Senior Offensive Security Engineer
On-siteDubai, Dubai, United Arab Emirates
Job Summary
Plan and execute full-kill-chain red team engagements across cloud, Kubernetes, CI/CD, and AI agent stacks, conducting social engineering simulations and source code analysis against trading and payment platforms. Build custom tooling and C2 infrastructure to evade detection while partnering with SOC to run purple-team exercises that close detection gaps. Mentor L1/L2 operators and author remediation-focused reports that drive actual fixes within a live financial environment processing $600B monthly. Report directly to leadership with a path from discovery to closure, shaping offensive security capabilities for a distributed team in Dubai and Malaysia.
Required Qualifications
- 6+ years doing actual offensive security
- Full-scope red team
- OSCP
- OSCE
- OSEP
- OSED
- CRTO
- Real depth in at least three of: internal AD/network exploitation, cloud attack paths (AWS/GCP), web/API exploitation, custom C2 development, social engineering/physical, mobile
- You can write your own tooling and implants in Python, Go, or Rust
- You've operated against modern EDR-instrumented environments
- You understand blast radius in a regulated fintech
- You can write a report that gets fixed
Desired Qualifications
- OSCE
- OSEP
- OSED
- CRTO
- equivalent adversary simulation cert
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.