وظيفة مستشار شاغرة لدى Protiviti Middle East Member Firm في الرياض
تفاصيل الوظيفة
شركة Protiviti Middle East Member Firm تبحث عن استشاريين ذوي خبرة للانضمام إلى فريق S&P في الرياض، المملكة العربية السعودية.
نبذة عن الوظيفة
سيتولى المرشح الناجح تقييم الوضع الأمني لأنظمة ومنصات وعمليات العملاء لحماية وتحسين سرية وسلامة وتوافر أنظمة المعلومات بما يتوافق مع أهداف الأعمال والمتطلبات التنظيمية والأهداف الاستراتيجية للعميل. سيعمل بشكل أساسي على تنفيذ وإدارة مهام استشارية متنوعة للعملاء، وقد يتطلب السفر إلى مواقع مختلفة في الشرق الأوسط.
المهام والمسؤوليات
- تقديم الابتكار في سياق برنامج اختبار الثغرات والاختراق (VAPT) من حيث العملية والتقنية.
- العمل كخبير موضوع (SME) لوظيفة الهجوم والاختراق (Attack & Pen).
- إجراء مراجعات لسطح الهجوم المصرح بها واختبارات الاختراق وتقييمات الفريق الأحمر ضد أهداف محددة.
- إعداد تقارير تقييم مفهومة للجمهور المستهدف وتشمل توصيات عملية ومعقولة بناءً على مبادئ إدارة المخاطر السليمة.
- تحديث المعايير والإجراءات المصممة لتحسين الوضع الأمني باستمرار.
- تقييم كفاية السياسات والمعايير والإجراءات مقارنة بأفضل الممارسات الأمنية.
- المساهمة في مستودعات المعلومات المتعلقة بالأمن وجهود تطوير الأعمال الأخرى.
- توجيه الأعضاء المبتدئين في الفريق وتقديم استشارات بناءة للمجموعات الأخرى.
الشروط والمتطلبات
- درجة البكالوريوس في علوم الحاسب أو ما يعادلها بشكل كبير.
- من 4 إلى 6 سنوات من الخبرة المهنية في مجال أمن المعلومات مع التركيز على التقييمات التقنية.
- معرفة متقنة بمفاهيم اختبار الاختراق وأفضل الممارسات.
- خبرة واسعة في أدوات اختبار الاختراق الشائعة مثل Nessus وAppscan وBurp Suite وNipper وExploit Pack وغيرها.
- إتقان أدوات وأطر الهجوم الأخرى مثل Wireshark وKali وMetasploit وغيرها.
- القدرة على التحقق من وجود الثغرات المحددة بدقة.
- إتقان منصات وتقنيات التطبيقات الشائعة لفهم وتقييم تقييمات التطبيقات المعقدة بشكل فعال عبر التقنيات اليدوية والأدوات البسيطة مثل البروكسي وإضافات المتصفح.
- فهم عميق لـ OWASP وCVE وضوابط الأمان العامة وغيرها من المواضيع الأساسية مثل أحدث ثغرات التطبيقات وأنظمة التشغيل.
- معرفة لغات البرمجة النصية مثل Python وShell Script وغيرها.
- يفضل الحصول على شهادات GIAC GPEN أو GWAPT أو CREST أو OSCE.
المهارات المطلوبة
- القدرة على الحفاظ على التفكير النقدي والرباطة الجأش تحت الضغط.
- مهارات قوية في التواصل الكتابي والشفهي باللغة الإنجليزية، مع القدرة على نقل المفاهيم المعقدة لجمهور الأعمال.
- القدرة على الإنتاجية والتركيز مع الحد الأدنى من الإشراف.
- فهم VAPT في سياق إدارة المخاطر والأولويات التنظيمية.
عرض النص الأصلي للإعلان
Role Summary
We are looking for experienced consultants to join our S&P team at Protiviti. The role will primarily involve executing and managing diverse client engagements. While the role is based in GCC resources may travel across various client locations in the Middle East, etc.
The successful applicant will be responsible for assessing the security posture of client systems, platforms, and processes to protect and continually improve the confidentiality, integrity, and availability of information systems in accordance with the client's business objectives, regulatory requirements, and strategic goals.
Responsibilities
- Provide innovation within the context of the Vulnerability and Penetration Testing (VAPT) program in relation to both process and technology.
- Serve as a Subject Matter Expert (SME) for the Attack & Pen function.
- Perform authorized attack surface reviews, penetration tests, and red team assessments against specific targets.
- Provide assessment reports that are easily understandable by the target audience and include practical and reasonable recommendations based on sound risk management principles.
- Update standards and procedures designed to continually improve security posture
- Assess the sufficiency of policies, standards, and procedures relative to security best practices.
- Contribute to the security-related information repositories and other business development endeavors.
- Mentor junior members of the team and provide constructive consultation to other peer groups.
Background Requirements
- Computer Science Bachelor’s Degree or substantial equivalent.
- 4 to 6 years of professional experience in information security with a focus on technical assessments.
- Commanding knowledge of pen testing concepts and best practices.
- Extensive experience with common Pentesting tools such as Nessus, Appscan, Burp Suite, Nipper, Exploit Pack etc.
- Proficiency with other common attack tools and frameworks such as Wireshark, Kali, and Metasploit, etc.
- Ability to validate the presence of identified vulnerabilities with accuracy.
- Mastery of common application platforms and technologies to effectively understand and evaluate complex application assessments via the use of manual techniques and simple tools such as proxies and browser plugins.
- In-depth understanding of OWASP, CVE general security controls, and other foundational topics such as the latest application and operating system exploits.
- Knowledge of common scripting and programming languages like python, shell script etc.
- GIAC GPEN, GWAPT, CREST or OSCE preferred.
Personal Skills:
- Ability to maintain critical thinking and composure under pressure.
- Strong written and oral communication skills in English. Ability to convey complex concepts to business audience.
- Ability to be productive and maintain focus with minimal supervision.
- Understands VAPT in the context of risk management and organizational priorities.
رقم الإعلان لدى المصدر: 4469826078