368,611open jobs
9,439companies
50,719added this week
Browse all
Location
Remote/Hybrid (Riyadh, Saudi Arabia)
Overview
Company
Impact
Profile match
Hala is a Saudi fintech that provides payments, banking and business tools to small and medium enterprises. Its products include card acceptance, expense cards, invoicing and merchant accounts delivered through a single app. The company grew out of the earlier Halalah wallet and is regulated by the Saudi Central Bank.

Who Are We

HALA is a leading fintech player in the MENAP region that aims to redefine financial services and build the future bank of SMEs. HALA aims at empowering SMEs to start, run, and grow their businesses by providing them with cutting-edge financial and technological tools.

HALA currently holds multiple entities in UAE, Saudi Arabia and Egypt (including HALA Payments and HALA Logistics) and offers solutions that enable merchants to digitize their payments as well as manage their sales and operations.

Founded in 2017, HALA is currently licensed by the Saudi Arabian Central Bank.

Role Summary

The Cybersecurity Offense Specialist is primarily responsible for executing the organization's offensive security assessments by conducting advanced penetration tests to simulate realistic cyberattacks and proactively identify and exploit security vulnerabilities across systems, networks, and applications. Critically, this role involves deeply documenting and communicating these findings and attack pathways to both technical and executive audiences with clear, actionable recommendations, and collaborating with defensive security teams to test, validate, and enhance the organization's overall detection and response capabilities against sophisticated, real-world threats.

Key Responsibilities

  • Execute HALA's offensive security assessments (red teaming, adversary simulation, penetration testing) in alignment with SAMA CSF and NCA ECC requirements.
  • Conduct controlled attack exercises on apps, cloud, APIs, and payment/merchant platforms to validate real-world exploitability.
  • Execute advanced penetration testing and source code reviews to identify deeply rooted vulnerabilities, and collaborate with Defense/SOC teams to validate and improve detections against these specific attack vectors.
  • Maintain and utilize offensive tooling and lab environments; strictly adhere to rules of engagement to ensure safe testing with zero business disruption.
  • Deliver clear, detailed remediation guidance to Product/Engineering teams and support the tracking and closure of critical findings.
  • Ensure all assessment activities, evidence, and reporting align with SAMA CSF and NCA ECC control objectives and audit expectations.

Minimum Qualifications

  • 3-5 years
  • Required: At least one recognized offensive security certification: OSCP, CRTO, eCPPT or equivalent.
  • Preferred (one or more): OSEP, OSWE, GXPN, GWAPT, GPEN, or CRTP/CRTE for advanced red team and adversary-simulation depth.

What We Offer You

We believe you will love working at HALA!

  • We have an inclusive and diverse culture that encourages innovation and flexibility in remote, in-office, and hybrid work setups.
  • We offer highly competitive compensation packages, including the potential for shares.
  • We prioritize personal development and offer regular training and an annual learning stipend to tackle new challenges and grow your career in a hyper-growth environment.
  • Join a talented team of over 30 nationalities working in 7 countries and gain valuable experience in an exciting industry.
  • We offer autonomy, mentoring, and challenging goals that create incredible opportunities for both you and the company.
  • You will be given a lot of responsibility and trust. We believe that the best results come when the people responsible for a function are given the freedom to do what they think is best.

If you think you have what it takes to join a remarkable team #apply_now 

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Riyadh
$145k – $193k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • Chicago • Washington • Denver • Jersey City • Boston
Python
AI/ML
AI Agents
Anomaly Detection
Embeddings
Fine-tuning
Function Calling
Hugging Face
LangChain
LLM
LLM Evaluation
LLM Guardrails
PyTorch
RAG
Red Teaming
Scikit-learn
Vertex AI
DevOps
Azure
GCP
Cybersecurity
Threat Modeling
Apply
$90k – $184k per year (Estimated) • Equity • Remote • Full-Time • 3+ years exp • United States
AI/ML
Red Teaming
Cybersecurity
Burp Suite
Cobalt Strike
Crowdstrike
Metasploit
MITRE ATT&CK
Nessus
Nmap
Apply
$16k – $40k per year (Estimated) • Remote • Full-Time • 2+ years exp • Moscow
Python
Databases
Chroma
ElasticSearch
Milvus
OpenSearch
pgvector
Qdrant
Weaviate
PostgreSQL
AI/ML
AI Agents
Anthropic
AWS Bedrock
Embeddings
Function Calling
Human-in-the-Loop
LLM
LLM Guardrails
NIST AI RMF
OpenAI
RAG
Red Teaming
Vertex AI
DevOps
AWS
Azure
Kubernetes
Cybersecurity
OWASP Top 10
Threat Modeling
Apply
$60k – $149k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Ottobrunn • Ulm
Python
AI/ML
Red Teaming
Cybersecurity
MITRE ATT&CK
Apply
up to $37k per year (gross) • In office • Full-Time • 3+ years exp • Novosibirsk
Bash
PowerShell
Python
AI/ML
Red Teaming
DevOps
AWS
IAM
Cybersecurity
Least Privilege
Metasploit
MITRE ATT&CK
Nessus
Nmap
OpenVAS
Snort
Suricata
Wazuh
Management
Slack
Apply
Remote/Hybrid • 2+ years exp • Riyadh
Apply
Remote/Hybrid • Riyadh
Apply
Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Riyadh
Python
SQL
Apply
In office • Full-Time • Bachelor's Degree • Riyadh
JavaScript
TypeScript
Frontend
React.js
Mobile
React Native
State Management
DevOps
CI/CD
Git
Apply
In office • Full-Time • Bachelor's Degree • Riyadh
Java
SQL
Java
Spring Boot
Databases
Apache Kafka
DevOps
CI/CD
Git
Kubernetes
OpenShift
Rest API
Apply
In office • Full-Time • Bachelor's Degree • Riyadh
Apply
In office • Full-Time • Bachelor's Degree • Riyadh
Java
SQL
Java
Spring Boot
Databases
Apache Kafka
DevOps
CI/CD
Git
Kubernetes
OpenShift
Rest API
Apply
In office • Full-Time • Bachelor's Degree • Riyadh
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.