📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

وظيفة أخصائي اختبارات اختراق (VAPT) لدى Tamkeen Technologies بالرياض

VAPT Specialist
🏢 Tamkeen Technologies
🕒 نُشرت: (أمس) 📍 الرياض وظائف الهندسة والتقنية
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

تعلن شركة Tamkeen Technologies عن توفر وظيفة أخصائي اختبارات اختراق وتقييم ثغرات (VAPT Specialist) في مدينة الرياض، السعودية، وذلك للانضمام إلى فريق أمن المعلومات.

نبذة عن الوظيفة

نبحث عن أخصائي VAPT ذي خبرة عملية قوية في اختبار اختراق الشبكات (Network Penetration Testing) كمجال رئيسي، إلى جانب خبرة في اختبار اختراق تطبيقات الويب والجوال، وتقييم الثغرات الأمنية، ومحاكاة الخصم (Red Teaming). سيكون المرشح مسؤولاً عن تحديد الثغرات الأمنية والتحقق منها واستغلالها عبر بيئات المؤسسات، وتقديم توصيات قابلة للتنفيذ للعلاج تستند إلى أُطر ومنهجيات أمنية قياسية.

المهام والمسؤوليات

  • إجراء اختبارات اختراق الشبكات الداخلية والخارجية كمسؤولية رئيسية.
  • إجراء اختبارات اختراق تطبيقات الويب وواجهات البرمجة (API) وتطبيقات الجوال.
  • تنفيذ تقييمات الثغرات الأمنية باستخدام Tenable.sc / Nessus.
  • إجراء أنشطة محاكاة الخصم (Red Teaming) لتقييم قدرة المؤسسة على اكتشاف الهجمات الواقعية والاستجابة لها والتخفيف من أثرها.
  • التحقق اليدوي من الثغرات واستغلالها بما يتجاوز المسح الآلي.
  • تنفيذ أنشطة الاستطلاع (reconnaissance)، وجمع المعلومات (enumeration)، والاستغلال (exploitation)، ورفع الامتيازات (privilege escalation)، والحركة الجانبية (lateral movement)، وأنشطة ما بعد الاستغلال (post-exploitation).
  • تقييم البنية التحتية للشبكات، و Active Directory، وأنظمة Windows/Linux، وخدمات الشبكة، والضوابط الأمنية.
  • تحديد الثغرات وتقييم أثرها الفني والتجاري.
  • إعداد تقارير فنية مفصّلة وملخصات تنفيذية.
  • تقديم توصيات علاجية واضحة وقابلة للتنفيذ.
  • إعادة اختبار الثغرات والتحقق من العلاج.
  • تطوير وصيانة منهجيات VAPT وقوائم الاختبارات والإجراءات الفنية.
  • اتباع أُطر ومنهجيات أمنية معترف بها مثل NIST و OWASP وممارسات اختبار الاختراق القياسية.
  • البحث عن الثغرات الناشئة والاستغلالات وتقنيات الهجوم ومنهجيات أمن الهجوم.

الشروط والمتطلبات

  • 3+ سنوات من الخبرة العملية في تقييم الثغرات الأمنية واختبار الاختراق.
  • خبرة قوية ومثبتة في اختبار اختراق الشبكات.
  • خبرة عملية في: اختبار اختراق الشبكات الداخلية والخارجية، اختبار أمان Active Directory، اختبار اختراق تطبيقات الويب وواجهات البرمجة، اختبار اختراق تطبيقات الجوال، تقييم الثغرات الأمنية، محاكاة الخصم.
  • يفضل وجود خبرة مع Tenable.sc / Nessus.
  • فهم قوي لـ NIST و OWASP ومنهجيات اختبار الاختراق.
  • معرفة قوية ببروتوكولات الشبكات، أنظمة Windows/Linux، Active Directory، آليات المصادقة، والضوابط الأمنية الشائعة للشبكات.
  • فهم قوي لتقنيات استغلال الثغرات وما بعد الاستغلال.
  • مهارات قوية في كتابة التقارير الفنية والتوثيق.
  • يفضل درجة البكالوريوس في الأمن السيبراني أو أمن المعلومات أو علوم الحاسب أو تقنية المعلومات أو مجال ذي صلة. يمكن النظر في الخبرة المهنية المعادلة والشهادات المهنية.
عرض النص الأصلي للإعلان

Job Summary

We are seeking an experienced VAPT Specialist with strong hands-on expertise in Network Penetration Testing as the primary area of responsibility, along with experience in Web and Mobile Application Penetration Testing, Vulnerability Assessment, and Red Teaming.

The candidate will be responsible for identifying, validating, and exploiting security vulnerabilities across enterprise environments and providing actionable remediation recommendations based on industry-standard security frameworks and methodologies.

Key Responsibilities

  • Perform Internal and External Network Penetration Testing as the primary responsibility.
  • Conduct Web Application, API, and Mobile Application Penetration Testing.
  • Perform Vulnerability Assessments using Tenable.sc / Nessus.
  • Conduct Red Teaming and adversary simulation activities to assess the organization's ability to detect, respond to, and mitigate realistic attacks.
  • Perform manual vulnerability validation and exploitation beyond automated scanning.
  • Conduct reconnaissance, enumeration, exploitation, privilege escalation, lateral movement, and post-exploitation activities.
  • Assess network infrastructure, Active Directory, Windows/Linux systems, network services, and security controls.
  • Identify vulnerabilities and assess their business and technical impact.
  • Prepare detailed technical reports and executive-level summaries.
  • Provide clear and actionable remediation recommendations.
  • Perform vulnerability retesting and validate remediation.
  • Develop and maintain VAPT methodologies, testing checklists, and technical procedures.
  • Follow recognized security frameworks and methodologies, including NIST, OWASP, and industry-standard penetration testing practices.
  • Research emerging vulnerabilities, exploits, attack techniques, and offensive security methodologies.

Required Experience & Qualifications

  • 3+ years of hands-on experience in Vulnerability Assessment and Penetration Testing.
  • Strong and proven experience in Network Penetration Testing.
  • Practical experience in:
  • Internal & External Network Penetration Testing
  • Active Directory Security Testing
  • Web Application & API Penetration Testing
  • Mobile Application Penetration Testing
  • Vulnerability Assessment
  • Red Teaming / Adversary Simulation
  • Experience with Tenable.sc / Nessus is preferred.
  • Strong understanding of NIST, OWASP, and penetration testing methodologies.
  • Strong knowledge of network protocols, Windows/Linux systems, Active Directory, authentication mechanisms, and common network security controls.
  • Strong understanding of vulnerability exploitation and post-exploitation techniques.
  • Strong technical report writing and documentation skills.

Education

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field is preferred.
  • Equivalent professional experience and industry certifications may be considered.

المصدر: LinkedIn - أُضيفت للموقع في 12 أغسطس 2026

وظائف أخرى لدى Tamkeen Technologies