Medior Security Pentester

Il y a 10 heures

Brussels, Belgique Federal Police Temps plein

Mission

  • The function ensures the preparation and autonomous conduct of penetration tests on web applications, networks and Windows/Active Directory environments, the production of technical reports and the contribution to remediation, with support from a senior profile on complex missions.

Deliverables

  • Comprehensive, accurate and reproducible technical reports by vulnerability (affected systems, operating conditions, evidence, impact, risk, recommendations)
  • Contribution to the executive summary for management, proofread by a senior
  • Scopes, objectives and rules of engagement of the missions, defined in contribution with a senior
  • Simple proofs of concept and scripts tailored to needs
  • Retests to validate the effectiveness of the corrections
  • Contribution to internal capitalization: methodologies, checklists, reporting templates, tools

Main tasks

  • Analyze technical architectures and data flows; Identify critical assets, attack surfaces, and trust relationships
  • Contribute to the definition of the scope, objectives and rules of engagement of the missions
  • Perform penetration tests (black box, grey box, white box) on web applications, APIs and administration portals
  • Perform internal and external penetration tests on network infrastructures and protocols
  • Perform penetration tests on Windows and Active Directory environments (Kerberos/NTLM, GPO, ACL, lateral movement)
  • Escalate risky situations, perimeter grey areas and critical discoveries to a senior profile
  • Document each vulnerability and write the technical report on your own
  • Present results to technical teams and project managers
  • Perform retests to validate the effectiveness of the corrections
  • Contribute, in support of a senior, to complementary missions (cloud, containers/CI-CD, mobile, purple teaming)

Key Competencies

  • Structured penetration testing methodology (black/grey/white box); Controlled and post-operation
  • Web Application and API Testing: OWASP Top 10, Modern Authentication/Authorization (OAuth 2.0/OIDC/SAML/JWT), Targeted Code Review
  • Network and infrastructure testing: protocols (TCP/IP, DNS, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP), segmentation, filtering
  • Windows/Active Directory Testing: Domain Enumeration, Kerberos/NTLM, GPO/ACL, Lateral Movement, PowerShell
  • Writing technical reports and ability to escalate/collaborate with a senior profile

Communication and collaboration

  • Present the results to the technical teams and project managers; Executive summary proofread by a senior
  • Ability to ask for support and climb at the right time; Teamwork and knowledge sharing
  • Bilingual preferably (French, Dutch) or sufficient knowledge of the second national language; Excellent understanding of technical English

Level and experience

  • Autonomous execution under general supervision, with escalation to a senior on complexity (SFIA level 3 – Apply)
  • Minimum 3 years of experience (ideally 3 to 5 years); Leads standard assignments on his own and contributes to complex assignments under the coordination of a senior

Diploma

  • Advanced degree in computer science, cybersecurity or telecommunications, or equivalent work experience.

Appreciated certifications:

  • OSCP/OSCP+,
  • Burp Suite Certified Practitioner (BSCP),
  • CRTP ;

No certification is required