About the Role
Nozom is seeking a Senior Penetration Tester to join its team in Riyadh, Saudi Arabia. This full-time position requires extensive hands-on experience in penetration testing and Red Team operations. The role involves leading advanced security assessments and attack simulations across a wide range of technical environments.
Role Summary
The Senior Penetration Tester will be responsible for identifying, exploiting, and documenting complex security vulnerabilities through comprehensive security assessments and adversary simulation exercises. This position demands a proactive approach to evaluating security postures and providing actionable recommendations to enhance organizational security.
Key Responsibilities
- Lead internal and external network penetration testing engagements.
- Conduct advanced Red Team and adversary simulation exercises based on defined tactics, techniques, and procedures (TTPs).
- Identify, exploit, validate, and thoroughly document complex security vulnerabilities.
- Perform secure code reviews to identify authentication flaws, hardcoded credentials, and insecure logic.
- Evaluate Active Directory attack paths, cloud attack vectors, and privilege escalation risks.
Assessment Domains
The scope of assessments will cover various critical areas, including:
- Networks (internal and external)
- Applications
- Endpoints and general infrastructure
- Wireless environments and internet-connected devices
- Cloud platforms, specifically AWS, Azure, GCP, and Oracle
Required Experience and Professional Conduct
Candidates should possess 5 to 10 years of experience in information security, with a focus on penetration testing and Red Team operations. Beyond technical skills, the role requires strong communication and leadership abilities:
- Prepare executive and technical reports with clear remediation recommendations.
- Present findings to clients and stakeholders effectively.
- Support remediation validation efforts.
- Mentor junior consultants, contributing to team development.
Work Environment
This is a full-time position located in Riyadh, Saudi Arabia, within Nozom's information security team. The role offers an opportunity to work on challenging security projects.
عن الدور
تبحث Nozom عن مختبر اختراق أول للانضمام إلى فريقها في الرياض، المملكة العربية السعودية. يتطلب هذا المنصب بدوام كامل خبرة عملية واسعة في اختبارات الاختراق وعمليات فريق Red. يتضمن الدور قيادة تقييمات أمنيّة متقدمة ومحاكاة هجمات عبر مجموعة واسعة من البيئات التقنية.
الملخص الوظيفي
سيكون مختبر الاختراق الأول مسؤولاً عن تحديد الثغرات الأمنية المعقدة واستغلالها وتوثيقها من خلال تقييمات أمنيّة شاملة وتمارين محاكاة للخصوم. يتطلب هذا المنصب نهجاً استباقياً لتقييم وضعية الأمن وتقديم توصيات قابلة للتنفيذ لتعزيز أمان المؤسسة.
المسوؤليات الرئيسية
- قيادة أعمال اختبارات اختراق الشبكات الداخلية والخارجية.
- إجراء تمارين متقدمة لفريق Red ومحاكاة خصوم بناءً على التكتيكات والتقنيات والإجراءات (TTPs) المحددة.
- تحديد واستغلال والتحقق من صحة وتوثيق الثغرات الأمنية المعقدة بشكل دقيق.
- إجراء مراجعات آمنة للكود لتحديد عيوب المصادقة والاعتماد على بيانات مُشفرة وصيغ منطق غير آمنة.
- تقييم مسارات هجوم Active Directory، وواجهات الهجوم السحابية، ومخاطر التصعيد الامتيازي.
مجالات التقييم
سيشمل نطاق التقييمات مجالات حاسمة متعددة، بما في ذلك:
- الشبكات (داخليّة وخارجية)
- التطبيقات
- نقاط النهاية والبنية التحتية العامة
- البيئات اللاسلكية والأجهزة المتصلة بالإنترنت
- منصات السحابة، وتحديداً AWS وAzure وGCP وOracle
الخبرة المطلوبة والسلوك المهني
على المرشحين أن يكون لديهم خبرة من 5 إلى 10 سنوات في أمن المعلومات، مع تركيز على اختبارات الاختراق وعمليات Red. بجانب المهارات التقنية، يتطلب الدور قدرات اتصال وقيادة قوية:
- إعداد تقارير تنفيذية وتقنية مع توصيات تصحيح واضحة.
- عرض النتائج للعملاء وأصحاب المصلحة بفعالية.
- دعم جهود التحقق من الإصلاحات.
- توجيه المستشارين المبتدئين، والمساهمة في تطوير الفريق.
بيئة العمل
هذا المنصب بدوام كامل ومقره في الرياض، المملكة العربية السعودية، ضمن فريق أمن المعلومات في Nozom. يوفر الدور فرصة للعمل على مشاريع أمنية وتحدياتها.