More jobs:
Cybersecurity Offensive Security Specialist
Job in
Kuwait City, Kuwait
Listed on 2026-09-21
Listing for:
International Turnkey Systems - ITS
Full Time
position Listed on 2026-09-21
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Network Security, Security Management & Operations
Job Description & How to Apply Below
The Cybersecurity Offensive Security Specialist is responsible for conducting advanced security assessments, penetration testing, red team operations, and security reviews across web applications, APIs, mobile applications, networks, cloud environments, IoT devices, and Operational Technology (OT) systems. The role focuses on identifying vulnerabilities, validating security controls, simulating real-world cyberattacks, and providing actionable remediation recommendations to improve the organization’s security posture.
Key Responsibilities Red Teaming & Adversary Emulation- Conduct advanced red team exercises simulating real-world threat actors.
- Execute attack scenarios aligned with MITRE ATT&CK framework.
- Perform phishing campaigns, credential attacks, social engineering simulations, and lateral movement exercises.
- Assess cyber defense effectiveness including SOC, SIEM, EDR
- Develop custom attack techniques and proof-of-concept exploits.
- Conduct Purple Team exercises with security monitoring teams.
- Perform black-box, gray-box, and white-box penetration testing.
- Assess internal and external network environments.
- Identify vulnerabilities in:
- Active Directory
- Windows and Linux systems
- Databases
- Virtualization environments
- Cloud platforms
- Validate remediation effectiveness through re-testing activities.
- Conduct security assessments against web applications using OWASP Testing Methodology.
- Identify vulnerabilities including:
- SQL Injection
- Cross-Site Scripting (XSS)
- Authentication flaws
- Session management weaknesses
- CSRF
- Access control issues
- File upload vulnerabilities
- Business logic flaws
- Perform manual exploitation and validation of findings.
- Review security architecture and secure coding controls.
- Conduct security testing of REST, SOAP, GraphQL, and Microservices APIs.
- Identify:
- Broken Object Level Authorization (BOLA)
- Broken Authentication
- Excessive Data Exposure
- SSRF Vulnerabilities
- Insecure Direct Object References
- JWT Security Weaknesses
- API Abuse Scenarios
- Assess API Gateway implementations and security controls.
- Review API documentation and specifications.
- Perform static and dynamic security assessments.
- Analyze APK packages and mobile application architecture.
- Evaluate local storage security, cryptography implementation, and backend integrations.
- Assess iOS application security controls.
- Perform runtime security analysis.
- Test jailbreak protections and application hardening mechanisms.
- Reverse engineering
- SSL Pinning bypass testing
- Data leakage assessments
- Secure storage validation
- Root/Jailbreak detection testing
- Mobile API security testing
- Conduct security assessments of Internet of Things (IoT) devices.
- Evaluate:
- Device firmware security
- Wireless communication protocols
- Authentication mechanisms
- Device hardening controls
- Embedded operating systems
- Perform firmware extraction and analysis.
- Identify insecure configurations and exposed services.
- Produce high-quality technical and executive security assessment reports.
- Present findings to technical and business stakeholders.
- Provide practical remediation recommendations.
- Assist asset owners with vulnerability remediation planning.
- Track remediation progress and perform validation testing.
- Red Team Operations
- Threat Emulation
- Penetration Testing Methodologies
- MITRE ATT&CK
- Cyber Kill Chain
- OWASP Top 10
- OWASP API Security Top 10
- Burp Suite Professional
- Postman
- JWT, OAuth2, OpenID Connect
- MobSF
- Frida
- Objection
- APKTool
- JADX
- Burp Suite Mobile Testing
- Active Directory Security
- Windows Security
- Linux Security
- Network Security
- Wireless Security
- Embedded Device Security
- Firmware Analysis
- Python
- Power Shell
- Bash
- API Automation
- Bachelor s Degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering, or related field.
- 4+ years of hands‑on penetration testing experience.
- Proven experience in:
- Red Teaming
- Web Application Security
- API Security Testing
- Mobile Security Assessments
- IoT/OT Security Assessments
- OSCP
- PNPT
- CRTO
- OSEP
- OSWE
- eWPTX
- eMAPT
- GMOB
- GICSP
- GRID
- GPEN
- GWAPT
- CARTP
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×