Consultant – Manager| Cyber Operate | Penetration Tester | KSA
Deloitte Middle East · Riyadh, Saudi Arabia · 1d ago
Our Purpose
Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most—for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
Our shared values guide the way we behave to make a positive, enduring impact:
During your tenure as a Consultant – Manager, you will demonstrate and develop your capabilities in the following areas.
Plan and scope engagements
·Agree scope, objectives, rules of engagement and test windows with system owners, and obtain written authorisation before any testing
·Choose the right approach for each target: black-box, grey-box or white-box, external or internal, announced or unannounced
·Follow a defined methodology (NIST SP 800-115, PTES, OWASP) and keep testing safe for live, guest-facing services
Conduct penetration tests
·Web applications and APIs: test authentication, authorisation, business logic, injection, session handling and API security, following the OWASP Testing Guide and ASVS
·Mobile applications: test iOS and Android apps and their back-ends following OWASP MASTG
·Internal and external networks: test perimeter exposure, internal segmentation, lateral movement and privilege escalation
·Active Directory and identity: test AD and Entra ID attack paths, Kerberos weaknesses, privilege misconfigurations and credential exposure
·Cloud environments: test Azure, AWS and GCP for misconfigurations, excessive permissions and exposed services
·Wireless and physical: test corporate and guest Wi-Fi and, where authorised, physical access controls
·Social engineering: run authorised phishing and pretexting exercises with the Awareness team
Run red and purple team exercises (Senior)
·Plan and lead objective-based red team exercises that emulate realistic threat actors, mapped to MITRE ATT&CK
·Run purple team sessions with the SOC to test and improve detection and response
Report and drive fixes
·Write clear, risk-rated reports with evidence, attack narratives and practical remediation steps, plus a short executive summary in plain language
·Brief technical teams and management on results, and explain business impact without exaggeration
·Retest fixes, confirm closure, and pass validated findings to Vulnerability Management and Risk for tracking
·Build reusable test cases, scripts and checklists to make testing faster and more consistent
Leadership Capabilities:
- Builds own understanding of our purpose and values; explores opportunities for impact.
- Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
- Understands expectations and demonstrates personal accountability for keeping performance on track.
- Actively focuses on developing effective communication and relationship-building skills.
- Understands how their daily work contributes to the priorities of the team and the business.
Qualifications:
·Years of experience: 2-7 total years
·Bachelor's in cybersecurity, computer science or a related field, or equivalent practical experience
·Hands-on experience delivering penetration tests for real organisations, not only labs or CTFs
·Strong with core tools: Burp Suite, Nmap, Metasploit, BloodHound and common post-exploitation frameworks
·Scripting in Python, Bash or PowerShell
·Strong report writing in English
·A recognised hands-on offensive certification (e.g. OSCP) for Mid and Senior levels
·Red team experience with C2 frameworks (e.g. Cobalt Strike, Sliver, Mythic) is preferred.
·Mobile application and cloud penetration testing experience is preferred.
·Exploit development or code review skills is preferred.
·Experience testing hospitality, payments, smart-city or OT-adjacent environments is preferred.
·Arabic language is preferred.
·At least one preferred: OSCP, CREST CRT/CCT, GPEN. Also valued: OSEP, OSWE, CRTO, GWAPT, eCPPT/eWPT, PNPT. CEH is accepted at Junior level only.
·Frameworks & Standards: NCA ECC-2:2024 (penetration testing) · NIST SP 800-115 · PTES · OWASP WSTG / ASVS / MASTG · MITRE ATT&CK · CREST methodology