Penetration Testing Resource Capabilities Required

Secure Maximum Company

Riyadh

On-site

SAR 300,000 - 480,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Secure Maximum Company in Saudi Arabia seeks a senior security tester with at least 8 years in penetration testing and application security, preferably within banking/financial sectors. You will lead full penetration testing lifecycle, assess digital RFCs, and provide risk-based remediation guidance across web, mobile and API platforms.

Collaborating with project teams, developers and change management, you will review RFCs, perform validation and re-testing to support secure deployments and

Qualifications

  • Minimum 8 years hands-on pentesting and application security work.
  • Last 4 years focused on banking/financial sector projects.
  • Experience with digital RFCs, internet/mobile banking APIs and digital channels.
  • Ability to manage full pentest lifecycle from planning to re-testing.

Responsibilities

  • Lead end-to-end penetration testing lifecycle across web, mobile and API platforms.
  • Assess RFCs and perform risk-based security recommendations.
  • Collaborate with project teams, developers and change management.
  • Validate remediation and perform re-testing to close findings.

Skills

Penetration testing
Application security
RFC security reviews
Risk-based recommendations
Project collaboration
Threat modelling
Remediation verification
Banking sector experience

Tools

SAST
DAST
OWASP Top 10
MITRE ATT&CK
CWE
SSDLC

Job description

Minimum 8 years of dedicated hands‑on experience in Penetration Testing and Application Security The resource must have spent the last 4 years performing penetration testing activities within the Banking and Financial sectors industry Proven experience in supporting and assessing Digital RFCs including internet banking mobile banking APIs digital channels payment systems and customer-facing applications Experience managing the full penetration testing lifecycle including planning execution reporting remediation validation and re-testing Experience working closely with project teams developers system owners and change management processes to support RFC security reviews and approvals Ability to handle multiple Digital RFC assessments concurrently and provide timely risk-based recommendations

strong Technical Capabilities strong
  • Web Application Penetration Testing
  • Mobile Application Security Testing
  • iOS
  • Android
  • API Security Testing
  • Network Penetration Testing
  • Internal
  • External
  • Authentication and Access Control Assessments
  • Vulnerability Assessment and Validation
  • Secure Configuration Reviews
  • Source Code Security Review
  • SAST
  • Dynamic Application Security Testing
  • DAST
  • Manual Exploitation and Attack Simulation
  • Security Architecture and Design Reviews
  • Threat Modeling and Attack Surface Analysis
  • Remediation Verification and Retesting

Strong knowledge of OWASP Top 10 (Open Worldwide Application Security Project Top 10).Strong knowledge of OWASP API Security Top 10 (Open Worldwide Application Security Project API Security Top 10). Strong knowledge of MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework. Strong knowledge of CWE (Common Weakness Enumeration). Strong understanding of SSDLC (Secure Software Development Lifecycle). Experience assessing applications and digital platforms against SAMA regulatory requirements and banking security best practices. Extensive experience assessing digital banking platforms, financial applications, and payment-related systems. Ability to perform risk assessments and provide practical security recommendations to support Digital RFC approval decisions.

Certifications (Preferred):
  • OSCP – Offensive Security Certified Professional
  • OSWE – Offensive Security Web Expert
  • OSEP – Offensive Security Experienced Penetration Tester
  • GPEN – GIAC Penetration Tester
  • GWAPT – GIAC Web Application Penetration Tester
  • GMOB – GIAC Mobile Device Security Analyst
  • CEH – Certified Ethical Hacker
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

Managed • Riyadh

On-site
SAR 130,000 - 230,000
Penetration Tester
Penetration Tester

Managed Services • Riyadh

On-site
SAR 120,000 - 180,000
Senior Offensive Security Consultant – FortiGuard Proactive Services
Senior Offensive Security Consultant – FortiGuard Proactive Services

Fortinet, Inc. • Riyad Al Khabra

On-site
SAR 299,000 - 450,000
Senior Penetration Tester - Banking & App Security
Senior Penetration Tester - Banking & App Security

Secure Maximum Company • Riyadh

On-site
SAR 300,000 - 480,000
Cyber Security Engineer (Offensive Security)
Cyber Security Engineer (Offensive Security)

Catalyic Security • Saudi Arabia

On-site
SAR 50,000 - 70,000
Penetration Tester — Web, API & Cloud Security
Penetration Tester — Web, API & Cloud Security

Managed • Riyadh

On-site
SAR 130,000 - 230,000
Senior Offensive Security Consultant - FortiGuard Proactive Services
Senior Offensive Security Consultant - FortiGuard Proactive Services

Zoomcar • Riyadh

On-site
SAR 168,000 - 244,000
Cybersecurity Assurance Specialist
Cybersecurity Assurance Specialist

Cloud Consultancy - CCDS • Riyadh

On-site
SAR 180,000 - 300,000
Cybersecurity Assurance Specialist
Cybersecurity Assurance Specialist

CCDS • Riyadh

On-site
SAR 240,000 - 480,000
Purple Teaming Engineer - Embedded Security
Purple Teaming Engineer - Embedded Security

Lucid Motors • Riyadh

On-site
SAR 200,000 - 250,000