Cybersecurity Offensive Specialist
الوصف الوظيفي
About HALA
HALA is a pioneering fintech organization in the MENAP region, dedicated to transforming financial services and shaping the future of banking for small and medium-sized enterprises (SMEs). By providing innovative financial and technological solutions, HALA empowers SMEs to establish, operate, and expand their businesses through advanced digital tools. With a presence across the UAE, Saudi Arabia, and Egypt—including entities such as HALA Payments and HALA Logistics—the company delivers cutting-edge solutions that enable merchants to digitize payments, streamline sales, and optimize operations. Founded in 2017, HALA operates under the regulatory oversight of the Saudi Arabian Central Bank, underscoring its commitment to compliance and excellence in financial technology.
Role Overview
The Cybersecurity Offensive Specialist plays a pivotal role in safeguarding HALA’s digital infrastructure by conducting sophisticated offensive security assessments. This position is centered on executing realistic cyberattack simulations to proactively identify and exploit vulnerabilities across systems, networks, and applications. The role requires meticulous documentation of findings, clear communication of attack pathways, and the formulation of actionable recommendations tailored to both technical and executive stakeholders. Additionally, the specialist will collaborate closely with defensive security teams to enhance detection and response capabilities, ensuring the organization remains resilient against evolving, real-world threats.
Key Responsibilities
- Conduct Offensive Security Assessments: Perform red teaming, adversary simulations, and penetration testing in strict alignment with the SAMA Cybersecurity Framework (CSF) and the National Cybersecurity Authority’s Essential Cybersecurity Controls (ECC) in Saudi Arabia.
- Execute Controlled Attack Exercises: Perform targeted assessments on applications, cloud environments, APIs, and payment/merchant platforms to validate the real-world exploitability of identified vulnerabilities.
- Advanced Penetration Testing & Code Reviews: Conduct in-depth penetration tests and source code reviews to uncover deeply embedded vulnerabilities. Collaborate with defense and Security Operations Center (SOC) teams to validate detection mechanisms and improve response strategies against these specific attack vectors.
- Maintain Offensive Tooling & Lab Environments: Develop and maintain specialized offensive security tools and lab environments while strictly adhering to established rules of engagement to ensure testing is conducted safely and without disrupting business operations.
- Deliver Actionable Insights: Provide clear, detailed remediation guidance to product and engineering teams, supporting the tracking and resolution of critical security findings to mitigate risks effectively.
- Ensure Regulatory Compliance: Ensure all assessment activities, evidence, and reporting align with SAMA CSF and NCA ECC control objectives, meeting audit expectations and regulatory requirements.
Minimum Qualifications
To qualify for this role, candidates must meet the following requirements:
- Experience: A minimum of 3 to 5 years in cybersecurity, with a focus on offensive security practices.
- Certifications: At least one recognized offensive security certification, such as OSCP (Offensive Security Certified Professional), CRTO (Certified Red Team Operator), eCPPT (eLearnSecurity Certified Professional Penetration Tester), or equivalent. Preferred certifications include OSEP (Offensive Security Experienced Penetration Tester), OSWE (Offensive Security Web Expert), GXPN (GIAC Exploit Researcher and Advanced Penetration Tester), GWAPT (GIAC Web Application Penetration Tester), GPEN (GIAC Penetration Tester), or CRTP/CRTE (Certified Red Team Professional/Expert) for advanced red teaming and adversary simulation expertise.
What We Offer
At HALA, we foster an inclusive and diverse work environment that encourages innovation, creativity, and flexibility. Our team operates across remote, in-office, and hybrid setups, ensuring a balanced and adaptable work experience. We provide highly competitive compensation packages, including the potential for equity participation, to recognize and reward your contributions. Professional growth is a priority, with regular training opportunities and an annual learning stipend to help you stay ahead in a dynamic and fast-paced industry.
Join a global team of over 30 nationalities spanning seven countries, where you’ll gain invaluable experience in a high-growth fintech sector. We empower our employees with autonomy, mentorship, and challenging goals, fostering an environment where both personal and professional development thrive. As a trusted member of our team, you’ll be entrusted with significant responsibility and the freedom to implement your ideas, driving impactful results for the organization and yourself.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.