Medior Security Pentester

Il y a 2 jours

Brussel Hoofdstad, Belgique HumanInTech Temps plein 55 000 € - 75 000 € Contrat

What you will do

You will join the cybersecurity team of a Belgian public-sector organisation to conduct authorised penetration testing across three main domains: web applications, API and administration portals; network infrastructures and protocols; and Windows/Active Directory environments.

You will work autonomously on standard-complexity missions and contribute to more complex assignments (cloud, containers, mobile, purple teaming) under the coordination of a senior pentester. All activities are conducted exclusively within an authorised framework, based on a defined scope and formalised rules of engagement.

Your main tasks include:

  • Analyse technical architectures and data flows; identify critical assets, attack surfaces and trust relationships
  • Contribute to defining the scope, objectives and rules of engagement for missions
  • Conduct penetration tests (black box, grey box, white box) on web applications, API and administration portals
  • Perform internal and external penetration tests on network infrastructures and protocols
  • Conduct penetration tests on Windows and Active Directory environments (Kerberos/NTLM, GPO, ACL, lateral movement)
  • Escalate risky situations, scope grey areas and critical discoveries to a senior profile
  • Document each vulnerability and write the technical report independently
  • Present findings to technical teams and project managers
  • Perform retests to validate the effectiveness of remediation
  • Contribute to internal knowledge capitalisation: methodologies, checklists, report templates, tooling

What we are looking for

Experience and level

  • Minimum 3 years of experience in penetration testing (ideally 3 to 5 years)
  • Ability to conduct standard missions independently and contribute to complex missions under senior coordination
  • Execution under general supervision, with escalation to a senior on complexity (SFIA level 3 – Apply)

Core competencies

  • Structured penetration testing methodology (black/grey/white box); controlled exploitation and post-exploitation
  • Web application and API testing: OWASP Top 10, modern authentication/authorisation (OAuth 2.0/OIDC/SAML/JWT), targeted code review
  • Network and infrastructure testing: protocols (TCP/IP, DNS, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP), segmentation, filtering
  • Windows/Active Directory testing: domain enumeration, Kerberos/NTLM, GPO/ACL, lateral movement, PowerShell
  • Technical report writing and ability to escape and collaborate with a senior profile

Tooling

  • Kali/Parrot, Burp Suite/OWASP ZAP, Nmap/Wireshark/Nessus, Metasploit/Impacket/NetExec, BloodHound

Methodologies and frameworks

  • OWASP WSTG/ASVS/API Security Top 10, PTES, MITRE ATT&CK, CVSS, CWE/CVE

Additional knowledge (asset)

  • Cloud (Azure/AWS/GCP), Linux, containers/Kubernetes/CI-CD, mobile applications

Certifications (appreciated but not required)

  • OSCP/OSCP+, Burp Suite Certified Practitioner (BSCP), CRTP

Languages

  • Bilingual (French, Dutch) preferred, or sufficient knowledge of the second national language
  • Excellent understanding of technical English

Communication and collaboration

  • Ability to present findings to technical teams and project managers
  • Capacity to ask for support and escalation at the right moment
  • Teamwork and knowledge sharing

The setting

This assignment runs from 1 November 2026 to 31 December 2026. You will work full-time in Brussels with no remote option. You will report to a senior pentester or security manager and collaborate with project teams and the CISO office.

Location: Brussels

Work address: Belgium

Employer / contracting party: HumanInTech

Applications close (Brussels time): October 7, 2026 at 2:0 AM

Engagement: Freelance or employed by HumanInTech

Working hours: Full-time

Experience: 3–5 years or more

Education: Bachelor's or more

Published: October 2026