Cloud Consultancy - CCDS تعلن عن وظيفة أخصائي ضمان الأمن السيبراني في الرياض
Cybersecurity Assurance Specialist
تفاصيل الوظيفة
تعلن شركة Cloud Consultancy - CCDS عن توفر وظيفة "أخصائي ضمان الأمن السيبراني" للعمل في الرياض (حضوري) بعقد خدمات أمنية مدارة قائم على المشروع لمدة 13 شهراً، تتطلب خبرة لا تقل عن 7 سنوات.
المهام والمسؤوليات
- تخطيط وتنفيذ اختبارات الاختراق المصرح بها عبر الشبكات والتطبيقات والأنظمة والبيئات السحابية ضمن النطاق المحدد.
- إجراء عمليات الاستطلاع وتحليل سطح الهجوم واكتشاف الثغرات والاستغلال الآمن واختبار رفع الصلاحيات والحركة الجانبية.
- محاكاة سيناريوهات هجومية واقعية مع الالتزام بقواعد الاشتباك المعتمدة وضمان حماية توفر الخدمة والبيانات.
- تقييم النتائج بناءً على الخطورة الفنية وقابلية الاستغلال والتأثير على الأعمال.
- إعداد تقارير فنية واضحة وملخصات تنفيذية تتضمن توصيات عملية للعلاج.
- عرض النتائج والتوصيات على الملاك الفنيين وأصحاب المصلحة.
- إجراء إعادة اختبار للتحقق من فعالية العلاج ومتابعة إغلاق النتائج.
- مراقبة اتجاهات الثغرات والمساهمة في التحسين المستمر لعمليات ضمان الأمن.
المهارات المطلوبة
- فهم عميق لأسطح الهجوم في الشبكات والتطبيقات والبنية التحتية والبيئات السحابية.
- قدرة عملية على الاستغلال ورفع الصلاحيات والحركة الجانبية والتحقق من العلاج.
- معرفة منهجيات اختبار OWASP ومعايير الاختبار الصناعية وممارسات تقييم الثغرات وإطار MITRE ATT&CK.
- قدرة قوية على إعداد التقارير الفنية والتنفيذية.
- فضول تحليلي قوي وعادات اختبار منهجية.
- القدرة على شرح نقاط الضعف المعقدة وتأثيرها على الأعمال بلغة واضحة.
- التعاون والبنّاءية عند العمل مع مالكي الأنظمة على العلاج.
- الأخلاقية والسرية والانضباط في التعامل مع الأنظمة والنتائج الحساسة.
الشروط والمتطلبات
- درجة البكالوريوس في علوم الحاسب أو أمن المعلومات أو مجال ذي صلة.
- خبرة لا تقل عن 7 سنوات في اختبار الاختراق أو ضمان الأمن السيبراني أو القرصنة الأخلاقية.
- يفضل وجود شهادات مهنية مثل OSCP أو OSEP أو CEH أو ما يعادلها.
عرض النص الأصلي للإعلان
Location: On-site - Riyadh, Saudi Arabia
Contract/engagement: Project-based managed cybersecurity services (13-month)
Minimum experience: 7+ years
Role Purpose
Provide technical cybersecurity assurance through penetration testing, vulnerability validation, remediation verification, and risk-based reporting.
Key Responsibilities
Technical and Professional Requirements
Preferred: OSCP, OSEP, CEH, or equivalent.
Application Note
Candidates should clearly state their nationality, years of relevant experience, current location, notice period, and valid professional certifications in their application. Shortlisted candidates may be asked to provide supporting documents and participate in technical interviews.
Contract/engagement: Project-based managed cybersecurity services (13-month)
Minimum experience: 7+ years
Role Purpose
Provide technical cybersecurity assurance through penetration testing, vulnerability validation, remediation verification, and risk-based reporting.
Key Responsibilities
- Plan and execute authorized penetration tests across in-scope networks, applications, systems, and cloud environments
- Perform reconnaissance, attack-surface analysis, vulnerability discovery, safe exploitation, privilege escalation, and lateral-movement testing
- Simulate realistic attack scenarios while following approved rules of engagement and protecting service availability and data
- Assess findings based on technical severity, exploitability, and business impact
- Prepare clear technical reports and executive summaries with practical remediation guidance
- Present findings and recommendations to technical owners and business stakeholders
- Conduct retesting to confirm remediation effectiveness and track closure of findings
- Monitor vulnerability trends and contribute to continuous improvement of security-assurance processes
Technical and Professional Requirements
- Bachelor's degree in Computer Science, Information Security, or a related field
- At least 7 years of experience in penetration testing, cybersecurity assurance, or ethical hacking
- Strong understanding of network, web/application, infrastructure, and cloud attack surfaces
- Hands-on capability in exploitation, privilege escalation, lateral movement, and remediation validation
- Knowledge of OWASP testing methodologies, industry testing standards, vulnerability-rating practices, and MITRE ATT&CK
- Strong technical and executive reporting capability
- Ethical, discreet, and disciplined in handling sensitive systems and findings
- Strong analytical curiosity and methodical testing habits
- Able to explain complex weaknesses and business impact in clear language
- Collaborative and constructive when working with system owners on remediation
Preferred: OSCP, OSEP, CEH, or equivalent.
Application Note
Candidates should clearly state their nationality, years of relevant experience, current location, notice period, and valid professional certifications in their application. Shortlisted candidates may be asked to provide supporting documents and participate in technical interviews.
المصدر: LinkedIn - أُضيفت للموقع في 28 أغسطس 2026
رقم الإعلان لدى المصدر: 4460349011
رقم الإعلان لدى المصدر: 4460349011