{bc}
linkedin

Specialist - Offensive Security

PureCS
Dubai, UAE
Full-time
Entry
Onsite
Discovered 2 weeks ago
Offensive securityPenetration testingNetwork securityWeb application security testingMobile application security testingAPI security testing
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

Offensive securityPenetration testingNetwork security
Smart Apply

Full Job Posting

Role Overview

PureCS is seeking an Offensive Security Specialist to strengthen cybersecurity across national-scale digital health platforms.

The role reports to the Head of Cybersecurity and is located in Dubai, transitioning to Abu Dhabi.

Penetration Testing and Exploitation

  • Execute periodic penetration tests across network, infrastructure, cloud, and application layers using black-box, gray-box, and white-box approaches.
  • Test network perimeters, internal segments, Active Directory or Entra ID, servers, endpoints, and hyperscaler cloud environments.
  • Conduct web, mobile, thick-client, and API penetration testing with remediation follow-up.
  • Perform controlled post-exploitation, privilege escalation, and lateral movement to demonstrate business impact.

Application and DevSecOps Security

  • Collaborate with development teams to test incremental changes during sprints.
  • Review SAST, DAST, and SCA outputs, prioritize critical issues, and coordinate fixes.
  • Integrate and use SAST and SCA tooling within DevOps pipelines.
  • Prepare secure coding practice documents tailored to organizational frameworks.

Threat and Vulnerability Management

  • Map engagements to OWASP Top 10, MITRE ATT&CK, and CVSS scoring.
  • Validate and triage automation outputs, eliminate false positives, and confirm exploitability.
  • Retest remediated findings and maintain accurate closure and coverage tracking.

Red Teaming and Automation

  • Support red and purple team exercises by validating detection and response capabilities with blue teams.
  • Develop scripts and tooling to automate standardized testing use cases.
  • Improve offensive security tooling, automation, and processes.

Qualifications and Experience

  • At least 3 years of hands-on offensive security or penetration testing experience across network and application environments.
  • At least 6 years of total IT experience.
  • Strong experience with Active Directory attack paths, privilege escalation, lateral movement, and exploitation.
  • Working knowledge of manual testing for web, mobile, API, and thick-client applications.
  • Understanding of operating system internals, network protocols, services, authentication, authorization, and common misconfigurations.
  • Knowledge of cloud-native application architecture and cloud infrastructure security.
  • Strong documentation, communication, and stakeholder risk communication skills.

Tools and Certifications

  • Proficiency with Burp Suite, Nmap, Metasploit, BloodHound, Impacket, and command-and-control frameworks.
  • Comfort with Python, PowerShell, and Bash scripting and adapting public exploits.
  • OSCP or PNPT certification is required or may be in progress.
  • OSWE, OSWA, eWPTX, or GWAPT certifications are preferred.
  • CRTP or CRTO certifications are a plus.

Why Work With PureCS

  • Work on national-scale digital health platforms with impact on patient safety and data protection.
  • Collaborate with cybersecurity, cloud, engineering, and health systems experts.
  • Access career development opportunities and work on cutting-edge security initiatives.

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at PureCS