Description
The penetration testing team leader is responsible for leading ZainTECH’s licensed penetration testing capability within the cybersecurity advisory services practice. The role oversees the delivery of offensive security engagements across enterprise, government, and critical infrastructure customers throughout the MENA region, ensuring all testing activities are performed in accordance with industry best practices, recognized testing methodologies, and NCSC Jordan licensing requirements. The role combines hands-on technical leadership with team management, customer engagement, and service governance responsibilities.
Also responsible for managing penetration testing engagements, developing offensive security capabilities, assuring quality of deliverables, and strengthening customer security postures through actionable remediation guidance.
Responsibilities
Penetration testing engagement leadership
Lead and manage penetration testing engagements across infrastructure, web, wireless, and applications to a recognized methodology.
Define engagement scope, objectives, testing methodology, and rules of engagement.
Ensure all testing activities are conducted safely and within approved customer authorizations.
Manage engagement timelines, resources, and delivery quality.
Act as the primary technical lead throughout the penetration testing lifecycle.
Offensive security delivery
Perform advanced penetration testing activities using both manual and automated testing techniques.
Identify, validate, and demonstrate security vulnerabilities and attack paths.
Assess exploitability, business impact, and risk exposure associated with identified findings.
Conduct vulnerability assessments, penetration testing, security validation exercises, configuration reviews, and red team-style activities where applicable.
Support retesting activities following remediation efforts.
Quality assurance & technical review
Review and validate penetration testing findings prior to customer delivery.
Ensure reports are technically accurate, risk-rated appropriately, actionable and business-focused, and aligned with industry standards.
Review attack chains and exploitation methodologies to ensure consistency and quality.
Maintain testing methodologies aligned with OWASP Testing Guide, PTES, OSSTMM, NIST guidance, and industry best practices.
Customer engagement & advisory services
Present technical findings and executive summaries to customer stakeholders.
Conduct remediation workshops and technical review sessions.
Support customers in understanding security risks, threat exposure, and recommended remediation activities.
Provide strategic guidance on improving overall security posture.
Support presales activities, customer workshops, and cybersecurity assessments where required.
Team leadership & capability development
Lead, mentor, and develop penetration testers within the cybersecurity practice.
Conduct technical coaching, skills development programs, knowledge-sharing sessions, and offensive security training initiatives.
Support recruitment, onboarding, and capability development activities.
Ensure team certifications remain current and aligned with NCSC requirements.
Drive continuous improvement across offensive security methodologies and tooling.
Governance, compliance & service development
Ensure compliance with NCSC Jordan licensing requirements, internal security policies, customer contractual obligations, and regulatory requirements.
Enforce secure testing practices, confidentiality requirements, and evidence handling procedures.
Support service development initiatives to expand ZainTECH’s offensive security capabilities.
Maintain operational documentation, testing standards, and quality assurance processes.
Coordinate reporting and compliance activities required by NCSC and other regulatory stakeholders.
Our culture & code of conduct
At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our code of conduct, which serves as a guiding framework for responsible behavior across everything we do — from how we work with each other to how we engage with clients and partners globally.
Requirements
- Bachelor's degree (minimum) in information technology or a related field.
- Minimum 5 years experience in cybersecurity, including at least 5 completed penetration testing projects.
- At least one valid NCSC-approved penetration testing certification like CPENT, CEPT, OSCE, LPT, CPT, GPEN, or another internationally recognized, equivalent certification in the same field that is approved by the NCSC.
- Deep, hands-on offensive skills across network, web, wireless, and application testing, and command of recognized methodologies (OWASP, PTES, OSSTMM).
- Leadership: proven ability to lead a testing team and present to client executives.
- Advanced degree in cybersecurity or a related discipline is preferable.
- Advanced credentials such as OSCE, CPENT, LPT, or GPEN are preferable.
- Experience in red teaming or an MSSP/consultancy offensive practice is preferable.
الوصف
يكون قائد فريق اختبار الاختراق مسؤولاً عن قيادة قدرة اختبار الاختراق المعتمدة من زينتك داخل ممارسة خدمات الاستشارات السيبرانية. تتولى هذه الوظيفة الإشراف على تقديم إجراءات الأمن الهجومية عبر عملاء المؤسسات والحكومة والبنية التحتية الحيوية في منطقة الشرق الأوسط وشمال أفريقيا، مع التأكد من أن جميع أنشطة الاختبار تتم وفق أفضل الممارسات الصناعية والمنهجيات المعترف بها ومتطلبات ترخيص NCSC الأردن. تجمع الوظيفة بين القيادة التقنية العملية وإدارة الفريق والتفاعل مع العملاء ومسؤوليات حوكمة الخدمة.
كما أنها مسؤولة عن إدارة أعمال اختبار الاختراق وتطوير قدرات الأمن الهجومي وضمان جودة المخرجات وتقوية وضع أمان العملاء من خلال توجيهات تصحيح قابلة للتنفيذ.
المسؤوليات
قيادة مشاركة اختبار الاختراق
قيادة وإدارة مشاركات اختبار الاختراق عبر البنية التحتية والويب واللاسلكية والتطبيقات وفق منهجية معترف بها.
تحديد نطاق المشاركة وأهدافها ومنهجية الاختبار وقواعد التفاعل.
ضمان أن جميع أنشطة الاختبار تتم بأمان وبناءً على تفويضات العملاء المعتمدة.
إدارة جداول زمنية للمشاركة والموارد وجودة التسليم.
العمل كقائد تقني رئيسي طوال دورة حياة اختبار الاختراق.
تسليم الأمن الهجومي
أداء أنشطة اختبار اختراق متقدمة باستخدام تقنيات اختبار يدوية وآلية.
تحديد والتحقق من الثغرات الأمنية ومسارات الهجوم وتبيانها.
تقييم قابلية الاستغلال والتأثير التجاري ومخاطر التعرض المرتبطة بالنتائج المحددة.
إجراء تقييمات الثغرات واختبارات الاختراق وتمارين التحقق الأمني ومراجعات التهيئة وأنشطة الفريق الأحمر حيثما أمكن.
دعم إعادة الاختبار بعد جهود التصحيح.
ضمان الجودة والمراجعة الفنية
مراجعة والتحقق من نتائج اختبار الاختراق قبل التسليم للعملاء.
ضمان أن التقارير دقيقة تقنياً ومُصنفة المخاطر بشكل مناسب وقابلة للتنفيذ ومركزة على الأعمال ومتوافقة مع المعايير الصناعية.
مراجعة سلاسل الهجوم ومنهجيات الاستغلال لضمان الاتساق والجودة.
الحفاظ على توافق المنهجيات مع OWASP Testing Guide وPTES وOSSTMM وتوجيه NIST وأفضل الممارسات الصناعية.
التفاعل مع العملاء وخدمات الاستشارات
عرض النتائج الفنية وملخصات تنفيذية لأصحاب المصلحة من العملاء.
إجراء ورش تصحيح واجتماعات مراجعة تقنية.
دعم العملاء في فهم مخاطر الأمن والتعرّض للتهديدات والإجراءات التصحيحية الموصى بها.
تقديم توجيه استراتيجي لتحسين وضع الأمان العام.
دعم نشاطات ما قبل البيع وورش عمل العملاء وتقييمات الأمن السيبراني عند الحاجة.
قيادة الفريق وتطوير القدرات
قيادة وتوجيه وتطوير مختبري الاختراق ضمن ممارسة الأمن السيبراني.
إجراء التدريب الفني وبرامج التطوير وتبادل المعرفة ومبادرات تدريب الأمن الهجومي.
دعم التوظيف والتأهيل وأنشطة تطوير القدرات.
ضمان بقاء شهادات الفريق سارية ومتوافقة مع متطلبات NCSC.
قيادة التحسين المستمر عبر منهجيات وأدوات الأمن الهجومي.
الحوكمة والامتثال وتطوير الخدمة
ضمان الامتثال لمتطلبات ترخيص NCSC الأردن وسياسات الأمن الداخلية والالتزامات التعاقدية للعملاء والمتطلبات التنظيمية.
تنفيذ ممارسات اختبار آمنة ومتطلبات السرية وإجراءات التعامل مع الأدلة.
دعم مبادرات تطوير الخدمة لتوسيع قدرات الأمن الهجومي لـ زينتك.
الحفاظ على الوثائق التشغيلية ومعايير الاختبار وعمليات ضمان الجودة.
تنسيق تقارير وأنشطة الامتثال المطلوبة من NCSC والجهات التنظيمية الأخرى.
ثقافتنا ومدون السلوك
في ZainTECH، نفخر بثقافة مبنية على التعاون والابتكار ونزاهة لا تقبل التنازلات. نبحث عن أفراد يشاركون هذه القيم ويلتزمون بمركزيّة العميل والتميّز الأخلاقي. من المتوقع أن يلتزم جميع الموظفين بمدونة السلوك لدينا، التي تشكل إطاراً توجيهياً للسلوك المسؤول في كل ما نقوم به — من كيفية العمل مع بعضنا بعضاً إلى كيفية تعاملنا مع العملاء والشركاء على مستوى العالم.
المتطلبات
- درجة البكالوريوس (على الأقل) في تكنولوجيا المعلومات أو مجال ذات صلة.
- خبرة لا تقل عن 5 سنوات في الأمن السيبراني، بما في ذلك完成 5 مشاريع اختبار اختراق.
- على الأقل شهادة اختبار اختراق معتمدة من NCSC مثل CPENT، CEPT، OSCE، LPT، CPT، GPEN، أو شهادة معادلة دولياً معترف بها في المجال نفسه وتوافقها NCSC.
- مهارات هجومية عملية عميقة عبر الشبكة والويب واللاسلكي والتطبيقات وامتلاك منهجيات معترف بها (OWASP وPTES وOSSTMM).
- القيادة: القدرة المثبتة على قيادة فريق اختبار وتقديم عروض أمام التنفيذيين clients.
- يفضل الحصول على درجة متقدمة في الأمن السيبراني أو تخصص ذو صلة.
- يفضل وجود اعتماد متقدم مثل OSCE أو CPENT أو LPT أو GPEN.
- يفضل الخبرة في فريق الهجوم الأحمر أو ممارسات MSSP/الاستشارات الهجومية.