Information Security Engineer - VAPT (Saudi National)

Tabby | تابي


Date: 11 hours ago
City: Riyadh
Contract type: Full time

Department: InfoSec Monitoring

Location: KSA

Description

We are thrilled to announce an opportunity for a skilled Information Security Engineer to join our team and play a role in enhancing our security measures by utilizing your abilities and deep knowledge of information security methodologies. Paying attention to details and efficiently solving problems will be crucial in ensuring the safety of Tabby’s systems.

The role you will be involved in both operations and important implementation projects contributing to the growth and maintenance of our technology infrastructure. If you have a passion for cybersecurity, possess technical skills and aspire to make a significant impact we strongly encourage you to apply and become an essential part of our dedicated cybersecurity team.

Key Responsibilities

  • Penetration Testing: Perform Dynamic Application Security Testing (DAST) and Static Application Security Testing (SAST) for Web, Mobile, and API applications. Plan and conduct Infrastructure Vulnerability Assessment and Penetration Testing of systems, switches, servers, and more.
  • Adversary Simulation (Red Teaming): Participate in sophisticated Red Team
  • engagements, emulating real-world threat actor Tactics, Techniques, and Procedures (TTPs) to assess the detection and response capabilities of the Blue Team/SOC.
  • Vulnerability & Application Security Analysis: Conduct both Dynamic (DAST) and Static (SAST) Application Security Testing, and perform systematic vulnerability assessments using automated tools combined with meticulous manual verification.
  • Report Development: Produce actionable, high-quality assessment reports that clearly articulate technical findings, business risk, and remediation strategies for both technical implementers and non-technical executives.
  • Control Evasion & Social Engineering: Conduct controlled offensive testing, including Breach & Attack Simulations (BAS) and targeted phishing campaigns, to assess the resilience and bypassability of technical and human controls.
  • Tool Development & Reporting: Develop and maintain custom scripts and tools to enhance offensive security capabilities, and produce high-quality, actionable reports detailing discovered threats and validated vulnerabilities on an ongoing basis.
  • Security Awareness: Experience in conducting phishing simulations and other
  • awareness exercises to evaluate employee susceptibility to social engineering attacks and provide targeted training to enhance resilience.

Skills, Knowledge and Expertise

  • Degree in Information Technology, Computer Science, Software Engineering, or related field
  • Knowledge of Information Technology security issues and approaches to manage
  • Information Technology security with a fast paced Fintech environment.
  • Security Qualification Good to have: Offensive Security Certified Professional (OSCP), GIAC Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), CREST Registered Penetration Tester (CRT) or equivalent.
  • Excellent communication, influencing and stakeholder management skills
  • 2-3 Experience of working across teams to deliver solutions and generate high levels of internal buy-in
  • Experience of working in a culturally diverse environment
  • Knowledge of online technologies, payment methods, content delivery networks, REST APIs, microservices, and application development.
  • Programming and scripting understanding (Bash, Python etc.)

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.

Post a resume

Similar jobs

Senior Foreman – Mechanical Construction

AL-AYUNI Investment and Contracting Company, Riyadh
1 day ago
Job SummaryThe Senior Foreman – Mechanical Construction is responsible for supervising, coordinating, and executing mechanical construction activities at site. The role ensures that work is completed safely, on schedule, within budget, and in compliance with project specifications, quality standards, and company policies. The Senior Foreman leads foremen and skilled workers while coordinating with engineers, project managers, and subcontractors.Key ResponsibilitiesSite Supervision...

Sr. Contract Administrator

AECOM, Riyadh
1 day ago
Company Description Work with Us. Change the World. At AECOM, we're delivering a better world. Whether improving your commute, keeping the lights on, providing access to clean water, or transforming skylines, our work helps people and communities thrive. We are the world's trusted infrastructure consulting firm, partnering with clients to solve the worldâs most complex challenges and build legacies for...

Security Manager

Accenture Middle East, Riyadh
3 days ago
Job Title: Cyber Security Strategy ManagerLocation: Riyadh, Saudi ArabiaAbout Accenture: Accenture is a global professional services company with leading capabilities in digital, cloud and security. Combining unmatched experience and specialized skills across more than 40 industries, we offer Strategy and Consulting, Interactive, Technology and Operations services—all powered by the world’s largest network of Advanced Technology and Intelligent Operations centers. Our...