Penetration Tester (Web & API)

🗓️ Posted 2026-08-11 Dubai - United Arab Emirates (UAE) Hybrid ICT

Company shared salary

NA

Market rate

AED 15,000–AED 25,000/mo (AED 180,000–AED 300,000/yr)

Based on similar roles (title + domain + location).

Responsibilities

  • Conduct manual penetration testing of web applications, REST/GraphQL APIs, and WebSockets.
  • Identify vulnerabilities aligned with OWASP Top 10 and OWASP API Security Top 10.
  • Test financial and trading-specific business logic, including transaction manipulation, race conditions, authorization flaws, price manipulation, and session-related vulnerabilities.
  • Perform vulnerability exploitation and validation using Burp Suite and other offensive security tools.
  • Develop custom scripts and techniques to identify vulnerabilities that automated scanners may miss.
  • Assess authentication, authorization, session management, input validation, API security, and transaction flows.
  • Produce detailed penetration testing reports with reproducible steps, risk ratings, business impact, and practical remediation recommendations.
  • Work closely with Development, DevSecOps, and Infrastructure teams to validate vulnerability remediation.
  • Conduct retesting to ensure identified vulnerabilities have been properly resolved.
  • Support continuous improvement of application security testing methodologies and security controls.
  • Ensure security testing activities are conducted with minimal impact on trading systems and business operations.