Senior Offensive Security Engineer
The Company
Toters is an on-demand e-commerce and delivery platform that enables customers to get anything in their city with the highest level of convenience.
At Toters, technology is at the heart of everything we do. Our product teams build features that simplify customers’ lives, while our engineers create scalable solutions to deliver faster and more cost-effectively. If you thrive in a high-growth startup environment and want to help reshape how people shop across the Middle East, join us.
Role Overview
As a Senior Offensive Security Engineer (L5), you will own complex offensive security initiatives that span multiple teams. You will lead advanced penetration testing, red team exercises, and adversarial simulations to uncover systemic weaknesses in our web applications, APIs, mobile apps, cloud infrastructure, identity, payment-adjacent flows, and overall attack surface.
You will act as a hands-on technical leader: influencing secure design decisions with evidence, mentoring mid-level and junior offensive engineers, and driving improvements that meaningfully reduce risk.
Description
In this senior role, you will take end-to-end ownership of offensive security efforts with a focus on high-impact outcomes. Your responsibilities include:
- Lead comprehensive penetration tests and red team / assumed-breach exercises targeting web applications, APIs, mobile applications, cloud infrastructure, and authentication systems (including identity and privileged-access paths).
- Lead mobile offensive testing on Android and iOS, including evaluation and bypass/validation of runtime protection, tamper resistance, certificate pinning / Certificate Transparency, and key/secret shielding using DexProtector or similar RASP / app-shielding tools, plus complementary tooling such as MobSF.
- Perform in-depth threat modeling and identify complex attack paths across services and trust boundaries (including authorization flaws, tenant isolation, token/session issues, edge/WAF bypass, and client-secret exposure).
- Deliver high-quality security assessment reports with clear risk ratings, business impact analysis, practical remediation guidance, and evidence quality that engineering and audit stakeholders can use in a SOC 2 and PCI DSS context—then re-test and validate fixes before closure.
- Collaborate with Engineering, DevOps, Product, and the Security Engineer track to influence secure architecture decisions and ensure vulnerabilities are addressed at the root cause.
- Develop and improve offensive security methodologies, tools, and automation to increase efficiency and coverage. AI-assisted testing is a must.
- Mentor mid-level and junior offensive security engineers, conduct offensive-focused code/design reviews, and help raise the overall security capability of the team.
- Participate in purple team exercises with the detection and incident response teams to improve defenses based on real attack simulations.
- Stay at the forefront of offensive security research, emerging threats, and TTPs, and assess their relevance to Toters.
- Contribute offensive input to security standards, policies, and secure development practices across the engineering organization (you advise; you do not own policy issuance or GRC evidence packs).
- Support structured disclosure (VDP / researcher reports) through reproduce, rate, de-duplicate, and validate.
Key Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience.
- 6+ years of hands-on experience in offensive security, penetration testing, or red teaming.
- Strong expertise in web application, API, and mobile security testing (Android and iOS).
- Working knowledge of DexProtector or similar mobile shielding / RASP tooling: what it protects, how testers evaluate residual risk, and how to validate that hardening holds.
- Advanced proficiency with offensive security tools (Burp Suite, Metasploit, Cobalt Strike or equivalent adversary-emulation platforms, custom tooling, etc.).
- Proficient in writing robust, reusable scripts and small tools for automation (Python preferred, Bash for quick tasks).
- Solid experience with cloud security testing (AWS preferred) and infrastructure attack techniques.
- Proven ability to lead complex security assessments from scoping to reporting and remediation validation.
- Strong risk assessment and threat modeling skills, with the ability to communicate technical risks clearly to both technical and non-technical stakeholders.
- Familiarity with SOC 2 and PCI DSS as they apply to offensive work (scoped pentests, application/API/payment-adjacent testing, evidence-quality reporting). This role does not own control design or audit evidence collection.
- Experience mentoring engineers and influencing cross-team security practices.
- Excellent written and verbal communication skills in English.
Nice to Have
- Industry-recognized certifications such as OSCP, OSCE, OSEP, CRTO, or PNPT.
- Experience running full-scope red team or assumed-breach exercises.
- Experience developing custom exploits, tooling, or automation for offensive security.
- Knowledge of MITRE ATT&CK and adversary emulation.
- AI and AI pentesting: testing LLM/agent applications (prompt injection, tool/plugin abuse, data-exfil via agents) and using AI-assisted pentest workflows with mandatory human review.
- Previous experience in high-scale e-commerce, delivery, or fintech environments, including payment API / tokenization / third-party PSP testing as a tester (not as PCI control owner).
- Fluency in Arabic and English (French is a plus).
What We Offer
- Competitive compensation package.
- Discounts on Toters orders.
- First-class medical insurance.
Ready to own offensive security at scale and help build a safer platform for millions across the Middle East? Apply now!
