Mid-level Security Pentester
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
Mission:
The role involves the preparation and independent execution of penetration tests on web applications, networks and Windows/Active Directory environments, the production of technical reports and the contribution to remediation, with support from a senior profile on complex missions.
Deliverables:
- Comprehensive, accurate and reproducible technical reports by vulnerability (systems concerned, operating conditions, evidence, impact, risk, recommendations)
- Contribution to the executive summary for management, reviewed by a senior
- Scope, objectives and rules of engagement for missions, defined in collaboration with a senior member
- Simple proofs of concept and scripts adapted to the needs
- Retests to validate the effectiveness of the corrections
- Contribution to internal knowledge capitalization: methodologies, checklists, report templates, tools
Main tasks:
- Analyze technical architectures and data flows; identify critical assets, attack surfaces, and trust relationships
- Contribute to defining the scope, objectives, and rules of engagement for missions
- Perform penetration tests (black box, grey box, white box) on web applications, APIs, and administration portals.
- Perform internal and external penetration tests on network infrastructures and protocols
- Perform penetration tests on Windows and Active Directory environments (Kerberos/NTLM, GPO, ACL, lateral movement)
- Escalate high-risk situations, grey areas of the scope, and critical discoveries to a senior profile
- Document each vulnerability and write the technical report yourself.
- Present the results to the technical teams and project managers
- Perform retests to validate the effectiveness of the fixes.
- Contribute, in support of a senior colleague, to complementary missions (cloud, containers/CI-CD, mobile, purple teaming)
Key skills:
- Structured penetration testing methodology (black/grey/white box); controlled exploitation and post-exploitation
- Web application and API testing: OWASP Top 10, modern authentication/authorization (OAuth 2.0/OIDC/SAML/JWT), targeted code review
- Tests réseau et infrastructures : protocoles (TCP/IP, DNS, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP), segmentation, filtrage
- Windows/Active Directory Tests: Domain Enumeration, Kerberos/NTLM, GPO/ACL, Lateral Movement, PowerShell
- Technical report writing skills and ability to escalate/collaborate with a senior profile
Communication et collaboration:
- Present the results to the technical teams and project managers; executive summary reviewed by a senior member
- Ability to ask for support and escalate at the right time; teamwork and knowledge sharing
- Preferably bilingual (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English
Level and experience:
- Autonomous execution under general supervision, with escalation to a senior manager based on complexity (SFIA level 3 – Apply)
- Minimum 3 years of experience (ideally 3 to 5 years); independently manages standard tasks and contributes to complex tasks under the coordination of a senior manager
Advanced degree in computer science, cybersecurity or telecommunications, or equivalent professional experience.
Preferred certifications:
- OSCP/OSCP+,
- Burp Suite Certified Practitioner (BSCP),
- CRTP ;