VAPT Principal Consultant
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 7+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 5 days ago
- Work mode
- In office
- Education
- Bachelor's degree in Cybersecurity, Computer Science or related field
- Eligibility
- Saudi Nationals only.
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Company
Join a leading national cybersecurity organization dedicated to securing Saudi Arabia's critical infrastructure and enterprise digital initiatives. Operating at the forefront of offensive and defensive security, this company plays a vital role in safeguarding the Kingdom's digital sovereignty, with advanced facilities located in Dhahran and Riyadh. This is an elite environment tailored for top cyber security professionals.
Role Overview
As the VAPT Principal Consultant, you will provide strategic direction and expert technical leadership for the Vulnerability Assessment and Penetration Testing practice. In this senior role, you will set offensive security strategies, manage complex red-team assignments, and advise high-level stakeholders, including C-suite executives and critical infrastructure clients.
Primary Responsibilities
- Establish and refine a strategic VAPT roadmap and governance framework aligned with leading global standards such as OWASP, PTES, OSSTMM, and NIST 800-115.
- Lead and supervise sophisticated penetration testing exercises covering web, mobile, cloud, IoT, OT/ICS, and wireless networks, and coordinate adversary emulation and red-team projects.
- Ensure technical rigor by verifying advanced exploitation and lateral movement tactics, and spearhead the creation of bespoke automation tools and threat modeling approaches.
- Communicate complex technical findings as actionable business risk insights and develop remediation strategies shared directly with executive leadership.
- Mentor and develop consulting teams, cultivate an offensive security culture, and design advanced training programs.
Candidate Requirements
- Strict requirement: Candidate must be a Saudi National.
- Minimum 7 years of progressive hands-on experience in offensive security, including penetration testing and red teaming.
- Proven leadership in managing large-scale multi-disciplinary engagements for enterprise or critical infrastructure sectors.
- Extensive knowledge of contemporary attack vectors including Web, Mobile, Cloud, IoT, OT, and Wireless environments, with expertise in vulnerability chaining techniques.
- Strong understanding of relevant regulatory and security compliance frameworks such as NIST, ISO 27001, PCI-DSS, and GDPR.
- Bachelor's degree in Cybersecurity, Computer Science, or a related discipline.
- Exceptional communication skills, with ability to influence and engage C-suite executives.
Benefits and Perks
- Prestigious leadership opportunity contributing directly to the security of national critical assets and digital infrastructure.
- Choice of work location between Riyadh and Dhahran in Saudi Arabia.
- Exposure to complex red-team operations and cutting-edge security technologies.
- Competitive salary and comprehensive benefits package.
Minimum education
Bachelor's Degree
Industry
Cybersecurity