وظيفة مستشار أمن سيبراني TVA شاغرة لدى NTT DATA, Inc. بمدينة الرياض
تفاصيل الوظيفة
انضم إلى شركة NTT DATA، إحدى الشركات الرائدة في مجال التكنولوجيا والخدمات، بصفتك مستشار أمن سيبراني (Cybersecurity Consultant TVA) في مدينة الرياض. ستكون جزءاً من فريق متخصص في تقييم الثغرات واختبار الاختراق، وتساعد المؤسسات على تعزيز وضعها الأمني والامتثال للمعايير التنظيمية.
المهام والمسؤوليات
- إجراء تقييمات الثغرات واختبارات الاختراق عبر الشبكات والبنية التحتية والخوادم والتطبيقات والبيئات السحابية.
- تنفيذ اختبارات اختراق الشبكات الداخلية والخارجية ضمن النطاق المتفق عليه.
- إجراء تقييمات أمنية لتطبيقات الويب وواجهات API باستخدام منهجيات معترف بها في الصناعة.
- إجراء المسح الآلي للثغرات باستخدام أدوات أمنية تجارية ومفتوحة المصدر سواءً كان المصادقة مفعلة أم لا.
- التحقق من الثغرات التي تحددها الأدوات الآلية وإزالة النتائج الإيجابية الخاطئة قبل إعداد التقارير.
- تنفيذ أنشطة استغلال خاضعة للتحكم لتأكيد تأثير الثغرات مع تقليل المخاطر التشغيلية.
- تقييم بيئات Windows وLinux وActive Directory وقواعد البيانات وأجهزة الشبكة والبنية التحتية الأمنية بحثاً عن نقاط الضعف.
- تقييم الثغرات بناءً على قابلية الاستغلال وأهمية الأصول والشدة الفنية والأثر التجاري.
- تعيين تصنيفات المخاطر باستخدام CVSS ومنهجيات تصنيف المخاطر الخاصة بالعميل.
- إعداد تقارير التقييم الفنية والملخصات التنفيذية وتوصيات المعالجة.
- تقديم نتائج التقييم وخطط معالجة المخاطر لأصحاب المصلحة التقنيين والتجاريين.
- إجراء ورش عمل للمعالجة وتقديم الإرشادات التقنية لفرق العميل.
- التحقق من فعالية المعالجة وإجراء إعادة الاختبار.
- الحفاظ على أدلة التقييم وسجلات الاختبار ولقطات الشاشة ومخرجات الأدوات والوثائق الداعمة.
- دعم أنشطة تخطيط التقييم بما في ذلك تحديد النطاق واختيار المنهجية ووضع قواعد الاشتباك.
- ضمان امتثال جميع أنشطة الاختبار لمتطلبات التفويض المعتمدة وإجراءات اختبار الأمان.
- دعم مبادرات الاستشارات الأمنية المتعلقة بتقوية الأنظمة ومعالجة الثغرات وأمن التطبيقات والبنية التحتية.
- المساعدة في التقييمات الأمنية وفقاً لأطر عمل معترف بها مثل NCA ECC وSAMA CSF وISO 27001 وCIS Controls وPCI DSS.
- المساهمة في التحسين المستمر لمنهجيات اختبار الأمان الداخلية وقوالب التقارير ومستودعات المعرفة.
- دعم أنشطة ما قبل البيع من خلال تقديم مدخلات تقنية لمقترحات العملاء وتحديد نطاقات التقييم وتقديرات الجهد.
- القيام بأي أنشطة استشارية أخرى في مجال الأمن السيبراني أو إدارة الثغرات أو اختبار الاختراق حسب الحاجة.
المهارات المطلوبة
- فهم قوي لمنهجيات تقييم الثغرات واختبار الاختراق.
- خبرة عملية في اختبار أمان الشبكات والبنية التحتية وتطبيقات الويب وواجهات API.
- معرفة متينة بشبكات TCP/IP والتوجيه والتبديل وDNS وHTTP/HTTPS وVPN وجدران الحماية وخدمات الشبكة المؤسسية.
- معرفة عملية جيدة ببيئات Windows وLinux وActive Directory.
- الإلمام بتقنيات الهجوم الشائعة مثل تصعيد الامتيازات وهجمات بيانات الاعتماد والحركة الجانبية واستغلال Active Directory.
- فهم قوي لأطر OWASP Top 10 وOWASP API Security Top 10 وCVSS وCWE وMITRE ATT&CK.
- خبرة عملية باستخدام أدوات تقييم الأمان مثل Burp Suite وNmap وNessus وQualys وRapid7 وMetasploit وWireshark وOWASP ZAP وKali Linux.
- القدرة على التحقق اليدوي من الثغرات والتمييز بين النتائج الحقيقية والنتائج الإيجابية الخاطئة.
- فهم تقنيات الأمان الشائعة مثل WAF وIDS/IPS وNAC وEDR وSIEM وحلول الوصول الآمن عن بُعد.
- قدرات أساسية في البرمجة النصية باستخدام Python أو PowerShell أو Bash أو لغات مماثلة.
- مهارات تحليلية قوية وحل المشكلات مع القدرة على التفكير من منظور المهاجم.
- مهارات ممتازة في كتابة التقارير وتوثيق الأدلة والعروض التقديمية.
- القدرة على توصيل الثغرات والمخاطر الفنية إلى أصحاب المصلحة التقنيين والتجاريين.
- القدرة على إدارة مهام متعددة للعملاء والعمل بشكل مستقل مع الحفاظ على جودة عالية للتسليمات.
- نزاهة مهنية عالية والالتزام بالحفاظ على سرية معلومات العملاء.
- مهارات تواصل قوية باللغة الإنجليزية كتابةً وتحدثاً؛ إجادة اللغة العربية ميزة إضافية.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو علوم الحاسب أو تقنية المعلومات أو هندسة الحاسب أو تخصص تقني ذي صلة. (قد تُقبل الخبرة العملية المكافئة في حال إثبات خبرة قوية في اختبار الأمان العملي).
- الشهادات المفضلة: OSCP، CREST CRT، GPEN، PNPT، eCPPT، CompTIA PenTest+، Burp Suite Certified Practitioner (BSCP)، CEH / CEH Practical.
- خبرة من 5 إلى 7 سنوات في الأمن السيبراني أو تقييم الثغرات أو اختبار الاختراق أو الاستشارات الأمنية.
- ما لا يقل عن 3 سنوات من الخبرة العملية الحديثة في تقييم الثغرات واختبار الاختراق.
- خبرة مثبتة في إجراء اختبارات اختراق الشبكات الداخلية والخارجية.
- خبرة عملية في إجراء تقييمات أمان تطبيقات الويب وواجهات API.
- خبرة في استخدام منصات إدارة الثغرات مثل Tenable أو Qualys أو Rapid7.
- خبرة قوية في استخدام أدوات مثل Burp Suite وMetasploit وNmap وKali Linux وWireshark.
- خبرة في التحقق من الثغرات والاستغلال والتحقق من المعالجة وإعادة الاختبار.
- خبرة في إعداد تقارير أمنية تقنية احترافية وعرض النتائج على العملاء وأصحاب المصلحة.
- خبرة في تقييم بيئات Windows وLinux وActive Directory والبنية التحتية للشبكات والبيئات المؤسسية.
- خبرة في العمل المباشر مع العملاء ضمن بيئة استشارات أمنية أو تكامل أنظمة أو خدمات مهنية.
- خبرة في اختبار أمان Active Directory تعتبر ميزة قوية.
- خبرة في أمن السحابة أو الشبكات اللاسلكية أو تطبيقات الهاتف المحمول أو حاويات أو فرق الاختراق الأحمر تعتبر ميزة إضافية.
- الإلمام بأطر NCA ECC أو SAMA CSF أو ISO 27001 أو PCI DSS أو ما شابهها يعتبر مفيداً.
عرض النص الأصلي للإعلان
Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion - it’s a place where you can grow, belong and thrive.
Your day at NTT DATA
The Cybersecurity Consultant is a hands-on cybersecurity professional responsible for conducting vulnerability assessments, penetration testing activities, and security reviews across customer environments. This role works closely with customers, infrastructure teams, application owners, and security stakeholders to identify security weaknesses, validate risks, and provide practical remediation recommendations.
The role combines technical security testing, customer engagement, and cybersecurity consultancy to help organizations strengthen their security posture, reduce risk, and improve compliance with security best practices and regulatory requirements.
Key responsibilities:
- Conduct vulnerability assessments and penetration tests across network, infrastructure, server, application, and cloud environments.
- Perform internal and external network penetration testing within approved scopes and rules of engagement.
- Conduct web application and API security assessments using recognized industry methodologies and frameworks.
- Perform authenticated and unauthenticated vulnerability scanning using approved commercial and open-source security tools.
- Validate vulnerabilities identified by automated tools and remove false positives before reporting.
- Perform controlled exploitation activities to confirm vulnerability impact while minimizing operational risk.
- Assess Windows, Linux, Active Directory, databases, network devices, and security infrastructure for security weaknesses.
- Evaluate vulnerabilities based on exploitability, asset criticality, technical severity, and business impact.
- Assign risk ratings using CVSS and applicable customer risk-classification methodologies.
- Prepare technical assessment reports, executive summaries, and remediation recommendations.
- Present assessment findings and risk remediation plans to technical and business stakeholders.
- Conduct remediation workshops and provide technical guidance to customer teams.
- Perform remediation validation and retesting activities.
- Maintain assessment evidence, testing records, screenshots, tool outputs, and supporting documentation.
- Support assessment planning activities, including scope definition, methodology selection, and rules of engagement.
- Ensure all testing activities comply with approved authorization requirements and security testing procedures.
- Support security consulting initiatives related to system hardening, vulnerability remediation, application security, and infrastructure security.
- Assist with security assessments aligned to recognized frameworks including NCA ECC, SAMA CSF, ISO 27001, CIS Controls, and PCI DSS.
- Contribute to continuous improvement of internal security testing methodologies, reporting templates, and knowledge repositories.
- Support presales activities by providing technical input for customer proposals, assessment scope definitions, and effort estimates.
- Perform any other cybersecurity consulting, vulnerability management, or penetration testing activities as required.
- Strong understanding of vulnerability assessment and penetration testing methodologies.
- Hands-on experience conducting network, infrastructure, web application, and API security testing.
- Strong knowledge of TCP/IP networking, routing, switching, DNS, HTTP/HTTPS, VPNs, firewalls, and enterprise network services.
- Good working knowledge of Windows, Linux, and Active Directory environments.
- Familiarity with common attack techniques including privilege escalation, credential attacks, lateral movement, and Active Directory exploitation.
- Strong understanding of OWASP Top 10, OWASP API Security Top 10, CVSS, CWE, and MITRE ATT&CK frameworks.
- Practical experience using security assessment tools such as Burp Suite, Nmap, Nessus, Qualys, Rapid7, Metasploit, Wireshark, OWASP ZAP, and Kali Linux.
- Ability to manually validate vulnerabilities and distinguish genuine findings from false positives.
- Understanding of common security technologies including WAF, IDS/IPS, NAC, EDR, SIEM, and secure remote access solutions.
- Basic scripting capabilities using Python, PowerShell, Bash, or similar languages.
- Strong analytical and problem-solving skills with the ability to think from an attacker's perspective.
- Strong report writing, evidence documentation, and presentation skills.
- Ability to communicate technical vulnerabilities and risks to both technical and business stakeholders.
- Ability to manage multiple customer engagements and work independently while maintaining high-quality deliverables.
- Strong professional integrity and commitment to maintaining customer confidentiality.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering, or a related technical discipline.
- Equivalent practical experience may be considered where strong hands-on security testing expertise is demonstrated.
- Preferred certifications include: OSCP, CREST CRT, GPEN, PNPT, eCPPT, CompTIA PenTest+, Burp Suite Certified Practitioner (BSCP), CEH / CEH Practical
- 5-7 years of cybersecurity, vulnerability assessment, penetration testing, or security consulting experience.
- Minimum 3 years of recent hands-on vulnerability assessment and penetration testing experience.
- Demonstrated experience conducting internal and external network penetration tests.
- Hands-on experience performing web application and API security assessments.
- Experience using vulnerability management platforms such as Tenable, Qualys, or Rapid7.
- Strong working experience with tools including Burp Suite, Metasploit, Nmap, Kali Linux, and Wireshark.
- Experience performing vulnerability validation, exploitation, remediation verification, and retesting.
- Experience preparing professional technical security reports and presenting findings to customers and stakeholders.
- Experience assessing Windows, Linux, Active Directory, network infrastructure, and enterprise environments.
- Experience working directly with customer engagements within a cybersecurity consulting, systems integration, or professional services environment.
- Experience with Active Directory security testing is strongly preferred.
- Cloud, wireless, mobile application, container security, or red team experience is advantageous.
- Exposure to NCA ECC, SAMA CSF, ISO 27001, PCI DSS, or related security frameworks is considered beneficial.
- Strong written and verbal English communication skills; Arabic language capability is an advantage.
On-site Working
About NTT DATA
NTT DATA is a $30+ billion business and technology services leader, serving 75% of the Fortune
Global 100. We are committed to accelerating client success and positively impacting society through
responsible innovation. We are one of the world’s leading AI and digital infrastructure providers, with
unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and
application services. Our consulting and industry solutions help organizations and society move
confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more
than 70 countries. We also offer clients access to a robust ecosystem of innovation centers as well as
established and start-up partners. NTT DATA is part of NTT Group, which invests over $3 billion each
year in R&D.
Equal Opportunity Employer
NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us. Apply today.
Third parties fraudulently posing as NTT DATA recruiters
NTT DATA recruiters will never ask job seekers or candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties who may attempt to impersonate NTT DATA recruiters whether in writing or by phone in order to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will come from an @nttdata.com email address. If you suspect any fraudulent activity, please contact us.
رقم الإعلان لدى المصدر: 4471766265