EJADA تعلن عن وظيفة أخصائي تقييم الثغرات واختبار الاختراق (VAPT) في الرياض
تفاصيل الوظيفة
تعلن شركة EJADA عن توفر فرصة وظيفية لأخصائي تقييم الثغرات واختبار الاختراق (VAPT) في الرياض، السعودية. يهدف الدور إلى تحديد وتقييم والتحقق من الثغرات الأمنية عبر التطبيقات والأنظمة والشبكات والبنية التحتية، ودعم استراتيجية الدفاع السيبراني من خلال أنشطة الاختبار وإدارة الثغرات وتحسين الوضع الأمني وفقًا لأفضل الممارسات.
المهام والمسؤوليات
- إجراء تقييمات الثغرات عبر بيئات الشبكة والتطبيقات وقواعد البيانات والسحابة والأجهزة الطرفية.
- تنفيذ أنشطة اختبار الاختراق ضد تطبيقات الويب وواجهات API والأنظمة والبنية التحتية للشبكة.
- تحديد الثغرات الأمنية والتكوينات الخاطئة والتحقق منها وإعادة إنتاجها.
- تنفيذ أنشطة اختبار أمني وفقًا للمنهجيات والأطر المعيارية في المجال.
- تقييم التطبيقات وفقًا لقائمة OWASP Top 10 والمخاطر الأمنية الشائعة الأخرى.
- تحليل نتائج فحص الثغرات وترتيب الأولويات بناءً على المخاطر والتأثير على الأعمال.
- إعداد تقارير تقييم مفصلة تشمل النتائج الفنية وتصنيف المخاطر وتوصيات المعالجة.
- التحقق من المعالجة وإعادة الاختبار لتأكيد إغلاق الثغرات.
- دعم أنشطة إدارة الثغرات عبر تتبع النتائج والتنسيق مع الجهات المعنية لجهود المعالجة.
- استخدام أدوات اختبار أمني وأجهزة فحص الثغرات ومنصات اختبار الاختراق.
- دعم تمارين الفريق الأحمر ومبادرات التقييم السيبراني الأخرى حسب الحاجة.
- الحفاظ على توثيق الاختبار والأدلة والإجراءات وسجلات التقييم.
- المساهمة في مبادرات التحسين المستمر لتعزيز عمليات وفعالية الاختبار الأمني.
- ضمان الامتثال لسياسات الأمن السيبراني والمعايير والمتطلبات التنظيمية.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو علوم الحاسب أو أمن المعلومات أو تقنية المعلومات أو مجال ذي صلة.
- شهادات مهنية مثل CEH أو eJPT أو PNPT أو Security+.
- شهادات متقدمة مثل OSCP أو GPEN أو GWAPT (مفضلة).
- خبرة لا تقل عن سنتين في تقييم الثغرات أو اختبار الاختراق أو الاختبار الأمني أو عمليات الأمن السيبراني.
- خبرة عملية في إجراء تقييمات الثغرات ومهام اختبار الاختراق.
- خبرة في الفحص الأمني والتحقق من المعالجة وعمليات إدارة الثغرات.
- خبرة في العمل مع أدوات الأمن المؤسسية وأفضل ممارسات الأمن السيبراني.
المهارات المطلوبة
- تقييم وإدارة الثغرات.
- اختبار اختراق تطبيقات الويب.
- اختبار اختراق الشبكات.
- اختبار أمن واجهات API.
- اختبار أمني وفق OWASP Top 10.
- الفحص الأمني والتحقق من الثغرات.
- إتقان أدوات مثل Burp Suite وNmap وMetasploit وNessus وOpenVAS أو ما يعادلها.
- منهجيات وأطر الاختبار الأمني.
- إعداد تقارير الثغرات وتتبع المعالجة.
- تقييم وتحليل المخاطر الأمنية.
- أساسيات البرمجة النصية والأتمتة (Python، Bash، PowerShell أو ما يشابهها).
- توثيق وكتابة تقارير أمنية.
- الإلمام بتمارين الفريق الأحمر ومحاكاة الخصوم.
- أمن أنظمة التشغيل (Windows، Linux).
- أساسيات أمن الشبكات وتحليل البروتوكولات.
عرض النص الأصلي للإعلان
Job Purpose:
The Vulnerability Assessment & Penetration Testing (VAPT) Specialist is responsible for identifying, assessing, and validating cybersecurity vulnerabilities across applications, systems, networks, and infrastructure environments. The role supports the organization's cybersecurity defense strategy through security testing activities, vulnerability management, penetration testing engagements, remediation validation, and continuous improvement of the security posture in alignment with established security frameworks and industry best practices.
Key Accountabilities:
- Conduct vulnerability assessments across network, application, database, cloud, and endpoint environments.
- Perform penetration testing activities against web applications, APIs, systems, and network infrastructure.
- Identify, validate, and reproduce security vulnerabilities and misconfigurations.
- Execute security testing activities aligned with industry-standard methodologies and frameworks.
- Assess applications against OWASP Top 10 and other common security risks.
- Analyze vulnerability scan results and prioritize findings based on risk and business impact.
- Prepare detailed assessment reports, including technical findings, risk ratings, and remediation recommendations.
- Perform remediation validation and retesting activities to confirm vulnerability closure.
- Support vulnerability management activities by tracking findings and coordinating remediation efforts with stakeholders.
- Utilize security testing tools, vulnerability scanners, and penetration testing platforms to conduct assessments.
- Support Red Team exercises and other cybersecurity assessment initiatives as required.
- Maintain testing documentation, evidence, procedures, and assessment records.
- Contribute to continuous improvement initiatives to enhance cybersecurity testing processes and effectiveness.
- Ensure compliance with cybersecurity policies, standards, and regulatory requirements.
Minimum Qualifications:
- Bachelor's Degree in Cybersecurity, Computer Science, Information Security, Information Technology, or a related field.
- Professional certifications such as CEH, eJPT, PNPT, Security+.
- Advanced certifications such as OSCP, GPEN, GWAPT.
Minimum Experience:
- +2 years of experience in Vulnerability Assessment, Penetration Testing, Security Testing, or Cybersecurity Operations.
- Hands-on experience performing vulnerability assessments and penetration testing engagements.
- Experience with security scanning, remediation validation, and vulnerability management processes.
- Experience working with enterprise security tools and cybersecurity best practices.
Job-Specific Skills:
- Vulnerability Assessment and Management.
- Web Application Penetration Testing.
- Network Penetration Testing.
- API Security Testing.
- OWASP Top 10 Security Testing.
- Security Scanning and Vulnerability Validation.
- Burp Suite, Nmap, Metasploit, Nessus, OpenVAS, or equivalent tools.
- Security Testing Methodologies and Frameworks.
- Vulnerability Reporting and Remediation Tracking.
- Security Risk Assessment and Analysis.
- Basic Scripting and Automation (Python, Bash, PowerShell, or similar).
- Security Documentation and Report Writing.
- Red Teaming and Adversary Simulation Awareness.
- Operating Systems Security (Windows, Linux).
- Network Security Fundamentals and Protocol Analysis.
رقم الإعلان لدى المصدر: 4459145697