Senior Security Pentester
Il y a 1 jour
Brussels, Brussels-Capital, Belgique
In4Matic
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
We’re looking for a Senior Penetration Testing Analyst to join our client’s cybersecurity team and lead complex offensive security engagements across a diverse technology landscape. You will take ownership of penetration tests from scoping and rules of engagement through execution, reporting and remediation support, covering infrastructure, cloud, applications, mobile and connected/embedded technologies. This is a highly autonomous expert role requiring broad technical coverage and the ability to advise both technical teams and management.
Role & Responsibilities
• Define and execute black-box, grey-box and white-box penetration tests across complex technology environments.
• Analyze technical architectures and data flows to identify critical assets, attack surfaces and trust relationships.
• Contribute to defining engagement scope, objectives and rules of engagement.
• Assess IoT and embedded systems, including firmware, hardware interfaces such as UART/JTAG/SWD, OTA update mechanisms and secure boot.
• Analyze and test communication protocols including TCP/IP, HTTP/HTTPS, MQTT, RTSP, VPN, Wi-Fi/BLE and TLS/mTLS/PKI.
• Conduct cloud penetration testing across Azure, AWS and GCP, covering IAM, virtual networks, storage, databases, containers/Kubernetes and CI/CD pipelines.
• Test web applications, APIs and backend services, including authentication, authorization, OWASP Top 10 and OAuth 2.0/OIDC/SAML/JWT.
• Perform mobile application security assessments on Android and iOS environments.
• Conduct penetration testing on Windows, Linux and Active Directory infrastructures.
• Use controlled exploitation, post-exploitation and lateral movement techniques within agreed engagement boundaries.
• Develop or adapt proof-of-concepts and scripts where required.
• Produce complete, accurate and reproducible technical reports, together with clear executive summaries for management.
• Present findings to technical teams, architects, project stakeholders and management.
• Advise teams on vulnerability remediation and recommend improvements to architectures, security standards and development practices.
• Retest identified vulnerabilities to validate the effectiveness of remediation.
• Mentor less experienced security professionals and contribute to internal knowledge sharing. Technical Profile The ideal candidate combines deep offensive security expertise with broad knowledge across multiple technology domains:
• Cloud security: IAM, virtual networks, storage, databases, containers/Kubernetes and CI/CD pipelines across Azure, AWS and GCP.
• IoT and embedded security: IoT/edge architectures, firmware analysis, hardware interfaces, update mechanisms and secure boot.
• Application, API and mobile security, including OWASP WSTG, ASVS, API Security Top 10, MASVS/MSTG and relevant IoT security frameworks.
• Network and protocol security covering TCP/IP, DNS, HTTP/HTTPS, REST, SOAP, WebSocket, gRPC, MQTT, AMQP, CoAP, RTSP, VPN and related technologies.
• Offensive security tooling such as Kali/Parrot, Burp Suite, OWASP ZAP, Nmap, Wireshark, Nessus, Metasploit, Impacket and BloodHound.
• Scripting and automation using Python, PowerShell and Bash, plus at least one additional programming language such as JavaScript, C, C++ or Java. Experience & Profile
• Minimum 10 years of experience in offensive security, with a proven ability to independently lead engagements from initial scoping through final presentation.
• Expert-level technical autonomy and the ability to provide authoritative security advice.
• Strong experience across multiple offensive security domains rather than specialization in a single technology.
• Excellent analytical, reporting and communication skills, with the ability to translate complex technical findings into actionable recommendations for both technical and management audiences.
• Comfortable mentoring less experienced profiles and sharing knowledge within a security team.
• Excellent written and spoken technical English is required; knowledge of French and Dutch is highly valued.
• Higher education in Computer Science, Cybersecurity, Electronics, Telecommunications or a related discipline, or equivalent professional experience.
• Offensive security certifications such as OSCP/OSCP+, OSWE, OSEP, GPEN/GWAPT or IoT-focused certifications are considered an advantage. No individual certification is mandatory; practical experience and breadth of expertise are the key criteria. Contactperson & Reference
• Reference #: INW28270
• Marilyn Weytens
• marilyn.weytens@i4m.be
• Define and execute black-box, grey-box and white-box penetration tests across complex technology environments.
• Analyze technical architectures and data flows to identify critical assets, attack surfaces and trust relationships.
• Contribute to defining engagement scope, objectives and rules of engagement.
• Assess IoT and embedded systems, including firmware, hardware interfaces such as UART/JTAG/SWD, OTA update mechanisms and secure boot.
• Analyze and test communication protocols including TCP/IP, HTTP/HTTPS, MQTT, RTSP, VPN, Wi-Fi/BLE and TLS/mTLS/PKI.
• Conduct cloud penetration testing across Azure, AWS and GCP, covering IAM, virtual networks, storage, databases, containers/Kubernetes and CI/CD pipelines.
• Test web applications, APIs and backend services, including authentication, authorization, OWASP Top 10 and OAuth 2.0/OIDC/SAML/JWT.
• Perform mobile application security assessments on Android and iOS environments.
• Conduct penetration testing on Windows, Linux and Active Directory infrastructures.
• Use controlled exploitation, post-exploitation and lateral movement techniques within agreed engagement boundaries.
• Develop or adapt proof-of-concepts and scripts where required.
• Produce complete, accurate and reproducible technical reports, together with clear executive summaries for management.
• Present findings to technical teams, architects, project stakeholders and management.
• Advise teams on vulnerability remediation and recommend improvements to architectures, security standards and development practices.
• Retest identified vulnerabilities to validate the effectiveness of remediation.
• Mentor less experienced security professionals and contribute to internal knowledge sharing. Technical Profile The ideal candidate combines deep offensive security expertise with broad knowledge across multiple technology domains:
• Cloud security: IAM, virtual networks, storage, databases, containers/Kubernetes and CI/CD pipelines across Azure, AWS and GCP.
• IoT and embedded security: IoT/edge architectures, firmware analysis, hardware interfaces, update mechanisms and secure boot.
• Application, API and mobile security, including OWASP WSTG, ASVS, API Security Top 10, MASVS/MSTG and relevant IoT security frameworks.
• Network and protocol security covering TCP/IP, DNS, HTTP/HTTPS, REST, SOAP, WebSocket, gRPC, MQTT, AMQP, CoAP, RTSP, VPN and related technologies.
• Offensive security tooling such as Kali/Parrot, Burp Suite, OWASP ZAP, Nmap, Wireshark, Nessus, Metasploit, Impacket and BloodHound.
• Scripting and automation using Python, PowerShell and Bash, plus at least one additional programming language such as JavaScript, C, C++ or Java. Experience & Profile
• Minimum 10 years of experience in offensive security, with a proven ability to independently lead engagements from initial scoping through final presentation.
• Expert-level technical autonomy and the ability to provide authoritative security advice.
• Strong experience across multiple offensive security domains rather than specialization in a single technology.
• Excellent analytical, reporting and communication skills, with the ability to translate complex technical findings into actionable recommendations for both technical and management audiences.
• Comfortable mentoring less experienced profiles and sharing knowledge within a security team.
• Excellent written and spoken technical English is required; knowledge of French and Dutch is highly valued.
• Higher education in Computer Science, Cybersecurity, Electronics, Telecommunications or a related discipline, or equivalent professional experience.
• Offensive security certifications such as OSCP/OSCP+, OSWE, OSEP, GPEN/GWAPT or IoT-focused certifications are considered an advantage. No individual certification is mandatory; practical experience and breadth of expertise are the key criteria. Contactperson & Reference
• Reference #: INW28270
• Marilyn Weytens
• marilyn.weytens@i4m.be