Managed.sa is seeking a hands-on Penetration Tester to conduct security assessments, identify and validate vulnerabilities, and provide practical remediation recommendations across client environments.
The ideal candidate has strong offensive-security skills, practical testing experience, and the ability to prepare clear and professional technical reports.
Key Responsibilities- Conduct penetration testing across web applications, APIs, networks, infrastructure, and cloud environments.
- Perform manual and automated vulnerability assessments.
- Safely exploit identified vulnerabilities to assess their technical and business impact.
- Test authentication, authorization, session management, and application logic.
- Participate in red-team and adversary-simulation activities when required.
- Conduct source-code security reviews and identify insecure coding practices.
- Document findings with supporting evidence, risk ratings, and remediation recommendations.
- Present and explain technical findings to clients and internal stakeholders.
- Conduct retesting to verify that vulnerabilities have been properly remediated.
- Stay updated on emerging vulnerabilities, exploitation techniques, and offensive-security tools.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Security, or a related field.
- 2–3 years of practical experience in penetration testing or offensive security.
- Hands-on experience in web application and network penetration testing.
- Strong knowledge of vulnerability assessment and exploitation techniques.
- Good understanding of network protocols, including TCP/IP, DNS, and HTTP.
- Strong working knowledge of Linux and Windows environments.
- Strong understanding of web technologies, APIs, authentication mechanisms, and the OWASP Top 10.
- Experience with tools such as Burp Suite, Metasploit, Nmap, Wireshark, and Nessus.
- Scripting skills in Python, Bash, PowerShell, Ruby, or a similar language.
- Strong technical-reporting and communication skills.
- Ability to work full-time on-site in Riyadh.
- Cloud security assessments.
- Red-team operations.
- Source-code security reviews.
- Client-facing penetration-testing engagements.
One or more of the following certifications would be an advantage:
- Offensive Security Certified Professional (OSCP)
- Certified Ethical Hacker (CEH)
- GIAC Penetration Tester (GPEN)
- Offensive Security Experienced Penetration Tester (OSEP)
- Certified Red Team Professional (CRTP)
- Certified Red Team Operator (CRTO)
Skills Required
- Bachelor's degree in Cybersecurity, Computer Science, Information Security, or related field.
- 2-3 years practical experience in penetration testing or offensive security.
- Hands-on experience in web application and network penetration testing.
- Strong knowledge of vulnerability assessment and exploitation techniques.
- Good understanding of network protocols (TCP/IP, DNS, HTTP).
- Strong working knowledge of Linux and Windows environments.
- Strong understanding of web technologies, APIs, authentication mechanisms, and OWASP Top 10.
- Experience with tools such as Burp Suite, Metasploit, Nmap, Wireshark, and Nessus.
- Scripting skills in Python, Bash, PowerShell, Ruby, or a similar language.
- Strong technical-reporting and communication skills.
- Ability to work full-time on-site in Riyadh.
- Cloud security assessments.
- Red-team operations experience.
- Source-code security review experience.
- Client-facing penetration-testing engagements experience.
- Certifications such as OSCP, CEH, GPEN, OSEP, CRTP, or CRTO.
What We Do
Managed Services Company is a startup specializes in providing bespoke services in the field of Cyber Security. These services range from identifying threats and vulnerabilities to planning, designing and implementing the relevant technological, organizational and risk-based countermeasures. We supply vendor-independent security services through our consultants and a wide network of partnerships. It can therefore provide in-depth expertise in the most widely used security technologies on the market and select the most suitable solution for any given case. In addition, Managed Services company is a managed service provider specializing in cyber threat intelligence, brand protection solutions, and security-management for complex systems. Our portfolio includes security assessment, real-time management and monitoring of security systems. Managed security also has expertise in advanced technologies like Blockchain, Internet of Things, and Smart Cities. We help our customer to secure those technologies by developing the right strategies and manage their security.







