Penetration Testing Resource Capabilities
Listed on 2026-09-18
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Minimum 8 years of dedicated hands‑on experience in Penetration Testing and Application Security The resource must have spent the last 4 years performing penetration testing activities within the Banking and Financial sectors industry Proven experience in supporting and assessing Digital RFCs including internet banking mobile banking APIs digital channels payment systems and customer-facing applications Experience managing the full penetration testing lifecycle including planning execution reporting remediation validation and re-testing Experience working closely with project teams developers system owners and change management processes to support RFC security reviews and approvals Ability to handle multiple Digital RFC assessments concurrently and provide timely risk-based recommendations
strong Technical Capabilities strong- Web Application Penetration Testing
- Mobile Application Security Testing
- iOS
- Android
- API Security Testing
- Network Penetration Testing
- Internal
- External
- Authentication and Access Control Assessments
- Vulnerability Assessment and Validation
- Secure Configuration Reviews
- Source Code Security Review
- SAST
- Dynamic Application Security Testing
- DAST
- Manual Exploitation and Attack Simulation
- Security Architecture and Design Reviews
- Threat Modeling and Attack Surface Analysis
- Remediation Verification and Retesting
Strong knowledge of OWASP Top 10 (Open Worldwide Application Security Project Top 10).Strong knowledge of OWASP API Security Top 10 (Open Worldwide Application Security Project API Security Top 10). Strong knowledge of MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework. Strong knowledge of CWE (Common Weakness Enumeration). Strong understanding of SSDLC (Secure Software Development Lifecycle). Experience assessing applications and digital platforms against SAMA regulatory requirements and banking security best practices.
Extensive experience assessing digital banking platforms, financial applications, and payment-related systems. Ability to perform risk assessments and provide practical security recommendations to support Digital RFC approval decisions.
- OSCP – Offensive Security Certified Professional
- OSWE – Offensive Security Web Expert
- OSEP – Offensive Security Experienced Penetration Tester
- GPEN – GIAC Penetration Tester
- GWAPT – GIAC Web Application Penetration Tester
- GMOB – GIAC Mobile Device Security Analyst
- CEH – Certified Ethical Hacker
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).