Enable job alerts via email!

Senior Information Security Consultant – Immediate

Securseed

Saudi Arabia

On-site

SAR 200,000 - 300,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a skilled security expert to enhance the security posture of client applications and information assets. This role involves rigorous testing and auditing against international standards, ensuring vulnerabilities are identified and remediated effectively. The ideal candidate will have extensive experience in web and mobile application security, as well as a strong background in vulnerability assessment and penetration testing. Join a dynamic team that values innovation and collaboration, where your expertise will directly impact the security landscape and contribute to the success of diverse consulting engagements across the Middle East.

Qualifications

  • 5+ years in web and mobile app security, vulnerability assessment, and penetration testing.
  • Certifications like OSCP or OSWE are essential for this role.

Responsibilities

  • Conduct security testing of web applications, APIs, and mobile apps.
  • Document vulnerabilities and provide remediation guidance.

Skills

Web Application Security
Mobile Application Security
Network Security
Cloud Infrastructure Security
Vulnerability Assessment
Penetration Testing
Threat Hunting
DevSecOps

Education

Security Certifications (OSCP, OSWE)

Tools

Automated Security Testing Tools
Code Review Tools

Job description

Job description

The candidate is responsible for establishing, implementing, monitoring, reviewing, and improving all suitable sets of controls for the prevention of threats to the security of client applications & information assets, ensuring the business objectives of the organization. Should rigorously test, scan, audit & re-test all scopes as per all international security standards like OWASP, SANS & others.

Responsibilities and Scope:

  • 5+ years of experience in web application and mobile application security, Network & Cloud Infrastructure Security, Vulnerability Assessment & Penetration Testing.
  • Exploit security flaws & vulnerabilities with attack simulations on multiple applications in the Android and IOS platforms.
  • Provide remediation guidance to identified vulnerabilities.
  • Manual and automated security testing of Web applications, APIs, and mobile Apps.
  • Use automated & manual code review techniques to identify application security vulnerabilities.
  • Identify complex vulnerabilities such as business logic flaws and articulate to both technical and non-technical partners.
  • Document & report vulnerabilities and work on periodic vulnerability mitigations, patching.
  • Analyze application security policies for effectiveness, make suggestions on security policy improvements, and work to enhance methodology material.
  • Develop & maintain security testing plans and automate penetration and other security testing on the applications, systems, networks, and data layers.
  • Develop meaningful metrics to reflect the true posture of the environment allowing the organization to make decisions based on potential security threats & risks.
  • Produce actionable, threat-based reports on security testing results.
  • Build and maintain relationships with key stakeholders and security partners.

Must-Have:

  • Team player with good interpersonal skills, able to work independently with minimum supervision in a complex Infrastructure environment.
  • Certifications: OSCP, OSWE or any other security certifications.
  • Self-driven, self-managed technical team leader.
  • Ability to clearly communicate needs and requirements and influence stakeholders with minimal supervision.
  • Ability to accurately estimate effort, set and meet periodic delivery deadlines.
  • Experience in research and development in Red Team Exercises, Threat Hunting, OSINT, Threat Modelling & building security tools is a plus.
  • Good understanding of DevSecOps, security architecture review and network security assessments is an added advantage.
  • Hands-on experience with technology to contribute to the design, development, and support of projects with security recommendations.

Nice to Have:

  • Good problem-solving skills, communication and documentation skills.
  • Ability to anticipate needs and provide creative input that ensures the success of the broader team.
  • Proficient in reading modern programming languages with the ability to quickly learn to read and interpret scripts written by others.
  • Ability to lead & drive multiple projects simultaneously.

No of Positions: 4

Note: The candidate would be expected to work in diverse consulting engagements and be willing to travel to Middle East countries for project execution at least 50% of their time.

Preference to candidates who can join immediately or within 15 days at the max.

Employment Type: Full-time

Industry
  • Information Technology & Services
Employment Type

Full-time

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.