OT Penetration Tester - dubai - GSS Tech Group

    GSS Tech Group
    GSS Tech Group dubai

    1 day ago

    Description
    Job Purpose

    The OT Penetration Tester is responsible for assessing the security posture of Operational Technology environments, including Industrial Control Systems (ICS), SCADA networks, PLCs, and critical infrastructure components.

    This role requires a safety-first approach, ensuring that all testing activities are performed without disrupting operations, affecting equipment, or compromising safety.

    The tester will identify vulnerabilities, evaluate risks, and provide clear recommendations to strengthen the resilience of industrial systems.
    Key Accountabilities
    Strategic

    Design, develop, and implement comprehensive OT penetration testing methodologies, frameworks, and testing procedures tailored specifically for utility sector operational technology environments, including electric grid systems, water/wastewater treatment facilities, natural gas distribution networks, and renewable energy installations.

    Build and maintain specialized security testing capabilities for ICS/SCADA protocols including Modbus, DNP3, IEC 61850, IEC , OPC UA, BACnet, Profinet, EtherNet/IP, and other utility-specific communication protocols

    Support the company's OT cybersecurity service strategy by delivering high-quality penetration testing aligned with UAE national cybersecurity frameworks (NESA, DESC, TDRA, and sector-specific regulations).

    Contribute to the development and continuous improvement of OT penetration testing methodologies, service offerings, and best practices.
    Provide strategic insights to management on emerging OT threats, client needs, and opportunities to enhance service capabilities.
    Ensure testing activities align with client risk profiles, contractual obligations, and long-term service objectives.
    Participate in pre-sales discussions by providing technical expertise to support proposals, scoping, and solution design.
    Create and maintain comprehensive knowledge repositories documenting OT vulnerabilities, exploit techniques, vendor-specific security weaknesses, and industry-specific threat intelligence relevant to the utility sector
    Design and implement red team exercises and adversary emulation scenarios that simulate real-world attack campaigns.
    Functional
    Perform safe, controlled penetration testing on OT networks, ICS/SCADA systems, PLCs, RTUs, HMIs, and industrial communication protocols for external clients.
    Conduct assessments of network segmentation, firewall rules, access controls, and industrial communication pathways.
    Identify vulnerabilities, misconfigurations, and potential attack vectors while ensuring zero disruption to client operations.
    Produce high-quality technical reports tailored for both technical and executive audiences, including risk ratings and remediation guidance.
    Present technical findings to diverse audiences including C-suite executives, engineering teams, operations management, regulatory compliance officers, and board-level stakeholders, translating complex technical vulnerabilities into business risk language
    Validate remediation actions and conduct re-testing as part of the managed service lifecycle.
    Support incident response engagements by providing exploitation insights and OT threat analysis when required.
    Ensure all testing activities comply with UAE laws, client contracts, and industry standards (IEC 62443, NIST
    Operations
    Deliver penetration testing engagements within agreed timelines, scope, and service-level agreements (SLAs).
    Coordinate with client operations, engineering teams, and plant management to define safe testing windows and boundaries.
    Maintain strict adherence to safety protocols, change-management processes, and client operational requirements.
    Document all testing activities, evidence, and results in accordance with internal and client audit requirements.
    Track and follow up on remediation progress with clients as part of ongoing managed service support.
    Ensure continuous improvement of tools, processes, and testing methodologies used in service delivery.
    Execute wireless security assessments of field communications including radio systems, satellite communications, cellular backhaul, and industrial wireless sensor networks deployed across utility infrastructure
    Perform security validation of cloud and hybrid architectures as utilities increasingly adopt cloud-based analytics, monitoring platforms, and distributed energy resource management systems (DERMS)
    People
    Collaborate with internal teams including SOC, OT engineers, service delivery managers, and cybersecurity consultants.
    Provide mentorship and technical guidance to junior penetration testers and analysts within the managed service team
    Conduct knowledge-sharing sessions, workshops, or awareness programs for clients on OT security risks and best practices.
    Communicate complex technical findings clearly and professionally to both technical and non-technical client stakeholders.
    Promote a culture of safety, professionalism, and client-centric service delivery within the team.
    Business Strategy
    Support the company's managed security services growth by delivering high-quality, client-satisfying penetration testing engagements.
    Provide input to enhance service offerings, pricing models, and value-added capabilities based on client feedback and market trends.
    Ensure testing activities support client business continuity, operational reliability, and regulatory compliance.
    Qualifications
    Bachelor's degree in Computer Science, Information Security, Electrical Engineering, Control Systems Engineering, or a related technical discipline.

    Preferred professional certifications:

    ICS/OT Security:
    GICSP, GRID, ISA/IEC 62443 Cybersecurity certifications

    Offensive Security:
    OSCP, OSWP, OSCE, OSEP

    Penetration Testing:
    CEH, CPT, GPEN, GXPN
    Additional OT-focused training or vendor certifications (e.g., Siemens, Schneider, ABB, Honeywell, Emerson) are highly advantageous.
    Strong working knowledge of industry standards and regulatory frameworks including:
    IEC 62443
    NIST SP 800-82
    UAE cybersecurity frameworks (NESA, DESC, TDRA)
    Experience
    8–10 years of hands‑on experience in penetration testing, vulnerability assessment, or red team operations.

    Minimum 3 years of direct experience within OT/ICS/SCADA environments, preferably in utilities, oil & gas, manufacturing, or other critical infrastructure sectors.

    Proven experience conducting safe and controlled security assessments across:
    ICS/SCADA networks
    PLCs, RTUs, and HMIs
    Industrial protocols (Modbus, DNP3, OPC UA, Profinet, etc.)
    Experience delivering managed security services or consulting engagements in client‑facing environments
    Language Requirements
    Fluent in English (spoken and written) – essential for client communication and technical reporting.
    Arabic proficiency is an advantage, particularly for UAE government and semi‑government engagements.
    Job‑Specific Skills
    Technical Competencies
    Strong understanding of OT/ICS architectures, industrial networking, and control system components.
    Advanced expertise in penetration testing methodologies, tools, and techniques (manual and automated).

    Ability to perform:
    Network penetration testing
    ICS protocol analysis
    Firewall and network segmentation assessments
    Wireless security testing
    Secure configuration reviews
    Strong awareness of OT-specific risk factors including safety impact, operational continuity, and system availability.
    Familiarity with SIEM platforms, SOC processes, and OT-focused incident response practices.
    Soft & Professional Skills
    Strong analytical and critical thinking capabilities.
    Excellent communication, stakeholder management, and presentation skills.
    Ability to operate effectively in high-risk, safety-critical environments.
    Strong documentation and technical reporting skills.
    Ability to collaborate with cross‑functional teams (OT engineers, SOC teams, governance, and operations).
    High level of professionalism, discretion, and compliance with UAE legal and regulatory requirements.
    Core Competencies
    OT Cybersecurity Assessment & Testing
    Red Team & Advanced Penetration Testing
    Industrial Network Security
    Regulatory & Compliance Alignment (UAE Frameworks)
    Client Advisory & Technical Reporting
    Risk-Based Security Assessment
    Cross-Functional Collaboration in Critical Infrastructure Environments
    #J-18808-Ljbffr

  • Work in company

    Penetration Tester

    Only for registered members

    We are seeking a skilled Penetration Tester with strong experience in CI/CD pipeline security to identify, assess, and mitigate security vulnerabilities across applications, infrastructure, and automated deployment environments. The role focuses on proactive security testing, sec ...

    Dubai د.إ180,000 - د.إ360,000 (AED) per year

    1 week ago

  • Work in company

    Penetration Tester

    Antons Recruitment Agency

    · We are seeking a skilled Penetration Tester with strong experience in CI/CD pipeline security to identify, assess, and mitigate security vulnerabilities across applications, infrastructure, and automated deployment environments. The role focuses on proactive security testing, ...

    Dubai, United Arab Emirates د.إ180,000 - د.إ360,000 (AED) per year

    1 week ago

  • Work in company

    Penetration Tester

    Guildhall Live Jobs

    This role will be responsible for conducting comprehensive security assessments across web and mobile applications, networks, and cloud infrastructures. · ...

    Dubai, United Arab Emirates د.إ180,000 - د.إ360,000 (AED) per year

    1 week ago

  • Work in company Remote job

    Penetration Tester

    Only for registered members

    FearsOff is a leading cybersecurity services provider, specializing in security assessments, offensive and continuous security testing for crypto exchanges, trading platforms, and financial institutions.The company is globally recognized for identifying and remediating critical v ...

    Dubai

    1 month ago

  • Work in company

    Penetration Tester

    Only for registered members

    Conduct penetration testing on web applications and APIs. · ...

    Dubai

    1 month ago

  • Work in company

    OT Penetration Tester

    Only for registered members

    The OT Penetration Tester is responsible for assessing the security posture of Operational Technology environments. · The tester will identify vulnerabilities and provide clear recommendations to strengthen the resilience of industrial systems. · QualificationsBachelor's degree ...

    Dubai

    3 weeks ago

  • Work in company

    Sr. Penetration Tester

    Only for registered members

    We are seeking a highly skilled Penetration Testing Engineer to join our cybersecurity team. The ideal candidate will perform complex security assessments, across infrastructure, applications, and cloud environments for internal as well as external clients. The ideal candidate wi ...

    Dubai

    6 days ago

  • Work in company

    OT Penetration Tester

    Only for registered members

    We are seeking an elite OT Penetration Tester to join our mission-critical team in Dubai. This freelance opportunity is designed for those who thrive on safeguarding the world's most vital infrastructure — from electric grids to water treatment plants — and who understand that in ...

    Dubai

    1 week ago

  • Work in company

    OT Penetration Tester

    Only for registered members

    JOB PURPOSE: · The OT Penetration Tester is responsible for assessing the security posture of Operational Technology environments, including Industrial Control Systems (ICS), SCADA networks, PLCs, and critical infrastructure components. This role requires a safety-first approach, ...

    Dubai, Dubai

    6 days ago

  • Work in company

    OT Penetration Tester

    Only for registered members

    JOB PURPOSE: · The OT Penetration Tester is responsible for assessing the security posture of Operational Technology environments, including Industrial Control Systems (ICS), SCADA networks, PLCs, and critical infrastructure components. This role requires a safety-first approach, ...

    Dubai

    6 days ago

  • Work in company

    Senior Penetration Tester

    Only for registered members

    Web Application VAPT · Mobile Application VAPT [iOS & Android] · Network VAPT · Threat Modeling · Secure Code Review · Secure Architecture Review · Vulnerability Research and Exploitation · Hardware Reverse Engineering · Developing VAPT Tools & Software · Desired Candidate Profil ...

    Dubai

    1 week ago

  • Work in company

    Senior Penetration Tester

    Only for registered members

    Perform penetration testing and vulnerability research on complex proprietary software hardware and client service environments. · Identify and assess vulnerabilities in systems and applications using manual automated testing methods including the discovery exploitation of code f ...

    Dubai

    1 month ago

  • Work in company

    Penetration Tester

    Only for registered members

    FearsOff is looking for an experienced Penetration Tester to deliver high-quality security testing across modern client environments. · CREST certification or accreditation is mandatory. · Apply by sending your CV and CREST certification details. CREST certified or accredited (re ...

    Dubai

    1 month ago

  • Work in company

    Penetration Tester

    Only for registered members

    Conduct comprehensive vulnerability assessments and penetration tests on diverse systems and applications to identify security weaknesses. · Develop and execute detailed penetration testing methodologies, including reconnaissance, exploitation, and post-exploitation phases to sim ...

    Dubai - United Arab Emirates (UAE) د.إ180,000 - د.إ360,000 (AED) per year Full time

    17 hours ago

  • Work in company

    Cyber Security Consultant, Penetration Tester

    Only for registered members

    As Security Consultant you will use your existing strong technical and analytical skills to develop a strategic and pragmatic view of enterprise security as well as conduct detailed security assessments (vulnerability analysis, penetration testing, red team engagements) for both ...

    Dubai, Dubai

    1 month ago

  • Work in company

    OT Penetration Tester

    Only for registered members

    As an OT Penetration Tester, you will be instrumental in protecting critical infrastructure across the utility sector. Your expertise will directly impact the safety, reliability, and operational continuity of essential services. · This is your chance to drive meaningful change w ...

    Dubai

    2 weeks ago

  • Work in company

    Senior Penetration Tester(Arabic Speaker)

    Only for registered members

    Perform penetration testing and vulnerability research on complex proprietary software hardware and client service environments · ...

    Dubai, Dubai

    1 month ago

  • Work in company

    Cyber Security Consultant Penetration Tester

    Only for registered members

    The job description is for a Cyber Security Consultant Penetration Tester who will use their strong technical and analytical skills to develop a strategic and pragmatic view of enterprise security. They will conduct detailed security assessments including vulnerability analysis, ...

    Dubai, Dubai

    1 month ago

  • Work in company

    Senior Penetration Tester

    Only for registered members

    We are seeking an experienced Senior Penetration Tester to join our team. · We require experience in Web Application VAPT and Mobile Application VAPT iOS & Android. · ...

    Dubai

    1 month ago

  • Work in company

    OT Penetration Tester

    Only for registered members

    JOB PURPOSE: · The OT Penetration Tester is responsible for assessing the security posture of Operational Technology environments, including Industrial Control Systems (ICS), SCADA networks, PLCs, and critical infrastructure components. This role requires a safety-first approach, ...

    Dubai

    1 week ago

  • Work in company

    AI Penetration Tester

    Only for registered members

    A highly skilled AI Penetration Tester is sought to assess the robustness security and resilience of AI systems across their lifecycle. · ...

    Dubai

    2 weeks ago

Jobs
>
Dubai