Medior Security Pentester

Il y a 23 heures

Brussels, Brussels-Capital, Belgique Keystone Solutions Temps plein
Mission Overview: Keystone Solutions is seeking a Medior Security Pentester / Ethical Hacker to join our consultancy mission at a client site. The consultant will have confirmed practical experience in penetration testing and will primarily work in three areas: web applications, APIs, and administration portals; network infrastructures and protocols; and Windows and Active Directory environments. The consultant will autonomously conduct standard complexity missions and contribute, under the coordination of a senior profile, to more complex missions (cloud, containers, mobile, purple teaming). All activities will be performed exclusively within an authorized framework, based on a defined scope and formalized engagement rules.

Key Responsibilities
• Prepare and conduct autonomous penetration tests on web applications, networks, and Windows/Active Directory environments, producing technical reports and contributing to remediation, with support from a senior profile on complex missions.
• Deliver comprehensive, precise, and reproducible technical reports by vulnerability (affected systems, exploitation conditions, evidence, impact, risk, recommendations).
• Contribute to the executive summary for management, reviewed by a senior.
• Define the scope, objectives, and engagement rules of missions in collaboration with a senior.
• Provide simple proof of concepts and scripts tailored to needs.
• Conduct retests to validate the effectiveness of corrections.
• Contribute to internal capitalization: methodologies, checklists, report templates, tooling. Key

Skills:
• Structured penetration testing methodology (black/grey/white box); controlled exploitation and post-exploitation.
• Web application and API testing: OWASP Top 10, modern authentication/authorization (OAuth 2.0/OIDC/SAML/JWT), targeted code review.
• Network and infrastructure testing: protocols (TCP/IP, DNS, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP), segmentation, filtering.
• Windows/Active Directory testing: domain enumeration, Kerberos/NTLM, GPO/ACL, lateral movement, PowerShell.
• Technical report writing and ability to escalate/collaborate with a senior profile. Communication and Collaboration:
• Present results to technical teams and project managers; executive summary reviewed by a senior.
• Ability to seek support and escalate at the right moment; teamwork and knowledge sharing.
• Bilingual preferred (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English. Experience and

Education:
• Autonomous execution under general supervision, escalating to a senior on complexity (SFIA level 3 – Apply).
• Minimum 8 years of experience (ideally 5 to 8 years); independently conducts standard missions and contributes to complex missions under senior coordination.
• Higher education degree in computer science, cybersecurity, or telecommunications, or equivalent professional experience. Certifications:
• Preferred: OSCP/OSCP+, Burp Suite Certified Practitioner (BSCP), CRTP; no certification is required. Work Environment:
• Responsibility level: SFIA level 3 – Apply (medior, trajectory towards senior).
• Reports to: Senior Pentester/Security Manager.
• Work regime: Full-time; interventions conducted exclusively within an authorized scope and according to formalized engagement rules.
•

Location:
Brussels.
• Team: Security team, in collaboration with project teams and the CISO office. If you are ready to tackle technical and strategic challenges in a dynamic consultancy environment, apply today at Keystone Solutions Career Portal. Duration: 01/11/2026
- 31/12/2026 2 months
• (full time) Skills required:
• Applications web et API : injections, IDOR, XSS, SSRF, désérialisation, gestion de sessions/tokens,
- Level: Confirmed
- Most recent: Any time
• Méthodologies et référentiels : OWASP WSTG/ASVS/API Security Top 10, PTES, MITRE ATT&CK, CVSS, CWE/C
- Level: Confirmed
- Most recent: Any time
• Notions complémentaires (atout) : cloud (Azure/AWS/GCP), Linux, conteneurs/Kubernetes/CI-CD, applica
- Level: Confirmed
- Most recent: Any time
• Outillage : Kali/Parrot, Burp Suite/OWASP ZAP, Nmap/Wireshark/Nessus, Metasploit/Impacket/NetExec, B
- Level: Confirmed
- Most recent: Any time
• Réseaux et protocoles : TCP/IP, DNS/DHCP/NTP/SNMP, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP/WinRM, VPN
- Level: Confirmed
- Most recent: Any time
• Windows et Active Directory : objets AD, GPO, ACL, relations d’approbation, Kerberos/NTLM (Kerberoas
- Level: Confirmed
- Most recent: Any time Language

requirements:
Dutch Level Active knowledge English Level Active knowledge French Level Active knowledge