About Us:
EhsanLab is a leading software testing and cybersecurity company delivering enterprise-grade solutions in quality assurance, performance testing, and advanced security services.
As part of our expansion into AI-driven automation and intelligent systems, we help organizations move beyond traditional operations and redesign how their businesses function through scalable, AI-powered solutions.
Our partners don’t come to us for experiments; they come to transform how their operations work.
We support startups, enterprises, and regulated organizations in building secure, reliable, and scalable digital systems.
Our security teams work closely with clients to deliver high-quality cybersecurity engagements across penetration testing, GRC, security assessments, and risk management.
About the Role
As a Lead Security Engineer at EhsanLab, you will provide technical leadership across client cybersecurity engagements, with a strong focus on penetration testing, vulnerability assessment, security assessments, and GRC-related security activities.
You will work closely with security consultants, technical teams, clients, and internal stakeholders to plan and execute security engagements, review technical outputs, manage complex security challenges, and ensure that delivered services meet EhsanLab’s technical and quality standards.
This role combines hands-on cybersecurity expertise, technical leadership, client engagement, security assessment, and knowledge transfer.
You will be expected to take ownership of technical outcomes, guide other security engineers, and communicate complex security risks clearly to both technical and non-technical stakeholders.
Key Responsibilities:
Security Engineering & Assessment
- Lead and execute security assessments, penetration tests, and vulnerability assessments across client environments.
- Perform security testing across web applications, APIs, networks, mobile applications, infrastructure, and other relevant systems.
- Identify, validate, and assess security vulnerabilities using both manual techniques and appropriate security tools.
- Conduct technical security reviews and help clients understand the practical impact of identified risks.
- Support GRC and security assessment activities where technical security expertise is required.
- Develop practical remediation recommendations based on identified vulnerabilities and risks.
Technical Leadership
- Provide technical direction and guidance to security engineers and consultants.
- Review technical findings, testing methodologies, evidence, and security reports before client delivery.
- Establish consistent technical approaches, testing standards, and documentation practices across engagements.
- Support complex security investigations and help teams resolve technical challenges.
- Mentor junior and mid-level security professionals through knowledge sharing and hands-on guidance.
- Promote secure-by-design principles across client engagements.
Client & Stakeholder Management
- Lead regular client meetings and communicate progress, risks, dependencies, commercial considerations, and required actions.
- Build strong relationships with technical, business, and executive stakeholders.
- Translate technical risks, compliance requirements, and delivery constraints into clear business communication.
- Ensure clients have the visibility required to make informed decisions.
Quality & Commercial Management
- Monitor engagement budgets, margins, resource utilization, and other agreed commercial performance indicators.
- Monitor delivery quality and ensure outputs pass appropriate internal review before client submission.
- Track milestones, margins, resource utilization, client feedback, rework, and unresolved risks.
- Conduct engagement retrospectives and turn lessons learned into improvements to templates, workflows, and delivery standards.
Required Qualifications:
- Relevant experience in cybersecurity services, GRC, penetration testing, technology consulting, project delivery, or a related field.
- Experience coordinating multiple client-facing technical engagements with competing deadlines and dependencies.
- Strong understanding of GRC principles, security controls, risk management, compliance assessments, audit processes, and evidence requirements.
- Working knowledge of penetration-testing engagements, including scoping, rules of engagement, delivery dependencies, quality review, and client reporting.
- Strong project and commercial-management capabilities, including planning, budgeting, forecasting, margin management, risk management, and change control.
- Experience managing, coordinating, or providing day-to-day leadership to technical delivery teams.
- Ability to contribute to hands-on security or GRC activities when required.
- Ability to communicate technical, compliance, commercial, and delivery matters to both technical and non-technical stakeholders.
- Experience working with security consultants, GRC specialists, project managers, sales teams, and client representatives.
- Confidence participating in client discovery, pre-sales, and service-expansion discussions. Strong written and spoken English.
- Sound judgment when handling confidential information and sensitive client matters.
Nice to Have:
- 5+ years of relevant cybersecurity, consulting, or technical-service delivery experience.
- Experience delivering GRC and penetration-testing services in consulting or managed-services environments.
- Familiarity with frameworks and standards such as ISO 27001, NIST CSF, PCI DSS, SAMA Cybersecurity Framework, or Central Bank of Egypt cybersecurity requirements.
- Project or service-management certification such as PMP, PRINCE2, ITIL, or Scrum.
What Makes This Role Unique
- Opportunity to lead real cybersecurity engagements across GRC and penetration testing.
- Exposure to clients across regulated industries and multiple markets.
- A role combining cybersecurity, delivery leadership, commercial management, and client engagement
- Direct interaction with security consultants, technical leaders, commercial teams, and client decision-makers.
- Fully remote working environment with client-site travel when required by the engagement.
How to Apply:
If you’re an experienced cybersecurity or technical-services professional who can own client engagements, lead delivery teams, and turn complex requirements into successful outcomes, we’d love to hear from you.
Please submit your resume using the application form below.
We value capability, ownership, and ambition, not just job titles or years of experience.
Deadline: Open until filled.
