وظيفة أخصائي أول اختبار اختراق شاغرة لدى CYBER سايبر في مكة وجدة
تفاصيل الوظيفة
تعلن شركة CYBER سايبر عن توفر وظيفة "أخصائي أول اختبار اختراق" في مكة وجدة، المملكة العربية السعودية. نحن نبحث عن مختبر اختراق متحمس وذو خبرة للانضمام إلى فريقنا، حيث سيكون مسؤولاً عن تحديد الثغرات في أنظمتنا وشبكاتنا، ومحاكاة هجمات المهاجمين، والتوصية بضوابط الأمان للتخفيف من المخاطر.
المهام والمسؤوليات
- تحديد طرق الهجوم المحتملة لاستغلال الثغرات في الأنظمة والشبكات.
- محاكاة هجمات الهندسة الاجتماعية لكشف الفجوات الأمنية.
- جمع معلومات حول طوبولوجيا الشبكة واستخدامها من خلال التحليل الفني والبحث مفتوح المصدر.
- إجراء مراجعات للكود باستخدام أدوات اختبار الأمان وفحص الكود.
- التوصية بضوابط أمان لمعالجة الثغرات التي تم تحديدها من خلال الاختبارات.
- إجراء مراجعات للتدابير الدفاعية واختبار اختراق البنية التحتية والأصول وفقاً لسياسات المنظمة.
- إجراء تقييمات للمخاطر والثغرات التقنية وغير التقنية.
- الحفاظ على مجموعة أدوات تدقيق الدفاع السيبراني القابلة للنشر بناءً على أفضل الممارسات في المجال.
- اختبار الثغرات في تطبيقات الويب والتطبيقات العميلة والتطبيقات القياسية.
- إجراء تقييمات أمنية مادية للخوادم والأنظمة وأجهزة الشبكة.
- الإبلاغ عن نتائج اختبار الاختراق وتقييم الثغرات، بما في ذلك مستوى المخاطر وتخفيف المقترح وتفاصيل إعادة إنتاج نتائج الاختبار.
- شرح الأثر التجاري للثغرات المحددة للدفاع عن الإصلاح.
- عرض نتائج الاختبار والمخاطر والاستنتاجات على الجماهير التقنية وغير التقنية.
- تصميم هجمات محاكاة تعكس الأثر على أعمال المنظمة ومستخدميها.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو علوم الحاسب أو تقنية المعلومات أو مجال ذي صلة.
- (مفضل) شهادات احترافية مثل: OSCP، OSWP، OSEP، GPEN، GWAPT، GMOB، GXPN، GWEB، GCPN، eWAPTX، أو eCTHP.
- خبرة من 5 إلى 7 سنوات في مجال ذي صلة.
المهارات المطلوبة
- مستوى متقدم في إجراء فحوصات الثغرات وتفسير النتائج.
- مستوى متوسط في إجراء اختبار الاختراق وفقاً لسياسات المنظمة وأفضل الممارسات.
- مستوى متقدم في تطوير أفكار حول بيئة التهديدات للمنظمة.
- مستوى متقدم في تحليل بيانات الثغرات والتكوين لتحديد مشكلات الأمن السيبراني.
- مستوى متقدم في محاكاة سلوكيات التهديدات.
- مستوى متوسط في تنفيذ تكتيكات وتقنيات وإجراءات الخصم (TTPs).
عرض النص الأصلي للإعلان
Summary
We are seeking a highly motivated and skilled Penetration Tester to join our team. You will be responsible for identifying vulnerabilities in our systems and networks, mimicking attacker methods, and recommending security controls to mitigate risks.
Responsibilities
- Identify potential attacker methods to exploit system and network vulnerabilities.
- Simulate social engineering attacks to uncover security gaps.
- Gather information about network topography and usage through technical analysis and open-source research.
- Conduct code reviews using security testing and code scanning tools.
- Recommend security controls to address vulnerabilities identified through testing.
- Conduct reviews of defensive measures and penetration testing of infrastructure and assets according to organizational policies.
- Perform technical and non-technical risk and vulnerability assessments.
- Maintain a deployable cyber defense audit toolkit based on industry best practices.
- Test for vulnerabilities in web applications, client applications, and standard applications.
- Conduct physical security assessments of servers, systems, and network devices.
- Report penetration testing and vulnerability assessment findings, including risk level, proposed mitigation, and details for reproducing test results.
- Explain the business impact of identified vulnerabilities to advocate for remediation.
- Present test findings, risks, and conclusions to both technical and non-technical audiences.
- Design simulated attacks that reflect the impact on the organization's business and users.
Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related discipline.
- (Preferred) Professional certifications such as OSCP, OSWP, OSEP, GPEN, GWAPT, GMOB, GXPN, GWEB, GCPN, eWAPTX, or eCTHP.
- 5-7 years of experience in a relevant field.
Skills
- Advanced proficiency in conducting vulnerability scans and interpreting results.
- Intermediate proficiency in conducting penetration testing aligned with organizational policies and best practices.
- Advanced proficiency in developing insights about an organization's threat environment.
- Advanced proficiency in analyzing vulnerability and configuration data to identify cybersecurity issues.
- Advanced proficiency in mimicking threat behaviors.
- Intermediate proficiency in implementing adversary Tactics, Techniques, and Procedures (TTPs).
رقم الإعلان لدى المصدر: 4461285386