Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
Secure Maximum Company in Saudi Arabia seeks a senior security tester with at least 8 years in penetration testing and application security, preferably within banking/financial sectors. You will lead full penetration testing lifecycle, assess digital RFCs, and provide risk-based remediation guidance across web, mobile and API platforms.
Collaborating with project teams, developers and change management, you will review RFCs, perform validation and re-testing to support secure deployments and
Minimum 8 years of dedicated hands‑on experience in Penetration Testing and Application Security The resource must have spent the last 4 years performing penetration testing activities within the Banking and Financial sectors industry Proven experience in supporting and assessing Digital RFCs including internet banking mobile banking APIs digital channels payment systems and customer-facing applications Experience managing the full penetration testing lifecycle including planning execution reporting remediation validation and re-testing Experience working closely with project teams developers system owners and change management processes to support RFC security reviews and approvals Ability to handle multiple Digital RFC assessments concurrently and provide timely risk-based recommendations
Strong knowledge of OWASP Top 10 (Open Worldwide Application Security Project Top 10).Strong knowledge of OWASP API Security Top 10 (Open Worldwide Application Security Project API Security Top 10). Strong knowledge of MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework. Strong knowledge of CWE (Common Weakness Enumeration). Strong understanding of SSDLC (Secure Software Development Lifecycle). Experience assessing applications and digital platforms against SAMA regulatory requirements and banking security best practices. Extensive experience assessing digital banking platforms, financial applications, and payment-related systems. Ability to perform risk assessments and provide practical security recommendations to support Digital RFC approval decisions.