VAPT Engineer –

VAPT Engineer –
نوع العمل : عمل كلى
الخبرة : 0-3 سنة
الراتب : Not Mentioned
المكان : · Saudi Arabia

For A Leading Fintech Company (Owned by One of Egypt’s Largest Local Banks)


Vulnerability Assessment & Penetration Testing (VAPT) Engineer


Position Summary

We need a VAPT Engineer with a strong programming background to join our core security team. The ideal candidate will be a hands-on technical expert responsible for leading sophisticated security assessments of our entire digital payments ecosystem. This includes our payment gateways, mobile applications, point-of-sale (POS) systems, and core fintech infrastructure. This role is crucial for ensuring our compliance with PCI DSS and Central Bank of Egypt (CBE) regulations. The candidate will not only identify vulnerabilities but also possess a deep understanding of payment technologies, cryptographic protocols, and regulatory requirements.

Key Responsibilities

  • Vulnerability Assessment & Penetration Testing:
  • Lead and perform comprehensive penetration tests on our payment gateways, REST APIs, mobile payment applications (iOS/Android), and POS systems.
  • Conduct security assessments of critical financial infrastructure, including on-premise and cloud environments.
  • Utilize and develop advanced manual and automated testing techniques to identify vulnerabilities and bypass security controls.
  • Secure Development & Automation:
  • Apply strong programming skills (Python, Java, Go) to create custom security tools, exploit scripts, and automation for continuous security testing.
  • Perform rigorous static and dynamic application security testing (SAST/DAST) and manual code reviews, with a specific focus on payment application logic.
  • Integrate security tools and processes directly into our CI/CD pipelines to enforce DevSecOps principles.
  • Hardware & Cryptographic Security:
  • Conduct assessments on payment hardware and firmware, with an emphasis on PCI PTS and SRED (Secure Reading and Exchange of Data) controls.
  • Test for tamper detection and response mechanisms, remote key injection (RKI), and secure key storage.
  • Validate the implementation of cryptographic protocols and the secure management of keys in Hardware Security Modules (HSMs).
  • Compliance & Auditing:
  • Serve as a key technical resource for PCI DSS and CBE security requirements.
  • Assist in preparing for and responding to internal and external audits by providing evidence, technical data, and risk-based analysis.
  • Document findings and remediation plans in a format that meets both technical and compliance reporting standards.
  • Reporting & Collaboration:
  • Translate complex technical findings into clear, concise reports for technical teams, while also preparing executive summaries for senior leadership and auditors.
  • Provide expert guidance to development and product teams on secure design and coding practices, ensuring vulnerabilities are remediated effectively.


Qualifications & Skills

Technical Skills (Must-Have):

  • Experience: 5+ years of hands-on experience in VAPT with a proven track record in the fintech or digital payments industry.
  • Programming: Strong proficiency in at least one or more programming languages such as Python, Java, or C#, with the ability to develop custom security tools.
  • Security Tools: Mastery of industry-standard VAPT tools (Burp Suite Professional, Metasploit, Nessus).
  • Application Security: Expert-level knowledge of web and mobile application vulnerabilities, common attack vectors, and secure coding practices.
  • Domain-Specific Expertise (Crucial):
  • Deep understanding of PCI DSS requirements and how they apply to all aspects of the payment lifecycle.
  • Experience with PCI PTS, SRED, and secure key management (DUKPT, RKI, etc.).
  • Strong knowledge of cryptographic protocols, PKI, and hardware security modules (HSMs).
  • Familiarity with financial systems and payment gateways.

Professional Skills (Must-Have):

  • Exceptional communication and reporting skills, with the ability to articulate technical risk in a business context.
  • Demonstrated experience in a regulated environment, particularly with central bank security regulations.
  • Strong analytical and problem-solving abilities with a proactive mindset.
  • Relevant professional certifications such as OSCP (Offensive Security Certified Professional), eWPTX, GPEN, or GWAPT are required.
  • Certifications such as PCIP (PCI Professional) or a background in QSA (Qualified Security Assessor) activities would be a significant advantage.

للتقديم الان