Penetration Testing Consultant

دوام كامل في CyberSec Consulting في Saudi Arabia
نُشرت يوم February 7, 2025

تفاصيل الوظيفة

CYBERSEC CONSULTING is a professional Cyber Security and Consulting services company headquartered in UAE to cover the India, Middle East, Africa and Levant market. We are a global provider of Cyber Security Professional Services, Remote Support, Certified Trainings, Outsourcing, Assessment and Consulting Services, as well as solutions for Security Operations Center (SOC) and Managed Security Services (MSS). Our firm focuses on end-to-end Cyber Security services, with professional Consultants specialized in the respective security domain and experience in handling medium to sophisticated service and consulting delivery engagements. The Role You Will Be Responsible For:

  • Conducting penetration testing, simulating an attack on the system to find exploitable weaknesses.
  • Developing and implementing security framework, policies, processes/procedures, and guidelines.
  • Maintaining security subject-matter expertise and keeping abreast of best practices & trends.
  • Managing vulnerability assessments.
  • Oversight & resolution of security incidents.
  • Designing, maintaining, and supporting the network infrastructure.
  • Monitoring system performance and ensuring reliability and availability.
  • Recommending infrastructure solutions to meet business requirements in compliance with IT policy & procedure.
  • Providing Level 2 support and troubleshooting as needed.
Ideal Profile:
  • You possess a Degree/Diploma in Computer Science, Engineering, or a related field.
  • Experience in the range of 2-3 years.
  • Hands-on experience with testing frameworks in line with Web App, Mobile, Web Services/APIs, and Network.
  • Experience with Open Web Application Security Project (OWASP) and Open Source Security Testing Methodology Manual (OSSTMM) methodologies and tools.
  • Work closely with application, network, and infrastructure teams when performing tests against new or existing systems.
  • Use manual techniques to exploit identified vulnerabilities like cross-site scripting, SQL injections, session hijacking, and buffer overflows.
  • Validate vulnerability assessment results, prioritize remediation requirements, and work with teams to address security problems.
  • Perform exploit analysis for identified vulnerabilities manually or with tools such as Metasploit.
  • Collaborate with application development and technology teams to identify and remediate security issues as part of Incident Response.
  • Participate in the SDLC process for testing new application systems/infrastructure.
  • Engage in multiple organizational areas such as security architecture and design, service delivery, training, and client communication.
  • Configure and educate on the use of vulnerability assessment scanners (e.g., Qualys, Nessus, Nmap, Metasploit, Snort, Nexpose).
  • Create, maintain, and report metrics that measure the effectiveness of various security controls.
  • Document significant exposure areas to information systems and recommend solutions.
  • Develop and maintain a formal reporting process highlighting results, conclusions, and recommendations.
  • Articulate risks and findings to management effectively.
  • Experience in preparing a security threat model and associated test plans.
  • Translate complex security threats into simpler procedures for web application developers and management.
  • Knowledge of current information security threats and coding best practices.
  • In-depth knowledge of application development processes and at least one programming or scripting language (e.g., Java, Scala, C#, Ruby, Perl, Python, PowerShell) is preferred.
  • Excellent communication skills, both written and verbal.
  • Critical thinking and good problem-solving abilities.
  • Organizational skills in planning and time management are preferred.
  • Certification on CEH (Certified Ethical Hacker) or OSCP (Offensive Security Certified Professional) is desirable.
What's on Offer?#J-18808-Ljbffr

Apply safely

To stay safe in your job search, information on common scams and to get free expert advice, we recommend that you visit SAFERjobs, a non-profit, joint industry and law enforcement organization working to combat job scams.

Share this job
تحسين فرصتك لحصول على وظيفة خذ دورة عبر الإنترنت على Penetration Testing ابتداءً من الآن. تطلب ترويج10 دولار للدورات عبر الإنترنت. انظر جميع الدورات
See All Penetration Jobs
تعليقات وملاحظات تعليقات وملاحظات