Penetration Tester
Antons
Posted 30+ days ago
Send me Jobs like this
Nationality
Any Nationality
Gender
Not Mentioned
Vacancy
1 Vacancy
Job Description
Roles & Responsibilities
Conduct penetration testing on web applications, APIs, networks, and cloud environments.
- Perform security assessments of CI/CD pipelines, including build, test, and deployment workflows.
- Identify vulnerabilities related to source code repositories, automation tools, container images, and secrets management.
- Test authentication, authorization, session management, and access controls.
- Assess API security, including token handling, rate limiting, and authorization flaws.
- Execute static (SAST), dynamic (DAST), and dependency security testing within CI/CD processes.
- Validate security of containerized environments (Docker, Kubernetes).
- Simulate real-world attack scenarios and document findings with clear remediation guidance.
- Collaborate with development and DevOps teams to implement secure-by-design practices.
- Support incident response investigations and post-incident analysis when required.
Required Skills & Experience
- 2+ years of experience in penetration testing, application security, or ethical hacking.
- Strong understanding of CI/CD pipelines and DevSecOps methodologies.
- Hands-on experience securing tools such as GitHub Actions, GitLab CI, Jenkins, Azure DevOps, or similar.
- Proficiency in web and API security testing (OWASP Top 10, OWASP API Top 10).
- Experience with authentication mechanisms (JWT, OAuth2, SSO).
- Knowledge of common vulnerabilities: SQLi, XSS, CSRF, SSRF, IDOR, RCE, misconfigurations.
- Familiarity with Linux environments, networking concepts, and cloud security fundamentals.
Tools & Technologies
- Penetration testing tools: Burp Suite, Metasploit, Nmap, OWASP ZAP, Nikto.
- CI/CD security tools: Snyk, Trivy, SonarQube, Dependabot, GitGuardian.
- Container and cloud security tools (experience preferred).
- Scripting knowledge in Python, Bash, or PowerShell is an advantage.
Desired Candidate Profile
2+ years of experience in penetration testing, application security, or ethical hacking.
- Strong understanding of CI/CD pipelines and DevSecOps methodologies.
- Hands-on experience securing tools such as GitHub Actions, GitLab CI, Jenkins, Azure DevOps, or similar.
- Proficiency in web and API security testing (OWASP Top 10, OWASP API Top 10).
- Experience with authentication mechanisms (JWT, OAuth2, SSO).
- Knowledge of common vulnerabilities: SQLi, XSS, CSRF, SSRF, IDOR, RCE, misconfigurations.
- Familiarity with Linux environments, networking concepts, and cloud security fundamentals.
Company Industry
Department / Functional Area
Keywords
- Penetration Tester
Disclaimer: Naukrigulf.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@naukrigulf.com
Similar Jobs
Application Security Engineer
Byte Guard
- 1 - 5 Years
- Jeddah - Saudi Arabia
Senior Penetration Tester
Dicetek LLC
- 7 - 14 Years
- Dubai - United Arab Emirates (UAE)
ETIC, Ethical Hacking Senior Associate - Cyber Security
PricewaterhouseCoopers
- 1 - 3 Years
- Egypt - Egypt
Senior Bug Bounty Security Engineer
Client of RecruitMe Plus
- 5 - 7 Years
- Dubai - United Arab Emirates
Penetration Tester
Al Reem Group
- 1 - 7 Years
- Abu Dhabi - United Arab Emirates