Medior Security Pentester
Il y a 10 heures
Brussels, Belgique
Federal Police
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
Mission
- The function ensures the preparation and autonomous conduct of penetration tests on web applications, networks and Windows/Active Directory environments, the production of technical reports and the contribution to remediation, with support from a senior profile on complex missions.
Deliverables
- Comprehensive, accurate and reproducible technical reports by vulnerability (affected systems, operating conditions, evidence, impact, risk, recommendations)
- Contribution to the executive summary for management, proofread by a senior
- Scopes, objectives and rules of engagement of the missions, defined in contribution with a senior
- Simple proofs of concept and scripts tailored to needs
- Retests to validate the effectiveness of the corrections
- Contribution to internal capitalization: methodologies, checklists, reporting templates, tools
Main tasks
- Analyze technical architectures and data flows; Identify critical assets, attack surfaces, and trust relationships
- Contribute to the definition of the scope, objectives and rules of engagement of the missions
- Perform penetration tests (black box, grey box, white box) on web applications, APIs and administration portals
- Perform internal and external penetration tests on network infrastructures and protocols
- Perform penetration tests on Windows and Active Directory environments (Kerberos/NTLM, GPO, ACL, lateral movement)
- Escalate risky situations, perimeter grey areas and critical discoveries to a senior profile
- Document each vulnerability and write the technical report on your own
- Present results to technical teams and project managers
- Perform retests to validate the effectiveness of the corrections
- Contribute, in support of a senior, to complementary missions (cloud, containers/CI-CD, mobile, purple teaming)
Key Competencies
- Structured penetration testing methodology (black/grey/white box); Controlled and post-operation
- Web Application and API Testing: OWASP Top 10, Modern Authentication/Authorization (OAuth 2.0/OIDC/SAML/JWT), Targeted Code Review
- Network and infrastructure testing: protocols (TCP/IP, DNS, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP), segmentation, filtering
- Windows/Active Directory Testing: Domain Enumeration, Kerberos/NTLM, GPO/ACL, Lateral Movement, PowerShell
- Writing technical reports and ability to escalate/collaborate with a senior profile
Communication and collaboration
- Present the results to the technical teams and project managers; Executive summary proofread by a senior
- Ability to ask for support and climb at the right time; Teamwork and knowledge sharing
- Bilingual preferably (French, Dutch) or sufficient knowledge of the second national language; Excellent understanding of technical English
Level and experience
- Autonomous execution under general supervision, with escalation to a senior on complexity (SFIA level 3 – Apply)
- Minimum 3 years of experience (ideally 3 to 5 years); Leads standard assignments on his own and contributes to complex assignments under the coordination of a senior
Diploma
- Advanced degree in computer science, cybersecurity or telecommunications, or equivalent work experience.
Appreciated certifications:
- OSCP/OSCP+,
- Burp Suite Certified Practitioner (BSCP),
- CRTP ;
No certification is required