Company logo hidden

Consultant – Manager| Cyber Operate | Penetration Tester | KSA

Unlock employer Saudi Arabia Direct to Company 1 hour ago · 08 Oct 2026

Financial

  • Estimate: $30k - $80k*
  • Zero income tax location

Accessibility

  • Visa Provided

Requirements

  • Experience: Intermediate
  • English: Professional
  • Arabic: Preferred

Position

Location
Riyadh

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

About the Role
During your tenure as a Consultant – Manager, you will demonstrate and develop your capabilities in the following areas:

Plan and Scope Engagements

  • Agree on scope, objectives, rules of engagement and test windows with system owners, and obtain written authorization before any testing.
  • Choose the right approach for each target: black-box, grey-box or white-box, external or internal, announced or unannounced.
  • Follow a defined methodology (NIST SP 800-115, PTES, OWASP) and keep testing safe for live, guest-facing services.

Conduct Penetration Tests

  • Web applications and APIs: Test authentication, authorization, business logic, injection, session handling, and API security, following the OWASP Testing Guide and ASVS.
  • Mobile applications: Test iOS and Android apps and their back-ends following OWASP MASTG.
  • Internal and External Networks: Test perimeter exposure, internal segmentation, lateral movement, and privilege escalation.
  • Active Directory and Identity: Test AD and Entra ID attack paths, Kerberos weaknesses, privilege misconfigurations, and credential exposure.
  • Cloud Environments: Test Azure, AWS, and GCP for misconfigurations, excessive permissions, and exposed services.
  • Wireless and Physical: Test corporate and guest Wi-Fi and, where authorized, physical access controls.
  • Social Engineering: Run authorized phishing and pretexting exercises with the Awareness team.

Run Red and Purple Team Exercises (Senior)

  • Plan and lead objective-based red team exercises that emulate realistic threat actors, mapped to MITRE ATT&CK.
  • Run purple team sessions with the SOC to test and improve detection and response.

Report and Drive Fixes

  • Write clear, risk-rated reports with evidence, attack narratives and practical remediation steps, plus a short executive summary in plain language.
  • Brief technical teams and management on results, and explain business impact without exaggeration.
  • Retest fixes, confirm closure, and pass validated findings to Vulnerability Management and Risk for tracking.
  • Build reusable test cases, scripts and checklists to make testing faster and more consistent.

Leadership Capabilities

  • Builds own understanding of our purpose and values; explores opportunities for impact.
  • Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
  • Understands expectations and demonstrates personal accountability for keeping performance on track.
  • Actively focuses on developing effective communication and relationship-building skills.
  • Understands how their daily work contributes to the priorities of the team and the business.

Qualifications

  • Years of Experience: 2-7 total years.
  • Education: Bachelor's in cybersecurity, computer science or a related field, or equivalent practical experience.
  • Hands-on experience delivering penetration tests for real organizations, not only labs or CTFs.
  • Strong proficiency with core tools: Burp Suite, Nmap, Metasploit, BloodHound, and common post-exploitation frameworks.
  • Scripting experience in Python, Bash, or PowerShell.
  • Strong report writing skills in English.
  • A recognized hands-on offensive certification (e.g., OSCP) for Mid and Senior levels.
  • Red team experience with C2 frameworks (e.g., Cobalt Strike, Sliver, Mythic) is preferred.
  • Mobile application and cloud penetration testing experience is preferred.
  • Exploit development or code review skills are preferred.
  • Experience testing hospitality, payments, smart-city, or OT-adjacent environments is preferred.
  • Arabic language skills are preferred.
  • At least one preferred: OSCP, CREST CRT/CCT, GPEN. Also valued: OSEP, OSWE, CRTO, GWAPT, eCPPT/eWPT, PNPT. CEH is accepted at Junior level only.
  • Frameworks & Standards: NCA ECC-2:2024 (penetration testing), NIST SP 800-115, PTES, OWASP WSTG / ASVS / MASTG, MITRE ATT&CK, CREST methodology.
Apply Direct

Jobs you might like   View all jobs

About Business Consulting and Services Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct