Job Details

Location

Egypt Delivery Center

Offensive Security Tech Lead, Cairo. Egypt


Connect to your career at Deloitte


Deloitte, established globally in 1845, is the world’s largest and leading professional services firm, providing Audit & Assurance, Tax & Legal and Consulting and related services to public and private clients spanning multiple industries. Present in more than 150 countries, Deloitte is distinct in its ability to help clients solve their most complex problems, from strategy to implementation.


Deloitte innovation hub (DIH) is a strategic initiative to support our ambition to become the leading business transformation partner of choice for our clients and to expand and scale our delivery footprint across EMEA. With access to a scaled, diverse, highly skilled, motivated, and engaged workforce, DIH is delivering complex technical solutions for clients’ most complex business problems, across portfolios that include ‘Strategy & Transactions’, ‘Customer’, ‘Engineering, AI & Data, ‘Enterprise, Technology & Performance’ and ‘Cyber’. DIH is aiming to become the destination for top talents in Egypt for a long, exciting career. 


We invest in outstanding people of diverse talents and backgrounds and empower them to achieve more than they could elsewhere. Our work combines advice with action and integrity. We believe that when our clients and society are stronger, so are we. Our organization has grown in scale and diversity, providing services across the region, with our shared culture remaining the same. We aim to help clients realize their ambitions, make a positive difference in society, and maximize the success of our people. This drive fuels the commitment and humanity that run deep through our every action.


Conduct in-depth penetration testing of web applications to identify vulnerabilities such as SQL injection, cross-site scripting (XSS), cross-site request forgery (CSRF), insecure direct object references (IDOR), and other OWASP Top 10 issues.

Test for business logic flaws, session management issues, and authentication/authorization vulnerabilities in web applications.

Use tools like Burp Suite, OWASP ZAP, and manual techniques to identify and exploit web application vulnerabilities.

Scripting and Automation


Research and implement advanced defense evasion techniques to bypass endpoint detection and response (EDR), antivirus, WAFs, and other security solutions.

Develop obfuscation methods for payloads and exploits to avoid detection by SIEM, IDS/IPS, and other monitoring tools.

Stay updated on the latest evasion techniques and adapt strategies to simulate sophisticated adversaries targeting web applications and other systems.

Code Review & Secure Development:


Perform thorough code reviews to identify vulnerabilities in web applications, APIs, and mobile apps, focusing on languages such as Java, JavaScript, Python, PHP, or C#.

Identify insecure coding practices, such as improper input validation, lack of output encoding, and insecure API integrations.

Collaborate with development teams to provide actionable recommendations for secure coding practices and remediation of identified vulnerabilities.

Mobile and API Security


Bachelor’s degree in Cybersecurity, information technology, computer science, or a relevant degree.

Minimum 7+ years of hands-on experience in penetration testing, red teaming, or related offensive security roles.

Proven experience occupying a leadership role in offensive security

Analytical capabilities, critical thinking, and problem-solving mindset (ability to analyze complex data and information to identify key insights and trends).

Proficient in English speaking and writing.

Flexibility for travel and working hours.

strong proficiency in web application pentesting tools such as Burp Suite, OWASP ZAP, and manual testing techniques.

Proficiency in scripting languages such as Python, PowerShell, Bash, or JavaScript for automation and tool development.

Deep understanding of defense evasion techniques, including bypassing WAFs, EDR, and AV solutions.

Expertise in code review for identifying vulnerabilities in web applications, APIs, and mobile apps.

Strong knowledge of mobile security testing tools (e.g., Frida, MobSF, Drozer) and API testing tools (e.g., Postman, Burp Suite).

Familiarity with common pentesting tools like Metasploit, Nmap, Cobalt Strike, BloodHound, and Kali Linux.

Understanding of cloud environments (AWS, Azure, GCP) and their associated attack vectors.

The following attributes are also preferable:


Desired Candidate Profile

  • Bachelor's degree in Cybersecurity, information technology, computer science, or a relevant degree.
  • Minimum 7+ years of hands-on experience in penetration testing, red teaming, or related offensive security roles.
  • Proven experience occupying a leadership role in offensive security
  • Analytical capabilities, critical thinking, and problem-solving mindset (ability to analyze complex data and information to identify key insights and trends).
  • Proficient in English speaking and writing.
  • Flexibility for travel and working hours.
  • Strong proficiency in web application pentesting tools such as Burp Suite, OWASP ZAP, and manual testing techniques.
  • Proficiency in scripting languages such as Python, PowerShell, Bash, or JavaScript for automation and tool development.
  • Deep understanding of defense evasion techniques, including bypassing WAFs, EDR, and AV solutions.
  • Expertise in code review for identifying vulnerabilities in web applications, APIs, and mobile apps.
  • Strong knowledge of mobile security testing tools (e.g., Frida, MobSF, Drozer) and API testing tools (e.g., Postman, Burp Suite).
  • Familiarity with common pentesting tools like Metasploit, Nmap, Cobalt Strike, BloodHound, and Kali Linux.
  • Understanding of cloud environments (AWS, Azure, GCP) and their associated attack vectors.
  • Relevant certifications such as OSCP, OSWE, OSEP, CRTO, CRTP, GWAPT, GXPN, or equivalent are a plus.
  • Active participation in CTF competitions with demonstrated achievements.
  • Experience with penetration testing of AI systems and Large Language Models (LLMs), including testing for vulnerabilities like prompt injection, data poisoning, model inversion, or adversarial attacks.
  • Experience with adversary emulation frameworks like MITRE ATT&CK or Caldera.
  • Knowledge of secure software development lifecycle (SDLC) and DevSecOps practices.
  • Contributions to the security community through blogs, tools, or conference talks.
  • Familiarity with container security (Docker, Kubernetes) and serverless architectures.

Similar Jobs

About Deloitte
Egypt, Egypt
Financial Services