Senior Security Pentester

Il y a 2 jours

Brussel Hoofdstad, Belgique HumanInTech Temps plein 85 000 € - 110 000 € Contrat

What you will do

You will prepare and execute penetration tests on a complete IoT ecosystem, covering field equipment, network infrastructure, cloud platforms, applications and mobile components. The work involves identifying, exploiting and documenting vulnerabilities that could affect the confidentiality, integrity, availability or authenticity of systems and data.

Your main tasks:

  • Analyse technical architectures and data flows; identify critical assets, attack surfaces and trust relationships
  • Participate in defining scope, objectives and rules of engagement for each assignment
  • Perform penetration tests (black box, grey box, white box) on cameras, edge equipment, gateways and central systems
  • Test IoT and embedded systems security: firmware, hardware interfaces (UART/JTAG/SWD), OTA updates, secure boot
  • Analyse and test communication protocols (TCP/IP, HTTP/HTTPS, MQTT, RTSP, VPN, Wi‑Fi/BLE, TLS/mTLS/PKI)
  • Conduct cloud penetration tests (IAM, virtual networks, storage, containers/Kubernetes, CI/CD pipelines) on Azure, AWS or GCP
  • Test web applications, APIs and backend services (authentication, authorisation, OWASP Top 10, OAuth 2.0/OIDC/SAML/JWT)
  • Test Android and iOS mobile applications when in scope
  • Perform penetration tests on Windows, Linux and Active Directory infrastructure
  • Document and present results to technical teams and management; advise teams on remediation

What we are looking for

You have at least 5 years of experience in offensive security and can lead an assignment independently, from scope definition to presenting results. You are explicitly not a junior.

Core competencies:

  • Mastery of penetration testing methodologies (black/grey/white box), controlled exploitation, post-exploitation and lateral movement
  • IoT and embedded systems expertise: firmware analysis, hardware interfaces (UART/JTAG/SWD), update mechanisms and secure boot
  • Network, protocol and cloud security (Azure/AWS/GCP): IAM, segmentation, containers/Kubernetes, CI/CD
  • Application, API and mobile security (OWASP, OAuth 2.0/OIDC/SAML/JWT, Android/iOS)
  • Writing technical and executive reports, guiding remediation and mentoring less experienced profiles

Technical skills (confirmed level):

  • Offensive tooling: Kali/Parrot, Burp Suite/OWASP ZAP, Nmap/Wireshark/Nessus, Metasploit/Impacket, Bloodhound/Mimikatz
  • Scripting and automation: Python, PowerShell, Bash and at least one additional language (JavaScript, C, Go, Ruby)
  • Methodologies and frameworks: OWASP (WSTG, ASVS, API Security Top 10, MASVS/MSTG, IoT Security Top 10)

Communication:

  • Present results to technical teams, architects, project managers and management
  • Able to guide less experienced profiles; teamwork and knowledge sharing
  • Preferably bilingual (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English, both written and spoken

Education:

Higher degree in computer science, cybersecurity, electronics or telecommunications, or equivalent professional experience. Technical certifications in offensive security are an asset (e.g. OSCP/OSCP+, OSWE, OSEP, GPEN/GWAPT, SEC556/PIPA for IoT). No single certification is individually required; the combination of practical experience and domain coverage is decisive.

Deliverables

  • Complete, precise and reproducible technical reports per vulnerability (affected systems, exploitation conditions, evidence, impact, risk level, recommendations)
  • Clear executive summary for management
  • Formalised scope, objectives and rules of engagement per assignment
  • Developed or adapted proof‑of‑concepts and scripts where needed
  • Retests to validate the effectiveness of corrections
  • Recommendations to improve architectures, security standards and development procedures

The setting

This assignment runs from 1 November 2026 to 31 December 2026. The location is Brussels, with no remote option. You will work within the cybersecurity service, focusing on offensive security for IoT ecosystems. All activities are carried out exclusively within an authorised framework, based on defined scope and formalised rules of engagement.

You can join us for this assignment as a freelancer or as an employee of HumanInTech. Same role, same team. If you join as an employee, your employment continues beyond this assignment. When it ends, we’ll work together to find your next assignment.

Location: Brussels

Work address: Belgium

Employer / contracting party: HumanInTech

Applications close (Brussels time): October 7, 2026 at 2:00 AM

Engagement: Free