Team CollaborationSupport red and purple team exercises, validating detection and response capabilities with the blue team.Contribute to enhancements in offensive security tooling, automation, and processes.Tooling & AutomationDevelop scripts and tooling to automate standardized testing use cases.Assist in improving offensive security program agility through tooling upgrades and process refinement.Qualifications & ExperienceMinimum 3 years of hands‑on experience in Offensive Security / Penetration Testing (network + application).Minimum 6 years total experience in IT.Strong experience with AD attack paths, privilege escalation, lateral movement, and exploitation.Working knowledge of manual testing for web apps, mobile apps (iOS/Android), APIs, and thick‑client applications.Solid understanding of OS internals (Windows/Linux), network protocols, services, and common misconfigurations.Strong understanding of authentication/authorization techniques and security issues across network, web, mobile, and API layers.Proficiency with offensive tooling: Burp Suite, Nmap, Metasploit, BloodHound, Impacket, C2 frameworks.Comfortable with scripting (Python, PowerShell, Bash) and adapting public exploits.Knowledge of cloud‑native application architecture and cloud infrastructure security.Ability to articulate technical findings as business risk to technical and non‑technical stakeholders.Strong documentation and communication skills.CertificationsRequired / In Progress: OSCP or PNPTPreferred: OSWE, OSWA, eWPTX, GWAPTPlus: CRTP, CRTO (Active Directory / Red Team certifications)Equal Employment OpportunityPureCS is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability, or any other protected characteristic.Why Work With UsSecure the UAE’s largest and most ambitious digital health transformation.Work on national‑scale platforms with real impact on patient safety and data protection.Collaborate with industry‑leading experts across cybersecurity, cloud, engineering, and health systems.Grow within a high‑performance, innovation‑driven environment.Competitive compensation, career development pathways, and opportunities to work on cutting‑edge security initiatives.