Cipher | سايڤر logo

Penetration Testing Specialist

Cipher | سايڤر • Riyadh, Riyadh Region, Saudi Arabia

remotefull-time
Posted Oct 7, 2026Apply by Apr 5, 2027
  • Role & seniority

    • Penetration Tester (hands-on), 2+ years experience; seniority level: mid/junior (based on 2+ years requirement)
  • Stack/tools

    • Testing areas: web, mobile, APIs, cloud, enterprise infrastructure

    • Security frameworks: OWASP, MITRE ATT&CK

    • Scripting: Python, PowerShell, Bash

    • Security testing methods: manual vuln discovery, source code review, business logic testing, red team simulations

    • Reporting: risk/business impact analysis; technical + executive presentations

    • Preferred certs: OSCP, eWPTX, CRTP (or equivalents)

  • Top 3 responsibilities

    • Plan and scope penetration tests with clients across systems/applications/environments

    • Perform manual penetration testing across web/mobile/API/cloud/infra, including advanced assessments (code review, business logic, red team)

    • Deliver and present actionable reports with vulnerabilities, risk/business impact, and remediation recommendations

  • Must-have skills

    • 2+ years hands-on pentesting/cybersecurity

    • Strong manual skills for vulnerability discovery

    • Ability to conduct adversary simulations and evaluate detection/response

    • Source code review and business logic testing

    • Clear communication: translate technical findings into business risks

    • Scripting proficiency (Python/PowerShell/Bash)

    • Working knowledge of OWASP and MITRE ATT&CK

  • Nice-to-haves

    • Relevant certifi

Full Description

‏⁦ Cipher | سايڤر is a cybersecurity solutions provider based in Riyadh, Saudi Arabia. The company's goal is to simplify the perception of complexity surrounding cybersecurity problems and solutions. Cipher's team of Saudi professionals and experts work tirelessly to develop, customize, and manage digital services and cybersecurity solutions to ensure their peace of mind. Our goal is to provide peace of mind to our clients by making digital security simple and efficient. ⁩

⁦⁩Key Responsibilities

⁦

  • Define scope and objectives of penetration tests with clients across systems, applications, and environments.

  • Perform manual penetration testing on web, mobile, APIs, cloud, and enterprise infrastructure.

  • Conduct advanced assessments including source code reviews, business logic testing, and red team simulations.

  • Simulate real-world attacks to evaluate detection and response capabilities.

  • Identify vulnerabilities, misconfigurations, and security gaps (onsite & remote).

  • Deliver clear, actionable technical reports with risk and business impact analysis.

  • Present findings to both technical teams and executive stakeholders.

  • Provide strategic recommendations to enhance security posture and reduce attack surface.

  • Stay up to date with emerging threats and frameworks (OWASP, MITRE ATT&CK).

⁦⁩Requirements

⁦• Minimum 2+ years of hands-on experience** in penetration testing and cybersecurity.

  • Bachelor’s degree in computer science, Cybersecurity, IT, or related field.

  • Certifications such as OSCP, eWPTX, CRTP (or equivalent) are highly preferred.

  • Strong experience across web, mobile, cloud, and infrastructure security testing.

  • Solid skills in manual vulnerability discovery, code review, and adversary simulation.

  • Proficiency in scripting (Python, PowerShell, Bash).

  • Strong analytical, problem-solving, and communication skills.

  • Ability to translate technical findings into business risks and recommendations.

Penetration TestingWeb Security TestingMobile Security TestingAPI Security TestingCloud Security TestingInfrastructure Security TestingSource Code ReviewBusiness Logic TestingRed Team SimulationsVulnerability DiscoveryAdversary SimulationPythonPowerShellBashOWASPMITRE ATT&CKmulti-location

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.