Company logo hidden

Cybersecurity Consultant TVA

Unlock employer Riyadh, Saudi Arabia Direct to Company 1 hour ago · 29 Sep 2026

Financial

  • Estimate: $30k - $80k*
  • Zero income tax location

Accessibility

  • Office Only
  • Visa Provided

Requirements

  • Experience: Senior
  • English: Professional
  • Arabic: Preferred

Position

About the role
The Cybersecurity Consultant is a hands-on cybersecurity professional responsible for conducting vulnerability assessments, penetration testing activities, and security reviews across customer environments. This role works closely with customers, infrastructure teams, application owners, and security stakeholders to identify security weaknesses, validate risks, and provide practical remediation recommendations. The position combines technical security testing, customer engagement, and cybersecurity consultancy to help organizations strengthen their security posture, reduce risk, and improve compliance with security best practices and regulatory requirements.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

Key responsibilities:

  • Conduct vulnerability assessments and penetration tests across network, infrastructure, server, application, and cloud environments.
  • Perform internal and external network penetration testing within approved scopes and rules of engagement.
  • Conduct web application and API security assessments using recognized industry methodologies and frameworks.
  • Perform authenticated and unauthenticated vulnerability scanning using approved commercial and open-source security tools.
  • Validate vulnerabilities identified by automated tools and remove false positives before reporting.
  • Perform controlled exploitation activities to confirm vulnerability impact while minimizing operational risk.
  • Assess Windows, Linux, Active Directory, databases, network devices, and security infrastructure for security weaknesses.
  • Evaluate vulnerabilities based on exploitability, asset criticality, technical severity, and business impact.
  • Assign risk ratings using CVSS and applicable customer risk-classification methodologies.
  • Prepare technical assessment reports, executive summaries, and remediation recommendations.
  • Present assessment findings and risk remediation plans to technical and business stakeholders.
  • Conduct remediation workshops and provide technical guidance to customer teams.
  • Perform remediation validation and retesting activities.
  • Maintain assessment evidence, testing records, screenshots, tool outputs, and supporting documentation.
  • Support assessment planning activities, including scope definition, methodology selection, and rules of engagement.
  • Ensure all testing activities comply with approved authorization requirements and security testing procedures.
  • Support security consulting initiatives related to system hardening, vulnerability remediation, application security, and infrastructure security.
  • Assist with security assessments aligned to recognized frameworks including NCA ECC, SAMA CSF, ISO 27001, CIS Controls, and PCI DSS.
  • Contribute to continuous improvement of internal security testing methodologies, reporting templates, and knowledge repositories.
  • Support presales activities by providing technical input for customer proposals, assessment scope definitions, and effort estimates.
  • Perform any other cybersecurity consulting, vulnerability management, or penetration testing activities as required.

To thrive in this role, you need to have:

  • Strong understanding of vulnerability assessment and penetration testing methodologies.
  • Hands-on experience conducting network, infrastructure, web application, and API security testing.
  • Strong knowledge of TCP/IP networking, routing, switching, DNS, HTTP/HTTPS, VPNs, firewalls, and enterprise network services.
  • Good working knowledge of Windows, Linux, and Active Directory environments.
  • Familiarity with common attack techniques including privilege escalation, credential attacks, lateral movement, and Active Directory exploitation.
  • Strong understanding of OWASP Top 10, OWASP API Security Top 10, CVSS, CWE, and MITRE ATT&CK frameworks.
  • Practical experience using security assessment tools such as Burp Suite, Nmap, Nessus, Qualys, Rapid7, Metasploit, Wireshark, OWASP ZAP, and Kali Linux.
  • Ability to manually validate vulnerabilities and distinguish genuine findings from false positives.
  • Understanding of common security technologies including WAF, IDS/IPS, NAC, EDR, SIEM, and secure remote access solutions.
  • Basic scripting capabilities using Python, PowerShell, Bash, or similar languages.
  • Strong analytical and problem-solving skills with the ability to think from an attacker's perspective.
  • Strong report writing, evidence documentation, and presentation skills.
  • Ability to communicate technical vulnerabilities and risks to both technical and business stakeholders.
  • Ability to manage multiple customer engagements and work independently while maintaining high-quality deliverables.
  • Strong professional integrity and commitment to maintaining customer confidentiality.

Academic qualifications and certifications:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering, or a related technical discipline.
  • Equivalent practical experience may be considered where strong hands-on security testing expertise is demonstrated.
  • Preferred certifications include: OSCP, CREST CRT, GPEN, PNPT, eCPPT, CompTIA PenTest+, Burp Suite Certified Practitioner (BSCP), CEH / CEH Practical.

Required experience:

  • 5-7 years of cybersecurity, vulnerability assessment, penetration testing, or security consulting experience.
  • Minimum 3 years of recent hands-on vulnerability assessment and penetration testing experience.
  • Demonstrated experience conducting internal and external network penetration tests.
  • Hands-on experience performing web application and API security assessments.
  • Experience using vulnerability management platforms such as Tenable, Qualys, or Rapid7.
  • Strong working experience with tools including Burp Suite, Metasploit, Nmap, Kali Linux, and Wireshark.
  • Experience performing vulnerability validation, exploitation, remediation verification, and retesting.
  • Experience preparing professional technical security reports and presenting findings to customers and stakeholders.
  • Experience assessing Windows, Linux, Active Directory, network infrastructure, and enterprise environments.
  • Experience working directly with customer engagements within a cybersecurity consulting, systems integration, or professional services environment.
  • Experience with Active Directory security testing is strongly preferred.
  • Cloud, wireless, mobile application, container security, or red team experience is advantageous.
  • Exposure to NCA ECC, SAMA CSF, ISO 27001, PCI DSS, or related security frameworks is considered beneficial.
  • Strong written and verbal English communication skills; Arabic language capability is an advantage.

Workplace type:
On-site Working

Equal Opportunity Employer
This organization is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category.

Apply Direct

Jobs you might like   View all jobs

About IT Services and IT Consulting Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct