الغرض من الدور
تسعى البنك إلى تعيين مهندس أمني أول متخصص في اختبار الاختراق، مع التركيز الأساسي على تطبيقات الويب، وواجهات برمجة التطبيقات (APIs)، وتطبيقات الهاتف المحمول. يتولى هذا الدور تحديد وتقييم الثغرات الاستغلالية، وتوصيل التأثير التجاري، والتعاون مع أصحاب التطبيقات للتحقق من إصلاحها. يعتبر الدعم المحدود لأدوات اختبار أمن التطبيقات مسؤولية ثانوية.
المسؤوليات الرئيسية
اختبار اختراق تطبيقات الويب وواجهات برمجة التطبيقات (APIs) وتطبيقات الهاتف المحمول
• تخطيط وتنفيذ اختبارات اختراق لتطبيقات الويب، وواجهات برمجة التطبيقات (APIs)، وتطبيقات أندرويد وآي أو إس، بما في ذلك الإصدارات الجديدة والتغييرات الرئيسية والتقييمات الدورية.
• إجراء اختبارات يدوية لتطبيقات الويب للتحقق من ثغرات المصادقة، والتفويض، وإدارة الجلسات، والحقن، ومعالجة الملفات، ومنطق الأعمال عبر أدوار المستخدمين.
• اختبار واجهات برمجة التطبيقات (RESTful، SOAP، GraphQL) للتحقق من التفويض على مستوى الكائن والدالة، ومعالجة الرموز، والتحقق من المدخلات، وتعرض البيانات الحساسة، واستغلال تدفقات العمل التجارية.
• تقييم تطبيقات الهاتف المحمول من خلال التحليل الثابت والديناميكي، بما في ذلك التخزين المحلي، وأمن النقل، والتفاعلات مع النظام الأساسي، والثنائيات التطبيقية، وواجهات برمجة التطبيقات الداعمة.
• التحقق من الثغرات باستخدام أدلة قابلة للتكرار واختبارات إثبات المفهوم المسيطر عليها؛ وترتيب النتائج حسب قابلية الاستغلال والتأثير التجاري.
• إعداد تقارير نتائج واضحة تتضمن الأصول المتأثرة، وخطوات إعادة الإنتاج، وشدة الثغرة، والأدلة، وإرشادات الإصلاح القابلة للتنفيذ لدعم متطلبات CBK CORF وضمانات البنك الداخلية.
• التعاون مع المطورين وأصحاب التطبيقات لشرح النتائج، وتقديم توصيات عملية للإصلاح، وإعادة اختبار الإصلاحات قبل إغلاقها.
• تحديد نطاق الاختبار، والمتطلبات المسبقة، وقواعد المشاركة مع أصحاب المصلحة؛ والمحافظة على تغطية الاختبار وحماية بيانات التقييم الحساسة.
• تنسيق اختبارات اختراق التطبيقات من قبل أطراف خارجية، ومراجعة المخرجات، وتتبع الإصلاحات وإعادة الاختبار مع أصحاب المصلحة المعنيين.
• الحفاظ على طرق اختبار قابلة للتكرار باستخدام إرشادات OWASP ذات الصلة لاختبار الويب، وواجهات برمجة التطبيقات، والهاتف المحمول؛ وتوجيه الزملاء في اختبار اختراق التطبيقات.
دعم أدوات أمن التطبيقات
• تقديم دعم محدود لتنفيذ وضبط أدوات اختبار أمن التطبيقات الثابتة (SAST)، وديناميكية (DAST)، وتحليل مكونات البرمجيات (SCA)، واختبار أمن تطبيقات الهاتف المحمول (MAST).
• المساعدة في التحقق من نتائج الأدوات وتقليل الإيجابيات الكاذبة؛ وتنسيق التكامل مع أنابيب CI/CD مع فرق DevOps والتطوير. يبقى هذا الدعم ثانوياً مقارنة باختبار الاختراق اليدوي، مع احتفاظ تلك الفرق بملكية الأنابيب.
المؤهلات المطلوبة
• 5 إلى 10 سنوات في مجال أمن المعلومات، مع خبرة عملية واسعة في اختبار الاختراق وإثبات عمق في اختبار تطبيقات الويب، وواجهات برمجة التطبيقات، وتطبيقات الهاتف المحمول.
• شهادة معترف بها في اختبار الاختراق، مثل OSCP، OSWE، GPEN، أو GWAPT.
• إتقان عملي لأدوات مثل Burp Suite وأدوات اختبار الهاتف المحمول مثل Frida، Objection، وMobSF، بما في ذلك التحقق اليدوي لما يتجاوز نتائج الماسحات الآلية.
• فهم قوي لـ HTTP، ومصادقة وتفويض التطبيقات، وهياكل واجهات برمجة التطبيقات الشائعة، وأمن أندرويد وآي أو إس، ومنهجيات اختبار OWASP.
• القدرة على كتابة البرامج النصية باستخدام Python، Bash، أو PowerShell لدعم الاختبار، وإعادة إنتاج النتائج، وأتمتة مهام التقييم المتكررة.
المؤهلات المفضلة
• الإلمام بأدوات SAST، DAST، SCA، وMAST وتكاملها مع منصات CI/CD مثل Jenkins، Azure DevOps، أو Tekton.
• خبرة سابقة في الخدمات المالية أو صناعة منظمة أخرى، مع الإلمام بـ CBK CORF، PCI DSS، أو NIST CSF.
• سجل قابل للإثبات في أبحاث ثغرات التطبيقات أو تجارب برامج مكافآت الثغرات، أو خبرة عملية في مسابقات CTF.
• القدرة على مراجعة الكود المصدر لدعم التحقيق في الثغرات والتحقق من إصلاحها.
المهارات الشخصية
• القدرة على شرح الثغرات الفنية والتأثير التجاري بوضوح للمطورين، وأصحاب التطبيقات، والإدارة، ومراجعي الجهات التنظيمية.
• التزام قوي بالإبلاغ، والانتباه للتفاصيل، والقدرة على إدارة أولويات الاختبار والتنسيق مع أصحاب المصلحة لإصلاح الثغرات.
Role Purpose
The Bank is seeking a senior security engineer specializing in penetration testing, with a primary focus on web applications, APIs, and mobile applications. The role identifies and validates exploitable vulnerabilities, communicates business impact, and works with application owners to verify remediation. Limited support for application security testing tools is a secondary responsibility.
Key Responsibilities
Web API and Mobile Penetration Testing
• Plan and execute penetration tests of web applications, APIs, and Android and iOS mobile applications, covering new releases, major changes, and periodic assessments.
• Perform manual web application testing for authentication, authorization, session management, injection, file handling, and business logic vulnerabilities across user roles.
• Test RESTful, SOAP, and GraphQL APIs for object- and function-level authorization, token handling, input validation, sensitive data exposure, and abuse of business workflows.
• Assess mobile applications through static and dynamic analysis, including local storage, transport security, platform interactions, application binaries, and supporting APIs.
• Validate vulnerabilities with reproducible evidence and controlled proof-of-concept testing; prioritize findings by exploitability and business impact.
• Produce clear findings reports with affected assets, reproduction steps, severity, evidence, and actionable remediation guidance to support CBK CORF and internal assurance requirements.
• Work with developers and application owners to explain findings, recommend practical fixes, and retest remediation before closure.
• Define test scope, prerequisites, and rules of engagement with stakeholders; maintain test coverage and protect sensitive assessment data.
• Coordinate third-party application penetration testing, review deliverables, and track remediation and retesting with relevant stakeholders.
• Maintain repeatable testing methods using relevant OWASP web, API, and mobile testing guidance; mentor colleagues in application penetration testing.
Application Security Tooling Support
• Provide limited support for implementing and tuning static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), and mobile application security testing (MAST) tools.
• Help validate tool findings and reduce false positives; coordinate CI/CD integration with DevOps and development teams. This support remains secondary to hands-on penetration testing, with pipeline ownership retained by those teams.
Required Qualifications
• 5–10 years in information security, with substantial hands-on penetration testing experience and demonstrated depth in web application, API, and mobile application testing.
• At least one recognized penetration testing certification, such as OSCP, OSWE, GPEN, or GWAPT.
• Practical proficiency with Burp Suite and mobile testing tools such as Frida, Objection, and MobSF, including manual validation beyond automated scanner results.
• Strong understanding of HTTP, application authentication and authorization, common API architectures, Android and iOS security, and OWASP testing methodologies.
• Ability to script in Python, Bash, or PowerShell to support testing, reproduce findings, and automate repetitive assessment tasks.
Preferred Qualifications
• Familiarity with SAST, DAST, SCA, and MAST tools and their integration with CI/CD platforms such as Jenkins, Azure DevOps, or Tekton.
• Prior experience in financial services or another regulated industry, with familiarity with CBK CORF, PCI DSS, or NIST CSF.
• A demonstrable application vulnerability research or bug bounty track record, or relevant hands-on CTF experience.
• Ability to review source code to support vulnerability investigation and remediation validation.
Soft Skills
• Ability to explain technical vulnerabilities and business impact clearly to developers, application owners, management, and regulatory reviewers.
• Strong reporting discipline, attention to detail, and ability to manage testing priorities and coordinate remediation with stakeholders.