Description
The penetration testing team leader is responsible for leading ZainTECH’s licensed penetration testing capability within the cybersecurity advisory services practice. The role oversees the delivery of offensive security engagements across enterprise, government, and critical infrastructure customers throughout the MENA region, ensuring all testing activities are performed in accordance with industry best practices, recognized testing methodologies, and NCSC Jordan licensing requirements. The role combines hands-on technical leadership with team management, customer engagement, and service governance responsibilities.
Also responsible for managing penetration testing engagements, developing offensive security capabilities, assuring quality of deliverables, and strengthening customer security postures through actionable remediation guidance.
Responsibilities
Penetration testing engagement leadership
Lead and manage penetration testing engagements across infrastructure, web, wireless, and applications to a recognized methodology.
Define engagement scope, objectives, testing methodology, and rules of engagement.
Ensure all testing activities are conducted safely and within approved customer authorizations.
Manage engagement timelines, resources, and delivery quality.
Act as the primary technical lead throughout the penetration testing lifecycle.
Offensive security delivery
Perform advanced penetration testing activities using both manual and automated testing techniques.
Identify, validate, and demonstrate security vulnerabilities and attack paths.
Assess exploitability, business impact, and risk exposure associated with identified findings.
Conduct vulnerability assessments, penetration testing, security validation exercises, configuration reviews, and red team-style activities where applicable.
Support retesting activities following remediation efforts.
Quality assurance & technical review
Review and validate penetration testing findings prior to customer delivery.
Ensure reports are technically accurate, risk-rated appropriately, actionable and business-focused, and aligned with industry standards.
Review attack chains and exploitation methodologies to ensure consistency and quality.
Maintain testing methodologies aligned with OWASP Testing Guide, PTES, OSSTMM, NIST guidance, and industry best practices.
Customer engagement & advisory services
Present technical findings and executive summaries to customer stakeholders.
Conduct remediation workshops and technical review sessions.
Support customers in understanding security risks, threat exposure, and recommended remediation activities.
Provide strategic guidance on improving overall security posture.
Support presales activities, customer workshops, and cybersecurity assessments where required.
Team leadership & capability development
Lead, mentor, and develop penetration testers within the cybersecurity practice.
Conduct technical coaching, skills development programs, knowledge-sharing sessions, and offensive security training initiatives.
Support recruitment, onboarding, and capability development activities.
Ensure team certifications remain current and aligned with NCSC requirements.
Drive continuous improvement across offensive security methodologies and tooling.
Governance, compliance & service development
Ensure compliance with NCSC Jordan licensing requirements, internal security policies, customer contractual obligations, and regulatory requirements.
Enforce secure testing practices, confidentiality requirements, and evidence handling procedures.
Support service development initiatives to expand ZainTECH’s offensive security capabilities.
Maintain operational documentation, testing standards, and quality assurance processes.
Coordinate reporting and compliance activities required by NCSC and other regulatory stakeholders.
Our culture & code of conduct
At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our code of conduct, which serves as a guiding framework for responsible behavior across everything we do — from how we work with each other to how we engage with clients and partners globally.
Requirements
- Bachelor's degree (minimum) in information technology or a related field.
- Minimum 5 years experience in cybersecurity, including at least 5 completed penetration testing projects.
- At least one valid NCSC-approved penetration testing certification like CPENT, CEPT, OSCE, LPT, CPT, GPEN, or another internationally recognized, equivalent certification in the same field that is approved by the NCSC.
- Deep, hands-on offensive skills across network, web, wireless, and application testing, and command of recognized methodologies (OWASP, PTES, OSSTMM).
- Leadership: proven ability to lead a testing team and present to client executives.
- Advanced degree in cybersecurity or a related discipline is preferable.
- Advanced credentials such as OSCE, CPENT, LPT, or GPEN are preferable.
- Experience in red teaming or an MSSP/consultancy offensive practice is preferable.
الوصف
يُسْتَخْدَم قائد فريق اختبار الاختراق لقيادة قدرة اختبار الاختراق المصرَّحة من قبل ZainTECH ضمن ممارسة خدمات الاستشارات السيبرانية. يتولى الدور الإشراف على تقديم engagements الأمن الهجومي عبر المؤسسات، والحكومات، والعملاء في البنية التحتية الحيوية في جميع أنحاء منطقة الشرق الأوسط وشمال إفريقيا، مع التأكد من أن جميع أنشطة الاختبار تُنفَّذ وفق أفضل الممارسات الصناعية والمنهجيات المعترف بها ومتطلبات ترخيص NCSC الأردن. يجمع الدور بين القيادة الفنية العملية وإدارة الفريق وتفاعل العملاء وواجبات حوكمة الخدمة.
كما يتحمل مسؤولية إدارة علاقات اختبار الاختراق، وتطوير قدرات الأمن الهجومي، وضمان جودة المخرجات، وتعزيز وضع الأمان لدى العملاء من خلال توجيهات تصحيحية قابلة للتنفيذ.
المسؤوليات
قيادة ارتباط اختبار الاختراق
قيادة وإدارة ارتباطات اختبار الاختراق عبر البنية التحتية والويب واللاسلكي والتطبيقات وفق منهجية معترف بها.
تحديد نطاق الارتباط والأهداف ومنهجية الاختبار وقواعد الاشتباك.
ضمان أن جميع أنشطة الاختبار تُنفَّذ بشكل آمن وبناءً على تفويضات العملاء المعتمدة.
إدارة جداول الارتباطات والموارد والجودة في التسليم.
العمل كالرئيس الفني القيادي طوال دورة حياة اختبار الاختراق.
تسليم الأمن الهجومي
أداء أنشطة اختبار اختراق متقدمة باستخدام تقنيات الاختبار اليدوية والآلية على حد سواء.
تحديد وتوثيق وإظهار الثغرات الأمنية ومسارات الهجوم.
تقييم قابليّة الاستغلال والأثر التجاري وخطر التعرض المرتبط بالنتائج المحددة.
إجراء تقييمات الثغرات، واختبار الاختراق، وتمارين التحقق الأمني، ومراجعات التهيئة، وأنشطة نمط الفريق الأحمر كلما أمكن ذلك.
دعم إعادة الاختبار بعد جهود التصحيح.
ضمان الجودة والمراجعة الفنية
مراجعة وتوثيق نتائج اختبار الاختراق قبل تسليمها للعميل.
التأكد من أن التقارير دقيقة تقنيًا وتقييم المخاطر مُناسب وأنها قابلة للتنفيذ ومركزة على الأعمال ومتوافقة مع المعايير الصناعية.
مراجعة سلاسل الهجوم ومنهجيات الاستغلال لضمان الاتساق والجودة.
الحفاظ على منهجيات الاختبار متوافقة مع OWASP Testing Guide وPTES وOSSTMM وتوجيه NIST وأفضل الممارسات الصناعية.
التفاعل مع العملاء والخدمات الاستشارية
عرض النتائج الفنية وملخصات التنفيذ لأصحاب المصلحة من العملاء.
عقد ورش عمل التصحيح وجلسات المراجعة الفنية.
دعم العملاء في فهم مخاطر الأمن والتعرض للتهديدات وأنشطة التصحيح الموصى بها.
تقديم إرشاد استراتيجي لتحسين الوضع الأمني العام.
دعم أنشطة ما قبل البيع، وورش عمل العملاء، وتقييمات الأمن السيبراني حيثما لزم الأمر.
قيادة الفريق وتطوير القدرات
قيادة وتوجيه وتطوير المختبرين في مجال الأمن السيبراني ضمن الممارسة.
تنفيذ تدريبات تقنية وبرامج تطوير المهارات وجلسات تبادل المعرفة ومبادرات التدريب الأمني الهجومي.
دعم التوظيف، والتأهيل والأنشطة التطويرية للقدرات.
التأكد من بقاء شهادات الفريق محدثة ومتوافقة مع متطلبات NCSC.
قيادة التحسين المستمر عبر منهجيات وأدوات الأمن الهجومي.
الحوكمة والالتزام وتطوير الخدمة
ضمان الامتثال لمتطلبات ترخيص NCSC الأردن والسياسات الأمنية الداخلية والالتزامات العقدية مع العملاء والمتطلبات التنظيمية.
فرض ممارسات الاختبار الآمن، ومتطلبات السرية، وإجراءات التعامل مع الأدلة.
دعم مبادرات تطوير الخدمة لتوسيع قدرات الأمن الهجومي لـ ZainTECH.
الحفاظ على الوثائق التشغيلية ومعايير الاختبار وعمليات ضمان الجودة.
تنسيق التقارير وأنشطة الامتثال المطلوبة من NCSC وأصحاب المصلحة التنظيميين الآخرين.
ثقافتنا ومدونة السلوك الخاصة بنا
في ZainTECH، نفخر بثقافة مبنية على التعاون والابتكار والنزاهة التي لا تقبل المساومة. نبحث عن أفراد يشاركوننا هذه القيم ويراعون العميلية والتميز الأخلاقي. من المتوقع أن يلتزم جميع الموظفين بمدونة السلوك لدينا، التي تعمل كإطار توجيهي لسلوك مسؤول في كل ما نقوم به — من كيف نعمل مع بعضنا البعض إلى كيفية تعاملنا مع العملاء والشركاء عالمياً.
المتطلبات
- درجة البكالوريوس (على الأقل) في تكنولوجيا المعلومات أو مجال ذو صلة.
- خبرة لا تقل عن 5 سنوات في الأمن السيبراني، بما في ذلك ما لا يقل عن 5 مشاريع اختبار اختراق مكتملة.
- شهادة اختبار اختراق معتمدة من NCSC مثل CPENT، CEPT، OSCE، LPT، CPT، GPEN، أو شهادة معادلة دولية معترف بها في نفس المجال معتمدة من NCSC.
- مهارات هجومية عملية عميقة عبر اختبارات الشبكات والويب واللاسلكي والتطبيقات، وإتقان المنهجيات المعترف بها (OWASP، PTES، OSSTMM).
- القيادة: القدرة المثبتة على قيادة فريق اختبار وتقديم تقارير للمسؤولين التنفيذيين لدى العميل.
- درجة متقدمة في الأمن السيبراني أو تخصص ذي صلة مفضلة.
- شهادات متقدمة مثل OSCE، CPENT، LPT، أو GPEN مفضلة.
- خبرة في الاختبار الأحمر أو ممارسة هجومية لدى مزود خدمات أمنية أو استشارية مفضلة.