ملخص الدور: نحن نبحث عن استشاريين ذوي خبرة للانضمام إلى فريق S&P لدينا في Protiviti. سيتضمن الدور بشكل أساسي تنفيذ وإدارة ارتباطات متنوعة مع العملاء. على الرغم من أن مقر الدور في دول مجلس التعاون الخليجي، فقد يسافر الموظفون عبر مواقع مختلفة للعملاء في الشرق الأوسط، وما إلى ذلك.
سيكون المتقدم الناجح مسؤولاً عن تقييم الوضع الأمني لأنظمة ومنصات وعمليات العملاء لحماية وتحسين سرية وسلامة وتوافر أنظمة المعلومات بشكل مستمر وفقاً لأهداف العمل والمتطلبات التنظيمية والأهداف الاستراتيجية للعميل.
المسؤوليات: تقديم الابتكار في سياق برنامج اختبار الثغرات والاختراق (VAPT) فيما يتعلق بكل من العملية والتكنولوجيا. العمل كخبير متخصص (SME) لوظيفة الهجوم والاختراق. إجراء مراجعات سطح الهجوم المصرح بها، واختبارات الاختراق، وتقييمات الفريق الأحمر ضد أهداف محددة. تقديم تقارير تقييم سهلة الفهم للجمهور المستهدف وتتضمن توصيات عملية ومعقولة بناءً على مبادئ سليمة لإدارة المخاطر. تحديث المعايير والإجراءات المصممة لتحسين الوضع الأمني باستمرار. تقييم كفاية السياسات والمعايير والإجراءات المتعلقة بأفضل الممارسات الأمنية. المساهمة في مستودعات المعلومات المتعلقة بالأمن ومساعي تطوير الأعمال الأخرى. توجيه أعضاء الفريق المبتدئين وتقديم استشارات بناءة لمجموعات الأقران الأخرى.
متطلبات الخلفية: درجة البكالوريوس في علوم الكمبيوتر أو ما يعادلها بشكل جوهري. من 4 إلى 6 سنوات من الخبرة المهنية في أمن المعلومات مع التركيز على التقييمات الفنية. معرفة قيادية بمفاهيم اختبار الاختراق وأفضل الممارسات. خبرة واسعة في أدوات اختبار الاختراق الشائعة مثل Nessus وAppscan وBurp Suite وNipper وExploit Pack وما إلى ذلك. إتقان أدوات وأطر الهجوم الشائعة الأخرى مثل Wireshark وKali وMetasploit وما إلى ذلك. القدرة على التحقق من وجود الثغرات المحددة بدقة. إتقان منصات وتقنيات التطبيقات الشائعة لفهم وتقييم تقييمات التطبيقات المعقدة بفعالية من خلال استخدام التقنيات اليدوية والأدوات البسيطة مثل الوكلاء (proxies) وإضافات المتصفح. فهم متعمق لـ OWASP وCVE وضوابط الأمان العامة والمواضيع الأساسية الأخرى مثل أحدث ثغرات التطبيقات وأنظمة التشغيل. معرفة لغات البرمجة والبرمجة النصية الشائعة مثل Python وShell script وما إلى ذلك. يفضل الحصول على شهادات GIAC GPEN أو GWAPT أو CREST أو OSCE.
المهارات الشخصية: القدرة على الحفاظ على التفكير النقدي والهدوء تحت الضغط. مهارات تواصل كتابية وشفوية قوية باللغة الإنجليزية. القدرة على نقل المفاهيم المعقدة إلى جمهور الأعمال. القدرة على أن تكون منتجاً والحفاظ على التركيز بأقل قدر من الإشراف. فهم VAPT في سياق إدارة المخاطر والأولويات التنظيمية.
Role Summary We are looking for experienced consultants to join our S&P team at Protiviti. The role will primarily involve executing and managing diverse client engagements. While the role is based in GCC resources may travel across various client locations in the Middle East, etc.
The successful applicant will be responsible for assessing the security posture of client systems, platforms, and processes to protect and continually improve the confidentiality, integrity, and availability of information systems in accordance with the client's business objectives, regulatory requirements, and strategic goals.
Responsibilities Provide innovation within the context of the Vulnerability and Penetration Testing (VAPT) program in relation to both process and technology. Serve as a Subject Matter Expert (SME) for the Attack & Pen function. Perform authorized attack surface reviews, penetration tests, and red team assessments against specific targets. Provide assessment reports that are easily understandable by the target audience and include practical and reasonable recommendations based on sound risk management principles. Update standards and procedures designed to continually improve security posture Assess the sufficiency of policies, standards, and procedures relative to security best practices. Contribute to the security-related information repositories and other business development endeavors. Mentor junior members of the team and provide constructive consultation to other peer groups.
Background Requirements Computer Science Bachelor’s Degree or substantial equivalent.4 to 6 years of professional experience in information security with a focus on technical assessments. Commanding knowledge of pen testing concepts and best practices. Extensive experience with common Pentesting tools such as Nessus, Appscan, Burp Suite, Nipper, Exploit Pack etc. Proficiency with other common attack tools and frameworks such as Wireshark, Kali, and Metasploit, etc. Ability to validate the presence of identified vulnerabilities with accuracy. Mastery of common application platforms and technologies to effectively understand and evaluate complex application assessments via the use of manual techniques and simple tools such as proxies and browser plugins. In-depth understanding of OWASP, CVE general security controls, and other foundational topics such as the latest application and operating system exploits. Knowledge of common scripting and programming languages like python, shell script etc. GIAC GPEN, GWAPT, CREST or OSCE preferred.
Personal Skills:Ability to maintain critical thinking and composure under pressure. Strong written and oral communication skills in English. Ability to convey complex concepts to business audience. Ability to be productive and maintain focus with minimal supervision. Understands VAPT in the context of risk management and organizational priorities.