Cybersecurity Consultant TVA

NTT Ltd Group Services United Kingdom LimitedRiyadh, Riyadh RegionOn-siteFull-timeListed 1 hour ago

Apply now

About this role

Make an impact with NTT DATA
Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive.

Your day at NTT DATA
The Cybersecurity Consultant is a hands-on cybersecurity professional responsible for conducting vulnerability assessments, penetration testing activities, and security reviews across customer environments. This role works closely with customers, infrastructure teams, application owners, and security stakeholders to identify security weaknesses, validate risks, and provide practical remediation recommendations.

The role combines technical security testing, customer engagement, and cybersecurity consultancy to help organizations strengthen their security posture, reduce risk, and improve compliance with security best practices and regulatory requirements.

Key responsibilities:

- Conduct vulnerability assessments and penetration tests across network, infrastructure, server, application, and cloud environments.
- Perform internal and external network penetration testing within approved scopes and rules of engagement.
- Conduct web application and API security assessments using recognized industry methodologies and frameworks.
- Perform authenticated and unauthenticated vulnerability scanning using approved commercial and open-source security tools.
- Validate vulnerabilities identified by automated tools and remove false positives before reporting.
- Perform controlled exploitation activities to confirm vulnerability impact while minimizing operational risk.
- Assess Windows, Linux, Active Directory, databases, network devices, and security infrastructure for security weaknesses.
- Evaluate vulnerabilities based on exploitability, asset criticality, technical severity, and business impact.
- Assign risk ratings using CVSS and applicable customer risk-classification methodologies.
- Prepare technical assessment reports, executive summaries, and remediation recommendations.
- Present assessment findings and risk remediation plans to technical and business stakeholders.
- Conduct remediation workshops and provide technical guidance to customer teams.
- Perform remediation validation and retesting activities.
- Maintain assessment evidence, testing records, screenshots, tool outputs, and supporting documentation.
- Support assessment planning activities, including scope definition, methodology selection, and rules of engagement.
- Ensure all testing activities comply with approved authorization requirements and security testing procedures.
- Support security consulting initiatives related to system hardening, vulnerability remediation, application security, and infrastructure security.
- Assist with security assessments aligned to recognized frameworks including NCA ECC, SAMA CSF, ISO 27001, CIS Controls, and PCI DSS.
- Contribute to continuous improvement of internal security testing methodologies, reporting templates, and knowledge repositories.
- Support presales activities by providing technical input for customer proposals, assessment scope definitions, and effort estimates.
- Perform any other cybersecurity consulting, vulnerability management, or penetration testing activities as required.

To thrive in this role, you need to have:

- Strong understanding of vulnerability assessment and penetration testing methodologies.
- Hands-on experience conducting network, infrastructure, web application, and API security testing.
- Strong knowledge of TCP/IP networking, routing, switching, DNS, HTTP/HTTPS, VPNs, firewalls, and enterprise network services.
- Good working knowledge of Windows, Linux, and Active Directory environments.
- Familiarity with common attack techniques including privilege escalation, credential attacks, lateral movement, and Active Directory exploitation.
- Strong understanding of OWASP Top 10, OWASP API Security Top 10, CVSS, CWE, and MITRE ATT&CK frameworks.
- Practical experience using security assessment tools such as Burp Suite, Nmap, Nessus, Qualys, Rapid7, Metasploit, Wireshark, OWASP ZAP, and Kali Linux.
- Ability to manually validate vulnerabilities and distinguish genuine findings from false positives.
- Understanding of common security technologies including WAF, IDS/IPS, NAC, EDR, SIEM, and secure remote access solutions.
- Basic scripting capabilities using Python, PowerShell, Bash, or similar languages.
- Strong analytical and problem-solving skills with the ability to think from an attacker's perspective.
- Strong report writing, evidence documentation, and presentation skills.
- Ability to communicate technical vulnerabilities and risks to both technical and business stakeholders.
- Ability to manage multiple customer engagements and work independently while maintaining high-quality deliverables.
- Strong professional integrity and commitment to maintaining customer confidentiality.

Academic qualifications and certifications:

- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering, or a related technical discipline.
- Equivalent practical experience may be considered where strong hands-on security testing expertise is demonstrated.
- Preferred certifications include: OSCP, CREST CRT, GPEN, PNPT, eCPPT, CompTIA PenTest+, Burp Suite Certified Practitioner (BSCP), CEH / CEH Practical

Required experience:

- 5-7 years of cybersecurity, vulnerability assessment, penetration testing, or security consulting experience.
- Minimum 3 years of recent hands-on vulnerability assessment and penetration testing experience.
- Demonstrated experience conducting internal and external network penetration tests.
- Hands-on experience performing web application and API security assessments.
- Experience using vulnerability management platforms such as Tenable, Qualys, or Rapid7.
- Strong working experience with tools including Burp Suite, Metasploit, Nmap, Kali Linux, and Wireshark.
- Experience performing vulnerability validation, exploitation, remediation verification, and retesting.
- Experience preparing professional technical security reports and presenting findings to customers and stakeholders.
- Experience assessing Windows, Linux, Active Directory, network infrastructure, and enterprise environments.
- Experience working directly with customer engagements within a cybersecurity consulting, systems integration, or professional services environment.
- Experience with Active Directory security testing is strongly preferred.
- Cloud, wireless, mobile application, container security, or red team experience is advantageous.
- Exposure to NCA ECC, SAMA CSF, ISO 27001, PCI DSS, or related security frameworks is considered beneficial.
- Strong written and verbal English communication skills; Arabic language capability is an advantage.

Workplace type :
On-site Working

About NTT DATA
NTT DATA is a $30+ billion business and technology services leader, serving 75% of the Fortune

Global 100. We are committed to accelerating client success and positively impacting society through

responsible innovation. We are one of the world’s leading AI and digital infrastructure providers, with

unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and

application services. Our consulting and industry solutions help organizations and society move

confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more

than 70 countries. We also offer clients access to a robust ecosystem of innovation centers as well as

established and start-up partners. NTT DATA is part of NTT Group, which invests over $3 billion each

year in R&D.

Equal Opportunity Employer
NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us. Apply today.

Third parties fraudulently posing as NTT DATA recruiters

NTT DATA recruiters will never ask job seekers or candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties who may attempt to impersonate NTT DATA recruiters whether in writing or by phone in order to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will come from an @nttdata.com email address. If you suspect any fraudulent activity, please contact us .