×
Register Here to Apply for Jobs or Post Jobs. X

VAPT Technical Lead

Job in Ras Al Khaimah, Ras Al Khaimah, UAE/Dubai
Listing for: Human Resources Department of Ras Al Khaimah Government
Full Time position
Listed on 2026-01-01
Job specializations:
  • IT/Tech
    Cybersecurity, IT Consultant
  • Engineering
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 200000 - 300000 AED Yearly AED 200000.00 300000.00 YEAR
Job Description & How to Apply Below

KEY ACCOUNTABILITIES & RESPONSIBILITIES

Performing regular vulnerability scans for all EGA IT Assets and prioritizing vulnerabilities based on risk.

Coordinating and supporting with IT Infrastructure teams for patch management and Web Application Development Teams for the code level remediations. Tracking and reporting on vulnerability posture.

Managing remediation activities from (EGA VAPT Program, Digital Forensics Operations, Security Performance Management Platforms, Trust.ae)

Collect, process, and analyze diverse threat intelligence to understand adversary tactics, techniques, and procedures (TTPs).

Formulate data-driven theories about potential hidden threats within the organization's environment.

Actively search through vast volumes of security logs and network data to uncover subtle malicious activities.

Develop specialized scripts and advanced queries to facilitate complex threat detection and analysis.

Generate clear vulnerability, intelligence reports and elevate confirmed threats to incident response teams with supporting forensic insights.

Provide critical feedback to improve existing security tools, detection rules, and overall defensive strategies.

Work closely with other security teams and leadership to communicate threat landscapes and enhance collective awareness.

Conduct Onsite Penetration Testing for EGA and its departments on site, on web applications, on Mobile Applications and APSs every Quarter in a year.

Manage VAPT engagements across networks, applications, cloud, and endpoints using industry-standard tools (e.g., Qualys, Burp Suite, Nessus, Metasploit, Nmap) and perform manual and automate Source Code Review of internally developed web applications. Manage end to end activity with the Web application Development team for the SSDLC (Secure Software Development Life Cycle)

Simulate real-world attack scenarios, developing threat models, and evaluating system resilience against advanced persistent threats (APTs).

Competent in producing clear, executive-level reports and technical documentation, articulating vulnerabilities, risks, and remediation strategies to both technical and non-technical stakeholders.

Stakeholder management and Team work:
Managing the departmental collaboration within EGA IT and the Government Department IT Departments and the Government Departments themselves to promote security best practices and ensure vulnerabilities are understood and remediated effectively.

Incident Response:
Collaborating with incident response teas suring security events and forensic investigations to, again, and ensure vulnerabilities are understood and remediated effectively.

Automation and AI :
Using Vulnerability Scanning automation and AI tools AI to spot patterns and vulneraibilities that saves the information security team from unnecessary efforts.

QUALIFICATIONS & EXPERIENCE

Bachelor’s degree in cyber security or information security engineering, Electronic and Telecommunication Engineering, IT Engineering, Computer Engineering, or any relevant discipline

Preferred

Bachelor’s degree in cyber security or information security engineering, Electronic and Telecommunication Engineering, IT Engineering, Computer Engineering

Minimum 7 years of Experience on the VAPT Domain

Preferred :
Preferred 10 years of Experience on the VAPT Domain

Certifications

OSCP, CEH and MS-AZ are prior to be acceptable but other certifications are acceptable as well.

Minimum 3 VAPT subject matter certification is required.

Preferred:
  • Offensive Security Certified Professional (OSCP)
  • Certified Ethical Hacker (CEH)
  • GIAC Penetration Tester (GPEN)
  • CompTIA Pen Test+
  • Microsoft Certified Azure Security Engineer Associate

English Language (spoken and written) – Essential, Arabic Language (spoken and written)

#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary