More jobs:
Information Security Engineer - VAPT
Job in
Riyadh, Riyadh Region, Saudi Arabia
Listed on 2026-05-31
Listing for:
tabby
Full Time
position Listed on 2026-05-31
Job specializations:
-
IT/Tech
Cybersecurity, IT Consultant
Job Description & How to Apply Below
We are thrilled to announce an opportunity for a skilled Information Security Engineer to join our team and play a role in enhancing our security measures by utilizing your abilities and deep knowledge of information security methodologies. Paying attention to details and efficiently solving problems will be crucial in ensuring the safety of Tabby’s systems. The role involves both operations and important implementation projects contributing to the growth and maintenance of our technology infrastructure.
Responsibilities- Penetration Testing – Perform Dynamic Application Security Testing (DAST) and Static Application Security Testing (SAST) for web, mobile, and API applications; plan and conduct infrastructure vulnerability assessment and penetration testing of systems, switches, servers, and more.
- Adversary Simulation – Red Teaming – Participate in sophisticated red‑team engagements emulating real‑world threat‑actor tactics, techniques, and procedures (TTPs) to assess the detection and response capabilities of the Blue Team Security Operations Center.
- Vulnerability & Application Security Analysis – Conduct both dynamic (DAST) and static (SAST) application security testing and perform systematic vulnerability assessments using automated tools combined with meticulous manual verification.
- Report Development – Produce actionable, high‑quality assessment reports that clearly articulate technical findings, business risk, and remediation strategies for both technical implementers and non‑technical executives.
- Control Evasion & Social Engineering – Conduct controlled offensive testing including breach and attack simulations (BAS) and targeted phishing campaigns to assess the resilience and bypassability of technical and human controls.
- Tool Development & Reporting – Develop and maintain custom scripts and tools to enhance offensive security capabilities and produce high‑quality, actionable reports detailing discovered threats and validated vulnerabilities on an ongoing basis.
- Security Awareness – Experience in conducting phishing simulations and other awareness exercises to evaluate employee susceptibility to social engineering attacks and provide targeted training to enhance resilience.
- Degree in Information Technology, Computer Science, Software Engineering, or related field.
- Knowledge of information technology security issues and approaches to manage information technology security in a fast‑paced fintech environment.
- Security qualification (good to have):
- Offensive Security Certified Professional (OSCP)
- GIAC Penetration Tester (GPEN)
- GIAC Web Application Penetration Tester (GWAPT)
- CREST Registered Penetration Tester (CRT)
- Excellent communication, influencing, and stakeholder‑management skills.
- 2–3 years of experience working across teams to deliver solutions and generate high levels of internal buy‑in.
- Experience of working in a culturally diverse environment.
- Knowledge of online technologies, payment methods, content delivery networks, REST APIs, microservices, and application development.
- Programming and scripting understanding (Bash, Python, etc.).
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×