Mid-level Security Pentester

Il y a 8 heures

Brussels, Belgique ProUnity Temps partiel 400 € - 500 € Contrat

Mission:

The role involves the preparation and independent execution of penetration tests on web applications, networks and Windows/Active Directory environments, the production of technical reports and the contribution to remediation, with support from a senior profile on complex missions. 

 

Deliverables:

  • Comprehensive, accurate and reproducible technical reports by vulnerability (systems concerned, operating conditions, evidence, impact, risk, recommendations) 
  • Contribution to the executive summary for management, reviewed by a senior 
  • Scope, objectives and rules of engagement for missions, defined in collaboration with a senior member 
  • Simple proofs of concept and scripts adapted to the needs 
  • Retests to validate the effectiveness of the corrections 
  • Contribution to internal knowledge capitalization: methodologies, checklists, report templates, tools 

 

Main tasks:

  • Analyze technical architectures and data flows; identify critical assets, attack surfaces, and trust relationships 
  • Contribute to defining the scope, objectives, and rules of engagement for missions 
  • Perform penetration tests (black box, grey box, white box) on web applications, APIs, and administration portals. 
  • Perform internal and external penetration tests on network infrastructures and protocols 
  • Perform penetration tests on Windows and Active Directory environments (Kerberos/NTLM, GPO, ACL, lateral movement) 
  • Escalate high-risk situations, grey areas of the scope, and critical discoveries to a senior profile 
  • Document each vulnerability and write the technical report yourself. 
  • Present the results to the technical teams and project managers 
  • Perform retests to validate the effectiveness of the fixes. 
  • Contribute, in support of a senior colleague, to complementary missions (cloud, containers/CI-CD, mobile, purple teaming) 

 

Key skills:

  • Structured penetration testing methodology (black/grey/white box); controlled exploitation and post-exploitation 
  • Web application and API testing: OWASP Top 10, modern authentication/authorization (OAuth 2.0/OIDC/SAML/JWT), targeted code review 
  • Tests réseau et infrastructures : protocoles (TCP/IP, DNS, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP), segmentation, filtrage 
  • Windows/Active Directory Tests: Domain Enumeration, Kerberos/NTLM, GPO/ACL, Lateral Movement, PowerShell 
  • Technical report writing skills and ability to escalate/collaborate with a senior profile 

 

Communication et collaboration:

  • Present the results to the technical teams and project managers; executive summary reviewed by a senior member 
  • Ability to ask for support and escalate at the right time; teamwork and knowledge sharing 
  • Preferably bilingual (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English 

Level and experience:

  • Autonomous execution under general supervision, with escalation to a senior manager based on complexity (SFIA level 3 – Apply) 
  • Minimum 3 years of experience (ideally 3 to 5 years); independently manages standard tasks and contributes to complex tasks under the coordination of a senior manager

 

Advanced degree in computer science, cybersecurity or telecommunications, or equivalent professional experience.

Preferred certifications:

  • OSCP/OSCP+,
  • Burp Suite Certified Practitioner (BSCP),
  • CRTP ;