Job Summary We are seeking an experienced Vulnerability Assessment & Penetration Testing (VAPT) Specialist to assess the security posture of the organization’s systems, networks, web applications, and physical infrastructure. The role is responsible for identifying and validating vulnerabilities, conducting authorized penetration testing, evaluating the effectiveness of layered security controls, and providing actionable recommendations to mitigate identified risks. Key Responsibilities Conduct Vulnerability Assessment and Penetration Testing (VAPT) across systems, networks, applications, web applications, and infrastructure. Perform vulnerability scanning across technology assets and identify deviations from approved security configurations, policies, standards, and baselines. Conduct authorized penetration tests using realistic attack techniques and scenarios to identify exploitable vulnerabilities and assess the organization’s security posture. Perform security testing of systems, networks, web applications, and physical facilities in accordance with approved testing procedures and scope. Assess the effectiveness of defense-in-depth and layered security controls against known vulnerabilities and realistic attack scenarios. Conduct web application security testing using appropriate penetration testing methodologies and tools. Perform source code reviews and security testing using static and dynamic application security testing tools where applicable. Identify, validate, and prioritize vulnerabilities based on their technical severity, exploitability, and potential business impact. Prepare comprehensive VAPT and vulnerability assessment reports, including risk ratings, technical findings, remediation recommendations, evidence, and sufficient technical details to reproduce the findings. Discuss and present VAPT findings with management, cybersecurity teams, IT teams, application owners, and other relevant stakeholders. Provide practical remediation recommendations and support technical teams in validating vulnerability remediation. Design, develop, and continuously improve VAPT processes, methodologies, procedures, and testing scenarios. Required Qualifications Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field. Minimum of 4–6 years of experience in Vulnerability Assessment, Penetration Testing, VAPT, or a related cybersecurity discipline. Strong hands-on experience in Vulnerability Assessment and Penetration Testing (VAPT). Experience conducting penetration testing across network, infrastructure, system, and web application environments.
ملخص الوظيفة: نحن نبحث عن متخصص ذو خبرة في تقييم الثغرات واختبار الاختراق (VAPT) لتقييم الوضع الأمني لأنظمة المؤسسة وشبكاتها وتطبيقات الويب والبنية التحتية المادية. هذا الدور مسؤول عن تحديد الثغرات والتحقق منها، وإجراء اختبارات الاختراق المعتمدة، وتقييم فعالية ضوابط الأمن متعددة الطبقات، وتقديم توصيات عملية للتخفيف من المخاطر المحددة. المسؤوليات الرئيسية: إجراء تقييم الثغرات واختبار الاختراق (VAPT) عبر الأنظمة والشبكات والتطبيقات وتطبيقات الويب والبنية التحتية. إجراء فحص الثغرات الأمنية عبر الأصول التكنولوجية وتحديد الانحرافات عن التكوينات والسياسات والمعايير الأمنية المعتمدة. إجراء اختبارات اختراق معتمدة باستخدام تقنيات وسيناريوهات هجوم واقعية لتحديد الثغرات القابلة للاستغلال وتقييم الوضع الأمني للمؤسسة. إجراء اختبارات أمنية للأنظمة والشبكات وتطبيقات الويب والمرافق المادية وفقاً لإجراءات ونطاق الاختبار المعتمد. تقييم فعالية ضوابط الدفاع المتعمق والأمن متعدد الطبقات ضد الثغرات المعروفة وسيناريوهات الهجوم الواقعية. إجراء اختبار أمن تطبيقات الويب باستخدام منهجيات وأدوات اختبار الاختراق المناسبة. إجراء مراجعات للكود المصدري واختبارات أمنية باستخدام أدوات اختبار أمن التطبيقات الثابتة والديناميكية حيثما ينطبق ذلك. تحديد الثغرات والتحقق منها وتحديد أولوياتها بناءً على خطورتها التقنية وقابليتها للاستغلال والأثر التجاري المحتمل. إعداد تقارير شاملة عن (VAPT) وتقييم الثغرات، بما في ذلك تصنيفات المخاطر والنتائج التقنية وتوصيات المعالجة والأدلة والتفاصيل التقنية الكافية لإعادة إنتاج النتائج. مناقشة وعرض نتائج (VAPT) مع الإدارة وفرق الأمن السيبراني وفرق تكنولوجيا المعلومات ومالكي التطبيقات وأصحاب المصلحة الآخرين ذوي الصلة. تقديم توصيات معالجة عملية ودعم الفرق التقنية في التحقق من معالجة الثغرات. تصميم وتطوير وتحسين عمليات ومنهجيات وإجراءات وسيناريوهات اختبار (VAPT) بشكل مستمر. المؤهلات المطلوبة: درجة البكالوريوس في الأمن السيبراني، أو أمن المعلومات، أو علوم الحاسب، أو تكنولوجيا المعلومات، أو مجال ذي صلة. خبرة لا تقل عن 4-6 سنوات في تقييم الثغرات، أو اختبار الاختراق، أو (VAPT)، أو تخصص أمني سيبراني ذي صلة. خبرة عملية قوية في تقييم الثغرات واختبار الاختراق (VAPT). خبرة في إجراء اختبارات الاختراق عبر بيئات الشبكة والبنية التحتية والأنظمة وتطبيقات الويب.