Location
Riyadh
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
About the Role
As a Consultant - Manager, you will be at the forefront of vulnerability assessments, leveraging your expertise to evaluate and enhance security across various systems. Your responsibilities will encompass conducting comprehensive assessments, managing scanning tools, driving remediation efforts, and developing a robust vulnerability management program. You will work collaboratively with multiple teams to ensure risk is effectively managed, and your findings will be critical in shaping security strategies.
Responsibilities
-
Conduct Vulnerability Assessments:
- Plan and run authenticated and unauthenticated assessments across various networks (corporate, data-center, DMZ, wireless, etc.).
- Evaluate cloud platforms such as Azure, AWS, and GCP considering workloads and configurations against CIS benchmarks.
- Assess systems including Windows and Linux servers, endpoints, databases, and security devices.
- Test web applications, APIs, and mobile app back-ends with authenticated DAST scanning.
- Produce clear assessment reports that include risk-rated findings, evidence, and practical remediation steps.
-
Run Tooling and Coverage:
- Operate and tune scanning platforms (e.g., Tenable, Qualys, Rapid7) including policies and schedules.
- Align scan coverage with asset inventories and mitigate blind spots.
- Work with the OT team to assess industrial and building systems.
-
Prioritize What Matters:
- Use metrics such as CVSS, EPSS, and threat intelligence to prioritize vulnerabilities.
- Validate critical findings and track emerging threats.
-
Drive Remediation:
- Collaborate with IT, cloud, and application owners to agree on remediation plans.
- Verify fixes by rescanning and manage the exception process with justification.
-
Set up the Programme and Report on It:
- Define policies and procedures for vulnerability management aligned with NCA ECC.
- Build dashboards and KPIs to report on SLA compliance and risk trends.
- Automate processes for scanning, ticketing, and reporting.
Leadership Capabilities
- Builds understanding of purpose and values; explores opportunities for impact.
- Demonstrates commitment to personal learning; acts as a brand ambassador.
- Maintains responsibility for performance and supports team priorities.
- Develops effective communication and relationship-building skills.
Qualifications
- Experience:
- 4-8 years of hands-on vulnerability assessment and management experience.
- Education:
- Bachelor’s degree in IT, cybersecurity, or a related field.
- Technical Skills:
- Practical experience with enterprise scanners (Tenable, Qualys, Rapid7).
- Experience in assessing on-premise networks and systems, cloud platforms, and web applications.
- Solid fundamental knowledge of Windows, Linux, networks, and cloud environments.
- Familiarity with NCA ECC vulnerability management requirements.
- Scripting in Python or PowerShell preferred; automation experience is a plus.
- Additional Preferred Skills:
- Experience with ITSM tools (ServiceNow, Jira).
- Understanding of cloud security (CSPM) or container scanning tools.
- Arabic language proficiency is preferred.
- At least one certification such as CompTIA Security+, CySA+, or CEH; valued certifications include GIAC (GSEC, GCIH).
- Frameworks and Standards Knowledge:
- Familiarity with NCA ECC-2:2024, NCA CCC, NIST SP 800-40, NIST SP 800-115, NIST CSF 2.0, ISO/IEC 27001:2022, CIS Controls v8, and CIS Benchmark.
Benefits
- Opportunity to work at a prestigious firm recognized as a top employer.
- Work in a dynamic environment focused on professional development and career growth.
- Collaborate with talented professionals dedicated to making a positive impact.