Job Description – Offensive Cybersecurity Expert (Qatar)
Position: Offensive Cybersecurity Specialist
Location: Qatar
Role Overview
We are seeking a highly skilled Offensive Cybersecurity Specialist. This role focuses on conducting offensive cyber assessments, penetration testing, red-team exercises, and vulnerability management across the bank’s IT applications and infrastructure. The incumbent will ensure compliance with IT Security Policies and Standards, strengthen security posture, and collaborate with internal and external stakeholders.
This is a hands-on, technical role requiring an ethical hacking mindset combined with strong analytical, communication, and reporting skills.
Key Responsibilities
- Perform penetration testing and vulnerability scanning of IT applications, systems, and infrastructure.
- Strong knowledge of penetration testing tools, red-team methodologies, and vulnerability scanning frameworks.
- Experience with DevSecOps, cloud-native security, container orchestration (Kubernetes), and Active Directory security.
- Conduct red team and simulated offensive attack exercises to test resilience.
- Manage vendor relationships for external penetration testing engagements.
- Assess system and application security against IT Security Policies and international standards.
- Provide subject matter expertise for IT security reviews, architecture assessments, and compliance evaluations.
- Work closely with IT and business teams to identify gaps, propose remediation, and improve security posture.
- Support regulatory, audit, and compliance requirements with accurate reporting.
- Stay updated on the latest cyber threats, vulnerabilities, and mitigation techniques.
Education & Experience:
- Bachelor’s degree in IT, Cybersecurity, or related field (Master’s preferred).
- Minimum 4 years of experience in offensive security assessments within banking or Big 4 consultancy.
- Strong experience in penetration testing, vulnerability scanning, and technical risk assessments.
- Exposure to red-team activities highly desirable.
- Mandatory certifications: CISSP, CISM, or CISA.
- Excellent written and verbal communication in English and Arabic.