Penetration Tester

🗓️ Posted 2026-08-10 Riyadh, Riyadh, Saudi Arabia Full-time Hybrid ICT

Company shared salary

NA

Market rate

SAR 18,000–SAR 25,000/mo (SAR 216,000–SAR 300,000/yr)

Based on similar roles (title + domain + location).

About the Company

Managed.sa is seeking a hands-on Penetration Tester to conduct security assessments, identify and validate vulnerabilities, and provide practical remediation recommendations across client environments. The ideal candidate has strong offensive-security skills, practical testing experience, and the ability to prepare clear and professional technical reports.

Responsibilities

  • Conduct penetration testing across web applications, APIs, networks, infrastructure, and cloud environments
  • Perform manual and automated vulnerability assessments
  • Safely exploit identified vulnerabilities to assess their technical and business impact
  • Test authentication, authorization, session management, and application logic
  • Participate in red-team and adversary-simulation activities when required
  • Conduct source-code security reviews and identify insecure coding practices
  • Document findings with supporting evidence, risk ratings, and remediation recommendations
  • Present and explain technical findings to clients and internal stakeholders
  • Conduct retesting to verify that vulnerabilities have been properly remediated
  • Stay updated on emerging vulnerabilities, exploitation techniques, and offensive-security tools

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Security, or a related field
  • 2-3 years of practical experience in penetration testing or offensive security
  • Hands-on experience in web application and network penetration testing
  • Strong knowledge of vulnerability assessment and exploitation techniques
  • Good understanding of network protocols, including TCP/IP, DNS, and HTTP
  • Strong working knowledge of Linux and Windows environments
  • Strong understanding of web technologies, APIs, authentication mechanisms, and the OWASP Top 10
  • Experience with tools such as Burp Suite, Metasploit, Nmap, Wireshark, and Nessus
  • Scripting skills in Python, Bash, PowerShell, Ruby, or a similar language
  • Strong technical-reporting and communication skills
  • Ability to work full-time on-site in Riyadh
  • Cloud security assessments
  • Red-team operations
  • Source-code security reviews
  • Client-facing penetration-testing engagements
  • Offensive Security Certified Professional (OSCP)
  • Certified Ethical Hacker (CEH)
  • GIAC Penetration Tester (GPEN)
  • Offensive Security Experienced Penetration Tester (OSEP)
  • Certified Red Team Professional (CRTP)
  • Certified Red Team Operator (CRTO)