Offensive Security Engineer — Exercise Red/Blue Team for NATO with security clearance

Il y a 2 semaines

Mons, Wallonia, Belgique WLG Temps plein
This role sits in a penetration testing cell and covers both halves of the discipline: the testing itself, and the part that decides whether anything gets fixed — reviews, advice and briefings to people who will act on them. A distinctive element is the exercise work. You would lead or join the red or blue team during military exercises, which is testing under a clock and in front of an audience. What you would be doing
* Lead or take part in the red or blue team during military exercises.
* Deliver web, infrastructure and application-level penetration testing.
* Run security design reviews for compliance with the governing policies and directives.
* Advise projects and programmes on security, and say plainly what has to change.
* Build and sustain communication with the accreditation boards and the units supporting them.
* Brief at executive and technical level on findings and testing outcomes, up to flag-officer level.
* Coordinate proactively with internal and external stakeholders alongside the head of the cell. What you would bring
* More than three years across web application and IT infrastructure penetration testing.
* Network security architecture design, and assessment of vulnerabilities in operating systems, software, protocols and networks.
* System and network administration of both Unix and Windows.
* Penetration testing tools, techniques and recognised methodologies.
* Scripting in at least one of Perl, Python, Ruby or a shell.
* Technical depth in system and network security, authentication protocols, cryptography, application security and malware.
* The ability to evaluate risk and write the mitigation plan, not only the finding.
* Clear, structured technical reports with an executive summary, findings and a remediation plan — for several different audiences. The work is full time on site in Mons, with about ten days of travel within Belgium foreseen.