Cyber security Engineer
✨ About This Role
Role Overview
Execute and lead offensive security engagements — from vulnerability assessment and penetration testing (VAPT) across web, mobile, network, API, cloud, and IoT, through to full adversary emulation and red teaming. Simulate real-world attacks to identify vulnerabilities before they can be exploited, deliver clear and actionable reporting,and work directly with client teams to drive remediation. This is a hands-on, client-facing career ladder spanning tester to principal.
Key Responsibilities
• Plan and execute VAPT engagements across web applications, mobile apps (Android & iOS), network
infrastructure, APIs, thick-client apps, Wi-Fi, cloud, and IoT.
• Perform manual and automated testing aligned to OWASP Top 10 and recognised industry frameworks.
• Identify, validate, and safely exploit vulnerabilities — SQL injection, XSS, RCE, authentication / access-control bypasses, and business logic flaws.
• Develop Proofs of Concept (PoCs) that clearly demonstrate technical impact and business risk.
• Produce detailed reports covering findings, business impact, CVSS scores, CWE references, and prioritised remediation guidance.
• Design engagement approaches aligned to regulatory frameworks including SAMA and CBB cybersecurity guidelines (senior level).
• Lead adversary emulation, red team, and purple team / RTBT exercises, and research emerging TTPs and tooling (principal level).
• Prepare project plans, run kickoff meetings, and coordinate with stakeholders across the engagement
lifecycle.
• Collaborate with client development teams to reproduce, explain, and retest issues, and support secure
coding practices.
• Support pre-sales with scoping, effort estimation, and technical guidance; mentor junior testers.
Required Qualifications
• 4+ years of hands-on penetration testing / VAPT experience (6+ for Senior, 10+ for Principal).
• Strong practical knowledge of web, mobile, network, and API security testing.
• Solid understanding of OWASP Top 10, CVSS scoring, and CWE classification.
• Proficiency with tools such as Burp Suite, Nmap, Metasploit, Nessus, Nikto, sqlmap, MobSF, and Frida.
Why You'll love working here:
Ready to lock in? 🔥
This opportunity is about to be someone else's W. Don't sleep on it! 💯