×
Register Here to Apply for Jobs or Post Jobs. X

Penetration Testing Resource Capabilities

Job in Riyadh, Riyadh Region, Saudi Arabia
Listing for: Secure Maximum Company
Full Time position
Listed on 2026-09-18
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 300000 - 480000 SAR Yearly SAR 300000.00 480000.00 YEAR
Job Description & How to Apply Below
Position: Penetration Testing Resource Capabilities Required

Minimum 8 years of dedicated hands‑on experience in Penetration Testing and Application Security The resource must have spent the last 4 years performing penetration testing activities within the Banking and Financial sectors industry Proven experience in supporting and assessing Digital RFCs including internet banking mobile banking APIs digital channels payment systems and customer-facing applications Experience managing the full penetration testing lifecycle including planning execution reporting remediation validation and re-testing Experience working closely with project teams developers system owners and change management processes to support RFC security reviews and approvals Ability to handle multiple Digital RFC assessments concurrently and provide timely risk-based recommendations

strong Technical Capabilities strong
  • Web Application Penetration Testing
  • Mobile Application Security Testing
  • iOS
  • Android
  • API Security Testing
  • Network Penetration Testing
  • Internal
  • External
  • Authentication and Access Control Assessments
  • Vulnerability Assessment and Validation
  • Secure Configuration Reviews
  • Source Code Security Review
  • SAST
  • Dynamic Application Security Testing
  • DAST
  • Manual Exploitation and Attack Simulation
  • Security Architecture and Design Reviews
  • Threat Modeling and Attack Surface Analysis
  • Remediation Verification and Retesting

Strong knowledge of OWASP Top 10 (Open Worldwide Application Security Project Top 10).Strong knowledge of OWASP API Security Top 10 (Open Worldwide Application Security Project API Security Top 10). Strong knowledge of MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework. Strong knowledge of CWE (Common Weakness Enumeration). Strong understanding of SSDLC (Secure Software Development Lifecycle). Experience assessing applications and digital platforms against SAMA regulatory requirements and banking security best practices.

Extensive experience assessing digital banking platforms, financial applications, and payment-related systems. Ability to perform risk assessments and provide practical security recommendations to support Digital RFC approval decisions.

Certifications (Preferred):
  • OSCP – Offensive Security Certified Professional
  • OSWE – Offensive Security Web Expert
  • OSEP – Offensive Security Experienced Penetration Tester
  • GPEN – GIAC Penetration Tester
  • GWAPT – GIAC Web Application Penetration Tester
  • GMOB – GIAC Mobile Device Security Analyst
  • CEH – Certified Ethical Hacker
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary