نظم تعلن عن وظيفة Penetration Tester في الرياض
Penetration Tester
🏢 نظم
تفاصيل الوظيفة
تسعى شركة نظم (NOZOM) إلى توظيف أخصائي أمن معلومات - مختبر اختراق (Penetration Tester) في الرياض، السعودية، للعمل على تقييم أمن الشبكات والتطبيقات والنقاط الطرفية والبيئات السحابية واكتشاف الثغرات وتقديم توصيات المعالجة.
المهام والمسؤوليات
- إجراء اختبارات الاختراق للشبكات الداخلية وتطبيقات الويب والنقاط الطرفية والشبكات اللاسلكية والبيئات السحابية.
- تحديد واستغلال والتحقق من صحة وتوثيق الثغرات الأمنية.
- إجراء مراجعات آمنة للكود البرمجي، واكتشاف عيوب المصادقة وبيانات الاعتماد المشفرة والمنطق غير الآمن.
- المشاركة في تمارين الفريق الأحمر المتقدمة ومحاكاة الهجمات متعددة المراحل.
- تقييم المنصات السحابية بما في ذلك AWS وAzure وGCP وOracle.
- إعداد تقارير فنية وتنفيذية مفصلة.
- عرض النتائج على أصحاب المصلحة ودعم التحقق من صحة المعالجة.
الشروط والمتطلبات
- درجة البكالوريوس في علوم الحاسب أو الأمن السيبراني أو مجال ذي صلة.
- خبرة لا تقل عن 3 سنوات في مجال خدمات أمن المعلومات.
- إتقان اللغة العربية (شرط أساسي).
- خبرة في تقييم الثغرات واستغلالها واختبار تطبيقات الويب وتحليل البروتوكولات الشبكية.
- معرفة بتقييم أمن السحابة ومخاطر تصعيد الصلاحيات.
- مهارات قوية في إعداد التقارير الفنية والتوثيق والتواصل.
المهارات المطلوبة
- يفضل امتلاك شهادة أو أكثر من الشهادات التالية: OSCP، GPEN، GWAPT، GXPN، eCPPT، eWPT، أو eWPTX.
عرض النص الأصلي للإعلان
Job Title: Information Security Specialist - Penetration Tester
Job Description:
NOZOM is seeking an Information Security Specialist with hands-on experience in penetration testing. The successful candidate will assess networks, applications, endpoints, wireless environments, and cloud platforms to identify security vulnerabilities and provide effective remediation recommendations.
Key Responsibilities:
- Conduct penetration testing for internal networks, web applications, endpoints, wireless networks, and cloud environments.
- Identify, exploit, validate, and document security vulnerabilities.
- Perform secure code reviews and identify authentication flaws, hardcoded credentials, and insecure logic.
- Participate in advanced Red Team exercises and multi-stage attack simulations.
- Assess cloud platforms, including AWS, Azure, GCP, and Oracle.
- Prepare detailed technical and executive reports.
- Present findings to stakeholders and support remediation validation.
Qualifications and Requirements:
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
- Minimum of 3 years of relevant experience in information security services.
- Fluency in Arabic is required.
- Experience in vulnerability assessment, exploitation, web application testing, and network protocol analysis.
- Knowledge of cloud security assessment and privilege escalation risks.
- Strong technical reporting, documentation, and communication skills.
- One or more of the following certifications is preferred: OSCP, GPEN, GWAPT, GXPN, eCPPT, eWPT, or eWPTX.
المصدر: LinkedIn - أُضيفت للموقع في 6 أغسطس 2026