Cipher | سايڤر is a cybersecurity solutions provider based in Riyadh, Saudi Arabia. The company's goal is to simplify the perception of complexity surrounding cybersecurity problems and solutions. Cipher's team of Saudi professionals and experts work tirelessly to develop, customize, and manage digital services and cybersecurity solutions to ensure their peace of mind. Our goal is to provide peace of mind to our clients by making digital security simple and efficient.
Key Responsibilities:
• Define scope and objectives of penetration tests with clients across systems, applications, and environments.• Perform manual penetration testing on web, mobile, APIs, cloud, and enterprise infrastructure.• Conduct advanced assessments including source code reviews, business logic testing, and red team simulations.• Simulate real-world attacks to evaluate detection and response capabilities.• Identify vulnerabilities, misconfigurations, and security gaps (onsite & remote).• Deliver clear, actionable technical reports with risk and business impact analysis.• Present findings to both technical teams and executive stakeholders.• Provide strategic recommendations to enhance security posture and reduce attack surface.• Stay up to date with emerging threats and frameworks (OWASP, MITRE ATT&CK).
Requirements:
• Minimum 2+ years of hands-on experience** in penetration testing and cybersecurity.• Bachelor’s degree in computer science, Cybersecurity, IT, or related field.• Certifications such as **OSCP, e WPTX, CRTP** (or equivalent) are highly preferred.• Strong experience across web, mobile, cloud, and infrastructure security testing.• Solid skills in manual vulnerability discovery, code review, and adversary simulation.• Proficiency in scripting (Python, Power Shell, Bash).• Strong analytical, problem-solving, and communication skills.• Ability to translate technical findings into business risks and recommendations.
Cipher | سايڤر هي مزود لحلول الأمن السيبراني مقرها الرياض، المملكة العربية السعودية. تهدف الشركة إلى تبسيط مفهوم التعقيد المحيط بمشاكل وحلول الأمن السيبراني. يعمل فريق سايڤر من المحترفين والخبراء السعوديين بلا كلل لتطوير وتخصيص وإدارة الخدمات الرقمية وحلول الأمن السيبراني لضمان راحة بال عملائهم. هدفنا هو توفير راحة البال لعملائنا من خلال جعل الأمن الرقمي بسيطاً وفعالاً.
المسؤوليات الرئيسية:
• تحديد نطاق وأهداف اختبارات الاختراق مع العملاء عبر الأنظمة والتطبيقات والبيئات. • إجراء اختبارات اختراق يدوية على الويب، وتطبيقات الهاتف، وواجهات برمجة التطبيقات (APIs)، والسحابة، والبنية التحتية للمؤسسات. • إجراء تقييمات متقدمة تشمل مراجعة الكود المصدري، واختبار منطق الأعمال، ومحاكاة الفريق الأحمر (Red Team). • محاكاة هجمات واقعية لتقييم قدرات الكشف والاستجابة. • تحديد الثغرات، والتكوينات الخاطئة، والفجوات الأمنية (في الموقع وعن بُعد). • تقديم تقارير فنية واضحة وقابلة للتنفيذ مع تحليل المخاطر وتأثير الأعمال. • عرض النتائج على كل من الفرق الفنية وأصحاب المصلحة التنفيذيين. • تقديم توصيات استراتيجية لتعزيز الوضع الأمني وتقليل مساحة الهجوم. • البقاء على اطلاع بأحدث التهديدات والأطر الأمنية (OWASP, MITRE ATT&CK).
المتطلبات:
• خبرة عملية لا تقل عن سنتين** في اختبار الاختراق والأمن السيبراني. • درجة البكالوريوس في علوم الحاسب، أو الأمن السيبراني، أو تكنولوجيا المعلومات، أو مجال ذي صلة. • يفضل بشدة الحصول على شهادات مثل **OSCP, eWPTX, CRTP** (أو ما يعادلها). • خبرة قوية في اختبار أمن الويب، والهاتف، والسحابة، والبنية التحتية. • مهارات قوية في اكتشاف الثغرات يدوياً، ومراجعة الكود، ومحاكاة الخصوم. • إتقان البرمجة النصية (Python, PowerShell, Bash). • مهارات قوية في التحليل وحل المشكلات والتواصل. • القدرة على ترجمة النتائج الفنية إلى مخاطر وتوصيات تجارية.