Cybersecurity Offensive Specialist
Listed on 2026-07-06
-
IT/Tech
Cybersecurity
Who Are We
HALA is a leading fintech player in the MENAP region that aims to redefine financial services and build the future bank of SMEs. HALA aims at empowering SMEs to start, run and grow their businesses by providing them with cutting-edge financial and technological tools. HALA currently holds multiple entities in UAE, Saudi Arabia and Egypt, including HALA Payments and HALA Logistics, and offers solutions that enable merchants to digitize their payments as well as manage their sales and operations.
Founded in 2017, HALA is currently licensed by the Saudi Arabian Central Bank.
The Cybersecurity Offense Specialist is primarily responsible for executing the organization’s offensive security assessments by conducting advanced penetration tests to simulate realistic cyberattacks and proactively identify and exploit security vulnerabilities across systems, networks and applications. Critically, this role involves deeply documenting and communicating these findings and attack pathways to both technical and executive audiences, with clear actionable recommendations, and collaborating with defensive security teams to test, validate and enhance the organization’s overall detection and response capabilities against sophisticated real‑world threats.
Key Responsibilities- Execute HALA’s offensive security assessments, red teaming, adversary simulation and penetration testing in alignment with SAMA CSF and NCA ECC requirements.
- Conduct controlled attack exercises on apps, cloud, APIs and payment merchant platforms to validate real‑world exploitability.
- Execute advanced penetration testing and source code reviews to identify deeply rooted vulnerabilities and collaborate with Defense SOC teams to validate and improve detections against these specific attack vectors.
- Maintain and utilize offensive tooling and lab environments, strictly adhering to rules of engagement to ensure safe testing with zero business disruption.
- Deliver clear, detailed remediation guidance to Product Engineering teams and support the tracking and closure of critical findings.
- Ensure all assessment activities, evidence and reporting align with SAMA CSF and NCA ECC control objectives and audit expectations.
- 3‑5 years of experience or additional relevant experience.
- At least one recognized offensive security certification: OSCP, CRTO, eCPPT or equivalent (Required).
- Preferred certifications (one or more): OSEP, OSWE, GXPN, GWAPT, GPEN, or CRTP/CRTE for advanced red team and adversary‑simulation depth.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).