Location: On-site – Riyadh, Saudi Arabia
Contract/engagement: Project-based managed cybersecurity services (13-month)
Minimum experience: 7+ years
Role Purpose
Provide technical cybersecurity assurance through penetration testing, vulnerability validation, remediation verification, and risk-based reporting.
Key Responsibilities
- Plan and execute authorized penetration tests across in-scope networks, applications, systems, and cloud environments.
- Perform reconnaissance, attack-surface analysis, vulnerability discovery, safe exploitation, privilege escalation, and lateral-movement testing.
- Simulate realistic attack scenarios while following approved rules of engagement and protecting service availability and data.
- Assess findings based on technical severity, exploitability, and business impact.
- Prepare clear technical reports and executive summaries with practical remediation guidance.
- Present findings and recommendations to technical owners and business stakeholders.
- Conduct retesting to confirm remediation effectiveness and track closure of findings.
- Monitor vulnerability trends and contribute to continuous improvement of security-assurance processes.
Technical and Professional Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- At least 7 years of experience in penetration testing, cybersecurity assurance, or ethical hacking.
- Strong understanding of network, web/application, infrastructure, and cloud attack surfaces.
- Hands-on capability in exploitation, privilege escalation, lateral movement, and remediation validation.
- Knowledge of OWASP testing methodologies, industry testing standards, vulnerability-rating practices, and MITRE ATT&CK.
- Strong technical and executive reporting capability.
Personal Requirements
- Ethical, discreet, and disciplined in handling sensitive systems and findings.
- Strong analytical curiosity and methodical testing habits.
- Able to explain complex weaknesses and business impact in clear language.
- Collaborative and constructive when working with system owners on remediation.
Professional Certifications
Preferred: OSCP, OSEP, CEH, or equivalent.