We are looking for a highly-motivated and dynamic candidate to join our Red Team and who will support our red teaming security program and offensive security operations. The candidate is expected to participate in Red Team/Purple team operations/penetration testing and adversary emulation assessments.
Responsibilities
- We are looking for a highly-motivated and dynamic candidate to join our Red Team and who will support our red teaming security program and offensive security operations.
- The candidate is expected to participate in Red Team/Purple team operations/penetration testing and adversary emulation assessments.
- Additionally, the candidate will assist Noon’s company in enhancing their cybersecurity resilience by providing an "attacker's approach" and identifying high-impact attack vectors that threat actors could use.
- An ideal candidate should have a passion for red teaming, must demonstrate technically sound offensive security skills, and have an attacker mindset.
- The candidate is also expected to coordinate across the infosec department to plan and oversee the execution of assessments, as well as assist in helping improve Noon security defense.
- Conduct thorough penetration testing for web services and APIs.
- Perform comprehensive security reviews on services and features.
- Validate and prioritize findings from various security pipelines, including but not limited to SAST and DAST integrations, and the bug bounty program, effectively distinguishing genuine issues from false positives.
- Enhance our pipeline's detection capabilities working on tuning scanners and identifying systemic gaps.
- Collaborate directly with development teams to ensure timely and effective remediation of vulnerabilities.
- Verify all reported security issues are fully resolved and not merely marked as closed, tracking SLAs etc.
Requirements
- We are hiring for Med/Senior levels.
- Strong hands-on web & API pentesting with ability to move beyond common vuln classes into real attack paths.
- Deep understanding of advanced vulnerabilities (SSRF with pivoting, injections, auth flaws, business-logic abuse).
- Ability to analyze systems across layers: code (backend logic), HTTP/protocol (request smuggling, caching issues), and architecture (trust boundaries, service interactions).
- Solid understanding of HTTP internals (parsing inconsistencies, proxy/CDN behavior, header manipulation).
- Capable of validating scanner findings, eliminating noise, and identifying detection gaps to improve coverage.
- Able to chain multiple weaknesses into realistic exploitation scenarios with clear impact.
Additional details
- Who are we? noon, the region's leading consumer commerce platform. On December 12th, 2017, noon launched its consumer platform in Saudi Arabia and the UAE, expanding to Egypt in February 2019. The noon ecosystem of services now includes marketplaces for food delivery, quick-commerce, fintech, and fashion. noon is a work in progress; we’re six years in, but only 5% done. Noon’s mission: every door, every day.
- Who will excel? ‘noon isn’t for everyone. And that’s okay.’ This is one of our core operating principles.
- We’re looking for resourceful doers. Thinkers who are both creative and analytical. Problem solvers who are enthusiastic about delivering results. Our ideal candidate will be comfortable in a fast-paced, multi-tasked, high-energy and often ambiguous environment.
- If the above values resonate with you, then noon might be the place for you.