Job Description
Roles & Responsibilities
The Penetration Tester is responsible for conducting authorized security assessments across enterprise, government, and critical infrastructure environments to identify, validate, and report security vulnerabilities. As part of ZainTECH's Cybersecurity practice, the role supports the delivery of penetration testing engagements across infrastructure, web, wireless and applications. The Penetration Tester performs hands-on offensive security testing, validates exploitability of identified vulnerabilities, and delivers clear, actionable remediation guidance to customers. The role works closely with cybersecurity consultants, advisory teams, and customer stakeholders to help strengthen security posture and reduce organizational risk across the MENA region.
Responsibilities:
Penetration Testing & Security Assessments
- Conduct penetration testing engagements across: External and internal networks, Web applications, APIs and web services, Wireless environments, Infrastructure and supporting systems
- Execute testing activities in accordance with approved methodologies, industry standards, and customer-defined rules of engagement
- Identify, validate, and safely demonstrate security vulnerabilities and attack paths
- Assess exploitability, business impact, and risk exposure associated with identified findings
- Perform security validation and retesting activities following remediation efforts
Vulnerability Analysis & Reporting
- Analyze identified vulnerabilities and security weaknesses to determine potential business impact
- Develop detailed technical findings and remediation recommendations
- Produce high-quality penetration testing reports that clearly communicate: Vulnerability details, Risk ratings, Attack scenarios, Business impact, Remediation guidance
- Ensure findings are reproducible, technically accurate, and aligned with industry best practices
Testing Governance & Compliance
- Conduct all testing activities within approved scope and rules of engagement
- Ensure customer systems, data, and environments are protected throughout testing activities
- Maintain strict confidentiality of customer information and testing results
- Adhere to applicable regulatory, contractual, and legal requirements governing penetration testing engagements
- Support compliance with NCSC Jordan licensing requirements and operational standards
Technical Research & Continuous Improvement
- Stay current on: Emerging threats, Attack techniques, Vulnerability trends, Security research, Offensive security tools and methodologies
- Contribute to the enhancement of penetration testing methodologies, tools, and processes
- Participate in internal knowledge-sharing initiatives and technical training programs
- Support continuous improvement activities within the Cybersecurity Advisory Services practice
Cross-Functional Collaboration
- Collaborate with: Penetration Testing Team Leaders, Cybersecurity Consultants, Security Architects, Managed Security Services teams
- Support remediation discussions and knowledge transfer activities where required
- Contribute technical expertise during customer engagements and security assessments
Desired Candidate Profile
Bachelor's degree or Intermediate Diploma from a recognized university or academic institution
Minimum 3 years of practical cybersecurity experience
Demonstrated participation in at least two completed penetration testing projects
Possession of at least one valid NCSC-approved penetration testing certification, including:
- Certified Ethical Hacker (CEH)
- CREST Registered Penetration Tester (CRT)
- Offensive Security Wireless Professional (OSWP)
- Offensive Security Certified Professional (OSCP)
- CompTIA PenTest+
- or another NCSC-approved equivalent certification
Hands-on offensive skills across network, web, and application testing, with command of common tooling (Burp Suite, Nmap, Metasploit) and scripting
وصف العمل
الأدوار والمسؤوليات
المختبر الاختراقي مسؤول عن إجراء تقييمات أمنيّة مفوّضة عبر البيئات المؤسسيّة والحكوميّة والبنى التحتية الحيوية لتحديد الثغرات الأمنية والتحقق منها وتوثيقها وتقديم تقارير عنها. كجزء من ممارسة الأمن السيبراني في زينتك، يدعم الدور تنفيذ مهام اختبارات الاختراق عبر البنية التحتية والويب والشبكات اللاسلكية والتطبيقات. يقوم المختبر الاختراقي بإجراء اختبارات أمنيّة هجومية عملية، والتحقق من قابلية الاستغلال للثغرات المحددة، وتقديم إرشادات إصلاح واضحة وقابلة للتنفيذ للعملاء. يعمل الدور عن كثب مع مستشارين الأمن السيبراني وفرق الاستشارة وأصحاب المصلحة من العملاء للمساعدة في تعزيز وضع الأمان وتقليل المخاطر التنظيمية عبر منطقة الشرق الأوسط وشمال أفريقيا.
المسؤوليات:
اختبار الاختراق وتقييمات الأمان
- إجراء أنشطة اختبار الاختراق عبر: الشبكات الخارجية والداخلية، تطبيقات الويب، واجهات برمجة التطبيقات وخدمات الويب، البيئات اللاسلكية، البنية التحتية والأنظمة الداعمة
- تنفيذ أنشطة الاختبار وفق منهجيات معتمدة ومعايير صناعية وقواعد الاشتباك المحددة من قبل العميل
- تحديد، والتحقق من، وعرض ثغرات أمنيّة ومسارات هجوم بشكل آمن
- تقييم قابلية الاستغلال والتأثير التجاري وخطر التعرض المرتبط بالنتائج المحددة
- إجراء أنشطة التحقق من الأمان وإعادة الاختبار بعد جهود الإصلاح
تحليل الثغرات والتقارير
- تحليل الثغرات ونقاط الضعف الأمنيّة لتحديد التأثير التجاري المحتمل
- تطوير نتائج فنية تفصيلية وتوصيات الإصلاح
- إنتاج تقارير اختبار اختراق عالية الجودة توضح بوضوح: تفاصيل الثغرة، تقييمات المخاطر، سيناريوهات الهجوم، التأثير التجاري، إرشادات الإصلاح
- التأكد من أن النتائج قابلة لإعادة الإنتاج دقيقة فنيًا ومتوافقة مع أفضل الممارسات الصناعيّة
الحوكمة والامتثال في الاختبار
- إجراء جميع الأنشطة ضمن النطاق المقبول وقواعد الاشتباك المعتمدة
- ضمان حماية أنظمة البيانات وبيئات العملاء طوال أنشطة الاختبار
- الحفاظ على سرّيّة معلومات العميل ونتائج الاختبار بشكل صارم
- الالتزام بمتطلبات التنظيمية والعقود والقوانين المعمول بها التي تحكم مهام اختبار الاختراق
- دعم الامتثال بمتطلبات ترخيص NCSC الأردن ومعايير التشغيل
الأبحاث الفنية والتحسين المستمر
- البقاء على اطلاع بالتهديدات الناشئة وتقنيات الهجوم واتجاهات الثغرات والأبحاث الأمنية وأدوات وأساليب الأمن الهجومي
- المساهمة في تعزيز منهجيات وأدوات وعمليات اختبار الاختراق
- المشاركة في مبادرات تبادل المعرفة والتدريب الفني الداخلية
- دعم أنشطة التحسين المستمر ضمن ممارسة خدمات الاستشارات الأمن السيبراني
التعاون عبر الوظائف
- التعاون مع: قادة فرق اختبار الاختراق، مستشارو الأمن السيبراني، مهندسو الأمن، فرق خدمات الأمن المدارة
- دعم مناقشات الإصلاح وأنشطة نقل المعرفة عند الحاجة
- المساهمة بخبرة تقنية أثناء ارتباطات العملاء وتقييمات الأمن
الملف المرغوب فيه للمرشح
درجة البكالوريوس أو Diploma متوسط من جامعة أو مؤسسة أكاديمية معترف بها
خبرة عملية لا تقل عن 3 سنوات في الأمن السيبراني
مشاركة مثبتة في مشروعين على الأقل لاختبار الاختراق
إمتلاك واحد على الأقل من شهادات اختبار الاختراق المعتمدة من NCSC، بما في ذلك:
- مختبر أخلاقي معتمد (CEH)
- مختبر اختراق مسجل من CREST (CRT)
- أخصائي شبكات وايرلس هجومي من Offensive Security (OSWP)
- محترف معتمد هجومي من Offensive Security (OSCP)
- PenTest+ من CompTIA
- أو شهادة مكافئة أخرى معتمدة من NCSC
مهارات عملية هجومية عبر الشبكات والويب والاختبار التطبيقي، مع قدرة على استخدام الأدوات الشائعة (Burp Suite, Nmap, Metasploit) والبرمجة النصية