Senior Security Pentester

Il y a 18 heures

Brussels, Belgique Federal Police Temps plein

Service: Cybersecurity – Offensive security / IoT ecosystem (ANPR cameras, sensors, cloud, applications)

Mission

  • The role includes the preparation and execution of penetration testing on the entire ANPR ecosystem (field equipment, network, cloud, applications, mobile), the production of actionable reports, and the guidance of teams on how to remediate identified vulnerabilities.

Deliverables

  • Complete, precise and reproducible technical reports per vulnerability (systems affected, operating conditions, evidence, impact, level of risk, recommendations)
  • Clear executive summary for management
  • Formalized scope, objectives and rules of engagement per assignment
  • Developed or modified proof-of-concepts and scripts where necessary
  • Retests to validate the effectiveness of the corrections
  • Recommendations to improve architectures, security standards, and development procedures

Main tasks

  • Analyze technical architectures and data streams; Identify critical assets, attack surfaces, and trusts
  • Participate in the definition of scope, objectives and rules of engagement of the assignments
  • Perform pen tests (black box, grey box, white box) on the ANPR ecosystem: cameras, edge equipment, gateways, central systems
  • IoT and embedded systems security testing (firmware, hardware interfaces UART/JTAG/SWD, OTA updates, secure boot)
  • Analyze and test communication protocols (TCP/IP, HTTP/HTTPS, MQTT, RTSP, VPN, Wi-Fi/BLE, TLS/mTLS/PKI, etc.)
  • Run cloud pen tests (IAM, virtual networks, storage, containers/Kubernetes, CI/CD pipelines) on Azure, AWS, or GCP
  • Test web applications, APIs, and backend services (authentication, authorization, OWASP Top 10, OAuth 2.0/OIDC/SAML/JWT)
  • Test Android and iOS mobile applications when they are in scope
  • Perform pen tests on Windows, Linux, and Active Directory infrastructure
  • Document and present results to technical teams and management, and advise teams on remediation

Core competencies

  • Mastery of penetration test methodologies (black/grey/white box), controlled operation, post-exploitation and lateral movement
  • IoT and embedded systems expertise: firmware analysis, hardware interfaces (UART/JTAG/SWD), update mechanisms and secure boot
  • Network, protocol, and cloud security (Azure/AWS/GCP): IAM, segmentation, containers/Kubernetes, CI/CD
  • Application, API, and mobile security (OWASP, OAuth 2.0/OIDC/SAML/JWT, Android/iOS)
  • Drafting technical and executive reports, remediation guidance and mentoring of less experienced profiles

Communication and collaboration

  • Presenting results to technical teams, architects, project managers and management
  • Able to supervise less experienced profiles; Teamwork and knowledge sharing
  • Preferably bilingual (French, Dutch) or sufficient knowledge of the second national language; Excellent understanding of technical English, both written and oral

Level and experience

  • Authoritative advice and fully independent implementation (SFIA level 5 – Ensure, advise)
  • At least 5 years of experience in offensive security; able to lead an assignment independently, from scope determination to presentation of the results; explicitly not a junior