M
Penetration Tester
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 2–3 yrs
- Salary
- —
- Openings
- 1
- Posted
- 2時間前
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Job description
Overview
Managed.sa is hiring a skilled Penetration Tester to perform comprehensive security evaluations, uncover vulnerabilities, and offer actionable remediation advice across various client environments.
Key Duties
- Carry out penetration tests on web applications, APIs, networks, infrastructure, and cloud systems.
- Utilize both manual and automated methods for vulnerability analysis.
- Safely exploit found weaknesses to determine their technical and business implications.
- Examine authentication, authorization, session strategies, and application logic for security flaws.
- Engage in red-team exercises and adversary simulation as needed.
- Analyze source code to detect insecure programming practices.
- Report findings with evidence, risk classification, and recommendations for fixes.
- Communicate technical results clearly to clients and internal teams.
- Conduct retesting to confirm corrective measures effectively address vulnerabilities.
- Keep abreast of newly discovered vulnerabilities, exploitation tactics, and offensive security tools.
Candidate Profile
- A Bachelor's degree in Cybersecurity, Computer Science, Information Security, or related disciplines is required.
- 2 to 3 years of hands-on experience in penetration testing or offensive security roles.
- Practical expertise in testing web applications and networks.
- A strong grasp of vulnerability identification and exploitation techniques.
- Good understanding of networking protocols such as TCP/IP, DNS, and HTTP.
- Proficiency in both Linux and Windows environments.
- In-depth knowledge of web technologies, APIs, authentication systems, and familiarity with the OWASP Top 10 vulnerabilities.
- Experience using tools like Burp Suite, Metasploit, Nmap, Wireshark, Nessus.
- Programming/scripting abilities in Python, Bash, PowerShell, Ruby, or comparable languages.
- Excellent skills in technical report writing and verbal communication.
- Willingness and ability to work full-time at the Riyadh location.
Preferred Qualifications and Experience
- Experience performing cloud security assessments.
- Participation in red-team operations.
- Competence in source-code security analysis.
- Client-facing experience in penetration testing engagements.
Certifications (Advantageous)
- Offensive Security Certified Professional (OSCP)
- Certified Ethical Hacker (CEH)
- GIAC Penetration Tester (GPEN)
- Offensive Security Experienced Penetration Tester (OSEP)
- Certified Red Team Professional (CRTP)
- Certified Red Team Operator (CRTO)