Senior Security Pentester
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
The role encompasses the preparation and execution of penetration tests on the entire ANPR ecosystem (field equipment, network, cloud, applications, mobile), the production of actionable reports, and guiding teams in remediating identified vulnerabilities.
Deliverables:
- Complete, precise, and reproducible technical reports per vulnerability (involved systems, operating conditions, evidence, impact, risk level, recommendations)
- Clear executive summary for management
- Formalized scope, objectives, and rules of engagement per assignment
- Developed or modified proof-of-concepts and scripts where necessary
- Retests to validate the effectiveness of the corrections
- Recommendations for improving architectures, security standards, and development procedures
Main tasks:
- Analyze technical architectures and data flows; identify critical assets, attack surfaces, and trust relationships
- Participate in determining the scope, objectives, and rules of engagement of the assignments
- Perform penetration tests (black box, grey box, white box) on the ANPR ecosystem: cameras, edge equipment, gateways, central systems
- Testing IoT and embedded systems for security (firmware, hardware interfaces UART/JTAG/SWD, OTA updates, secure boot)
- Analyzing and testing communication protocols (TCP/IP, HTTP/HTTPS, MQTT, RTSP, VPN, Wi-Fi/BLE, TLS/mTLS/PKI, etc.)
- Perform cloud pentesting (IAM, virtual networks, storage, containers/Kubernetes, CI/CD pipelines) on Azure, AWS or GCP
- Testing web applications, APIs, and backend services (authentication, authorization, OWASP Top 10, OAuth 2.0/OIDC/SAML/JWT)
- Test mobile Android and iOS applications when they fall within the scope
- Perform penetration tests on Windows, Linux, and Active Directory infrastructure
- Document results and present them to technical teams and management, and advise teams on remediation.
Core competencies:
- Mastery of penetration testing methodologies (black/grey/white box), controlled operation, post-exploitation, and lateral movement
- IoT and embedded systems expertise: firmware analysis, hardware interfaces (UART/JTAG/SWD), update mechanisms, and secure boot
- Network, protocol, and cloud security (Azure/AWS/GCP): IAM, segmentation, containers/Kubernetes, CI/CD
- Application, API, and mobile security (OWASP, OAuth 2.0/OIDC/SAML/JWT, Android/iOS)
- Drafting technical and executive reports, guidance on remediation and mentoring of less experienced profiles
Communication and collaboration:
- Presenting results to technical teams, architects, project managers, and management
- Able to mentor less experienced profiles; teamwork and knowledge sharing
- Preferably bilingual (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English, both written and spoken.
Level and experience:
- Authoritative advice and fully independent execution (SFIA level 5 – Ensure, advise)
- Minimum 10 years of experience in offensive security; capable of independently leading an assignment, from scope definition to presentation of results; expressly not a junior