Medior Security Pentester
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
What you will do
You will join the cybersecurity team of a Belgian public-sector organisation to conduct authorised penetration testing across three main domains: web applications, API and administration portals; network infrastructures and protocols; and Windows/Active Directory environments.
You will work autonomously on standard-complexity missions and contribute to more complex assignments (cloud, containers, mobile, purple teaming) under the coordination of a senior pentester. All activities are conducted exclusively within an authorised framework, based on a defined scope and formalised rules of engagement.
Your main tasks include:
- Analyse technical architectures and data flows; identify critical assets, attack surfaces and trust relationships
- Contribute to defining the scope, objectives and rules of engagement for missions
- Conduct penetration tests (black box, grey box, white box) on web applications, API and administration portals
- Perform internal and external penetration tests on network infrastructures and protocols
- Conduct penetration tests on Windows and Active Directory environments (Kerberos/NTLM, GPO, ACL, lateral movement)
- Escalate risky situations, scope grey areas and critical discoveries to a senior profile
- Document each vulnerability and write the technical report independently
- Present findings to technical teams and project managers
- Perform retests to validate the effectiveness of remediation
- Contribute to internal knowledge capitalisation: methodologies, checklists, report templates, tooling
What we are looking for
Experience and level
- Minimum 3 years of experience in penetration testing (ideally 3 to 5 years)
- Ability to conduct standard missions independently and contribute to complex missions under senior coordination
- Execution under general supervision, with escalation to a senior on complexity (SFIA level 3 – Apply)
Core competencies
- Structured penetration testing methodology (black/grey/white box); controlled exploitation and post-exploitation
- Web application and API testing: OWASP Top 10, modern authentication/authorisation (OAuth 2.0/OIDC/SAML/JWT), targeted code review
- Network and infrastructure testing: protocols (TCP/IP, DNS, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP), segmentation, filtering
- Windows/Active Directory testing: domain enumeration, Kerberos/NTLM, GPO/ACL, lateral movement, PowerShell
- Technical report writing and ability to escape and collaborate with a senior profile
Tooling
- Kali/Parrot, Burp Suite/OWASP ZAP, Nmap/Wireshark/Nessus, Metasploit/Impacket/NetExec, BloodHound
Methodologies and frameworks
- OWASP WSTG/ASVS/API Security Top 10, PTES, MITRE ATT&CK, CVSS, CWE/CVE
Additional knowledge (asset)
- Cloud (Azure/AWS/GCP), Linux, containers/Kubernetes/CI-CD, mobile applications
Certifications (appreciated but not required)
- OSCP/OSCP+, Burp Suite Certified Practitioner (BSCP), CRTP
Languages
- Bilingual (French, Dutch) preferred, or sufficient knowledge of the second national language
- Excellent understanding of technical English
Communication and collaboration
- Ability to present findings to technical teams and project managers
- Capacity to ask for support and escalation at the right moment
- Teamwork and knowledge sharing
The setting
This assignment runs from 1 November 2026 to 31 December 2026. You will work full-time in Brussels with no remote option. You will report to a senior pentester or security manager and collaborate with project teams and the CISO office.
Location: Brussels
Work address: Belgium
Employer / contracting party: HumanInTech
Applications close (Brussels time): October 7, 2026 at 2:0 AM
Engagement: Freelance or employed by HumanInTech
Working hours: Full-time
Experience: 3–5 years or more
Education: Bachelor's or more
Published: October 2026