
G42
Senior Specialist - Penetration Testing (Red Team)
- Permanent
- Abu Dhabi, United Arab Emirates
- Experience 2 - 5 yrs
Job expiry date: 10/12/2025
Job overview
Date posted
26/10/2025
Location
Abu Dhabi, United Arab Emirates
Salary
AED 15,000 - 20,000 per month
Compensation
Comprehensive package
Experience
2 - 5 yrs
Seniority
Senior & Lead
Qualification
Bachelors degree
Expiration date
10/12/2025
Job description
The Senior Specialist - Penetration Testing (Core42) is a key member of the Red Team responsible for conducting advanced penetration testing and red teaming activities across the organizationās infrastructure, applications, and networks. The role involves identifying vulnerabilities, assessing overall security posture, and collaborating with internal teams to ensure timely remediation and system hardening. The specialist performs end-to-end testing on internal and external assets, leveraging open-source intelligence (OSINT) and threat intelligence to simulate real-world attacks. Responsibilities include application security testing on both web and mobile platforms, manual and automated source code reviews, and comprehensive security assessments for wireless and IoT devices. The role also supports vulnerability management, ensuring prioritization and remediation across all assets. Additional responsibilities include performing network and configuration reviews of firewalls, VPNs, and Active Directory environments (Azure and on-prem), implementing CIS-aligned hardening standards, and documenting detailed test methodologies, findings, and remediation steps. The position demands hands-on technical expertise in industry-standard tools such as Burp Suite, Metasploit, Nmap, Kali Linux, and Bloodhound, as well as scripting proficiency in Python, PowerShell, and Bash. The ideal candidate will hold relevant certifications like OSCP, OSCE, CRTP, CREST, CISSP, or GWAPT and possess strong communication skills to articulate complex technical findings to both technical and executive stakeholders.
Required skills
Key responsibilities
- Perform proactive red teaming and penetration testing exercises on internal and external assets to evaluate and improve security posture
- Conduct OSINT and threat intelligence gathering using open source and commercial tools to understand the threat landscape
- Execute comprehensive penetration tests on web and mobile applications using both manual and automated methods, providing detailed vulnerability reports and remediation recommendations
- Perform manual and automated source code reviews to identify security weaknesses and collaborate with developers for resolution
- Assess and secure wireless networks and IoT devices through testing and configuration validation
- Support the vulnerability management program by identifying, prioritizing, and coordinating remediation efforts across organizational assets
- Implement infrastructure and server hardening in alignment with CIS standards and organizational baselines
- Review network and security device configurations and rulesets, including firewalls and VPNs, ensuring adherence to best practices
- Conduct detailed Azure and on-prem Active Directory assessments to identify weaknesses and recommend countermeasures
- Prepare detailed documentation for all assessments including methodologies, findings, and remediation steps
- Collaborate with cross-functional teams to enhance organization-wide security awareness and ensure consistent improvement of defenses
Experience & skills
- Bachelorās degree in Computer Science, Information Security, or a related field (or equivalent work experience)
- Preferred certifications such as OSCP, OSCE, CRTP, CREST, CISSP, GWAPT, or equivalent
- Strong hands-on experience with manual penetration testing methodologies and red team tactics
- Proficiency in tools such as Burp Suite, Metasploit, Nmap, Kali Linux, and Bloodhound
- Experience conducting security assessments across network, infrastructure, web, mobile, wireless, IoT, containers, and Kubernetes environments
- Proficiency in scripting languages such as Python, PowerShell, and Bash for automation and tool development
- Excellent communication skills for conveying complex technical findings to both technical and non-technical stakeholders
- Proactive and collaborative mindset with the ability to work across teams to enhance security posture