img
Contract TypeFull-time
Workplace typeRemote
LocationRiyadh

Job Description

About the Role

NTT DATA is seeking a Cybersecurity Consultant TVA to join their team in Riyadh. This full-time role involves hands-on cybersecurity work, focusing on vulnerability assessments, penetration testing, and security reviews within customer environments. The consultant will collaborate with customers, infrastructure teams, application owners, and security stakeholders to identify weaknesses, validate risks, and provide remediation recommendations.

Role Context

This position combines technical security testing with customer engagement and cybersecurity consultancy. The primary objective is to help organizations enhance their security posture, mitigate risks, and improve adherence to security best practices and regulatory requirements. The role requires 5-10 years of experience in a relevant field.

Key Responsibilities

  • Conduct vulnerability assessments and penetration tests across network, infrastructure, server, application, and cloud environments.
  • Perform internal and external network penetration testing within approved scopes.
  • Conduct web application and API security assessments using industry methodologies.
  • Perform authenticated and unauthenticated vulnerability scanning using commercial and open-source tools.
  • Validate identified vulnerabilities and remove false positives before reporting.
  • Perform controlled exploitation activities to confirm vulnerability impact while minimizing operational risk.
  • Assess Windows, Linux, Active Directory, databases, network devices, and security infrastructure for weaknesses.
  • Evaluate vulnerabilities based on exploitability, asset criticality, technical severity, and business impact.
  • Assign risk ratings using CVSS and applicable customer risk-classification methodologies.
  • Prepare technical assessment reports, executive summaries, and remediation recommendations.
  • Present assessment findings and risk remediation plans to stakeholders.
  • Conduct remediation workshops and provide technical guidance to customer teams.
  • Perform remediation validation and retesting activities.
  • Maintain assessment evidence, testing records, and supporting documentation.
  • Support assessment planning activities, including scope definition and methodology selection.
  • Ensure all testing activities comply with authorization requirements and security testing procedures.
  • Support security consulting initiatives related to system hardening, vulnerability remediation, and application/infrastructure security.
  • Assist with security assessments aligned to frameworks including NCA ECC, SAMA CSF, ISO 27001, CIS Controls, and PCI DSS.
  • Contribute to continuous improvement of internal security testing methodologies and reporting templates.
  • Support presales activities by providing technical input for customer proposals and effort estimates.
  • Perform other cybersecurity consulting, vulnerability management, or penetration testing activities as required.

Required Qualifications and Skills

  • Strong understanding of vulnerability assessment and penetration testing methodologies.
  • Hands-on experience conducting network, infrastructure, web application, and API security testing.
  • Strong knowledge of TCP/IP networking, routing, switching, DNS, HTTP/HTTPS, VPNs, firewalls, and enterprise network services.
  • Good working knowledge of Windows, Linux, and Active Directory environments.
  • Familiarity with common attack techniques including privilege escalation, credential attacks, lateral movement, and Active Directory exploitation.
  • Strong understanding of OWASP Top 10, OWASP API Security Top 10, CVSS, CWE, and MITRE ATT&CK frameworks.
  • Practical experience using security assessment tools such as Burp Suite, Nmap, Nessus, Qualys, Rapid7, Metasploit, Wireshark, OWASP ZAP, and Kali Linux.
  • Ability to manually validate vulnerabilities and distinguish genuine findings from false positives.
  • Understanding of common security technologies including WAF, IDS/IPS, NAC, EDR, SIEM, and secure remote access solutions.
  • Basic scripting capabilities using Python, PowerShell, Bash, or similar languages.
  • Strong analytical and problem-solving skills with the ability to think from an attacker's perspective.
  • Strong report writing, evidence documentation, and presentation skills.
  • Ability to communicate technical vulnerabilities and risks to both technical and business stakeholders.
  • Ability to manage multiple customer engagements and work independently while maintaining high-quality deliverables.
  • Strong professional integrity and commitment to maintaining customer confidentiality.

Work Environment

This is a full-time position based in Riyadh, where the consultant will engage directly with customers and various internal and external stakeholders to deliver cybersecurity services.

Application Process

Interested candidates are encouraged to apply. Salary details will be discussed during the interview process.


Requirements

  • Requires 5-10 Years experience

Similar Jobs