img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Penetration Tester Role

AppSec is seeking a motivated Penetration Tester to join its growing cybersecurity team in Riyadh. This full-time position is for individuals with 0-1 years of experience who are adept at identifying vulnerabilities across code, applications, and enterprise environments.

Core Responsibilities

The Penetration Tester will be responsible for conducting comprehensive security assessments. Key duties include:

  • Performing end-to-end penetration testing on web applications, mobile applications, and infrastructure/networks.
  • Executing Active Directory attacks, including enumeration, privilege escalation, lateral movement, and domain compromise within enterprise environments.
  • Conducting internal and external security assessments, focusing on vulnerability identification and exploitation.

Reporting and Threat Intelligence

This role involves analyzing security findings and communicating them effectively. Responsibilities include:

  • Analyzing identified vulnerabilities, evaluating associated business risks, and delivering clear, actionable technical reports to engineering and development teams.
  • Staying informed about emerging threats, zero-day vulnerabilities, and advanced offensive security techniques to maintain and enhance the organization's security posture.

Required Qualifications and Experience

Candidates must meet the following criteria:

  • Must be a Saudi national.
  • 1–2 years of hands-on experience in penetration testing, ethical hacking, or security research.
  • Demonstrated experience in web, mobile, and infrastructure penetration testing.
  • Practical experience with Active Directory attacks, gained in real-world or lab environments.
  • Proficiency with industry-standard tools such as Burp Suite, Metasploit, Nmap, Wireshark, Kali Linux, BloodHound, and Impacket.
  • A solid understanding of the OWASP Top 10, network protocols, and operating system internals (Windows/Linux).
  • Possession of one or more offensive security certifications, including OSCP, OSEP, eWPTX, eMAPT, or equivalent hands-on credentials.

Communication and Collaboration

Effective communication is essential for this role. The Penetration Tester must possess excellent communication skills, enabling them to articulate complex risks clearly to both technical and non-technical stakeholders.

Work Location and Type

This is a full-time position based in Riyadh.


Requirements

  • For Saudis Only
  • No experience required

Similar Jobs