About the Role
Managed Services is seeking a Penetration Tester to join their team in Riyadh. This full-time role involves conducting comprehensive security assessments, identifying and validating vulnerabilities, and providing practical remediation recommendations across various client environments. The ideal candidate will possess strong offensive-security skills and practical testing experience, coupled with the ability to prepare clear and professional technical reports.
Key Responsibilities
- Conduct penetration testing across web applications, APIs, networks, infrastructure, and cloud environments.
- Perform manual and automated vulnerability assessments.
- Safely exploit identified vulnerabilities to assess their technical and business impact.
- Test authentication, authorization, session management, and application logic.
- Participate in red-team and adversary-simulation activities when required.
- Conduct source-code security reviews and identify insecure coding practices.
- Document findings with supporting evidence, risk ratings, and remediation recommendations.
- Present and explain technical findings to clients and internal stakeholders.
- Conduct retesting to verify that vulnerabilities have been properly remediated.
- Stay updated on emerging vulnerabilities, exploitation techniques, and offensive-security tools.
Qualifications and Experience
- Bachelor’s degree in Cybersecurity, Computer Science, Information Security, or a related field.
- 2–3 years of practical experience in penetration testing or offensive security.
- Hands-on experience in web application and network penetration testing.
Technical Skills and Knowledge
- Strong knowledge of vulnerability assessment and exploitation techniques.
- Good understanding of network protocols, including TCP/IP, DNS, and HTTP.
- Strong working knowledge of Linux and Windows environments.
- Strong understanding of web technologies, APIs, authentication mechanisms, and the OWASP Top 10.
- Experience with tools such as Burp Suite, Metasploit, Nmap, Wireshark, and Nessus.
- Scripting skills in Python, Bash, PowerShell, Ruby, or a similar language.
- Strong technical-reporting and communication skills.
Preferred Qualifications
Candidates with the following experience or certifications will be at an advantage:
- Experience in cloud security assessments, red-team operations, source-code security reviews, or client-facing penetration-testing engagements.
- One or more of the following certifications: Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH), GIAC Penetration Tester (GPEN), Offensive Security Experienced Penetration Tester (OSEP), Certified Red Team Professional (CRTP), or Certified Red Team Operator (CRTO).
Work Environment
This is a full-time, on-site position based in Riyadh.
عن الدور
تبحث الخدمات المدارة عن مختبر اختراق للانضمام إلى فريقهم في الرياض. تتضمن هذه الوظيفة بدوام كامل إجراء تقييمات أمنية شاملة، وتحديد الثغرات والتحقق منها، وتقديم توصيات عملية للإصلاح عبر بيئات عمل العملاء المختلفة. سيملك المرشح المثالي مهارات أمن هجومي قوية وخبرة عملية في الاختبار، بالإضافة إلى القدرة على إعداد تقارير تقنية واضحة ومهنية.
المسؤوليات الأساسية
- إجراء اختبارات الاختراق عبر تطبيقات الويب وواجهات برمجة التطبيقات والشبكات والبنية التحتية وبيئات السحابة.
- إجراء تقييمات الثغرات يدويًا وآليًا.
- استغلال الثغرات المحددة بأمان لتقييم أثرها الفني والتجاري.
- اختبار المصادقة والتفويض وإدارة الجلسات ومنطق التطبيق.
- المشاركة في أنشطة فريق الرد السريع وروما/تمثيل العدو عند الحاجة.
- إجراء مراجعات أمان الكود المصدري وتحديد ممارسات الترميز غير الآمنة.
- توثيق النتائج مع الأدلة الداعمة وتقييم المخاطر وتوصيات الإصلاح.
- عرض النتائج الفنية وشرحها للعملاء وأصحاب المصلحة الداخليين.
- إجراء إعادة اختبار للتحقق من أن الثغرات تم إصلاحها بشكل صحيح.
- الاطلاع المستمر على الثغرات الناشئة وتقنيات الاستغلال وأدوات الأمن الهجومي.
المؤهلات والخبرة
- درجة البكالوريوس في الأمن السيبراني أو علوم الحاسوب أو أمن المعلومات أو مجال ذي صلة.
- 2–3 سنوات من الخبرة العملية في اختبار الاختراق أو الأمن الهجومي.
- خبرة عملية في اختبار اختراق تطبيقات الويب والشبكات.
المهارات التقنية والمعرفة
- معرفة قوية بتقييم الثغرات وتقنيات الاستغلال.
- فهم جيد لبروتوكولات الشبكة بما في ذلك TCP/IP وDNS وHTTP.
- معرفة عمل قوية بأنظمة Linux وWindows.
- فهم قوي لتقنيات الويب وواجهات برمجة التطبيقات وآليات المصادقة وOWASP Top 10.
- خبرة بالأدوات مثل Burp Suite وMetasploit وNmap وWireshark وNessus.
- مهارات البرمجة في Python أو Bash أو PowerShell أو Ruby أو لغة مشابهة.
- مهارات تقارير تقنية واتصالات قوية.
المؤهلات المفضلة
سيكون لمرشحون لديهم الخبرة أو الشهادات التالية ميزة:
- خبرة في تقييمات أمان السحابة، عمليات فريق الأمان الأحمر، مراجعات أمان الكود المصدري، أو مشاركات اختراق-واجهة العملاء.
- أحد الشهادات التالية أو أكثر: Offensive Security Certified Professional (OSCP)، Certified Ethical Hacker (CEH)، GIAC Penetration Tester (GPEN)، Offensive Security Experienced Penetration Tester (OSEP)، Certified Red Team Professional (CRTP)، أو Certified Red Team Operator (CRTO).
بيئة العمل
هذه وظيفة بدوام كامل موجودة في الرياض.