Medior Security Pentester

Il y a 14 heures

Brussels, Brussels-Capital, Belgique In4Matic Temps plein
We’re looking for a Penetration Testing Analyst to join our client’s cybersecurity team and independently conduct security assessments across web applications, networks and Windows/Active Directory environments. You will be responsible for executing standard penetration testing engagements from preparation through reporting and retesting, while working closely with a senior security professional on complex or high-risk assignments. Role & Responsibilities
• Analyze technical architectures and data flows to identify critical assets, attack surfaces and trust relationships.
• Contribute to defining assessment scopes, objectives and rules of engagement.
• Conduct black-box, grey-box and white-box penetration tests on web applications, APIs and administrative portals.
• Perform internal and external infrastructure and network penetration testing.
• Assess Windows and Active Directory environments, including Kerberos/NTLM, GPOs, ACLs and lateral movement.
• Carry out controlled exploitation and post-exploitation activities within agreed engagement boundaries.
• Document vulnerabilities accurately, including affected systems, exploitation conditions, evidence, impact, risk and remediation recommendations.
• Produce complete and reproducible technical reports and contribute to executive-level reporting.
• Develop simple proof-of-concepts and scripts when required.
• Present findings to technical teams and project stakeholders.
• Conduct retests to verify the effectiveness of remediation measures.
• Escalate critical findings, high-risk situations and scope uncertainties to a senior security specialist.
• Contribute, with senior guidance, to complementary security assessments involving cloud, containers/CI-CD, mobile environments and purple teaming.
• Help improve internal methodologies, checklists, reporting templates and security testing tools. Technical Profile The ideal candidate has solid practical knowledge of penetration testing methodologies and security assessment techniques, including:
• Web and API security testing, including OWASP Top 10, injection vulnerabilities, IDOR, XSS, SSRF, deserialization, session/token management and modern authentication mechanisms.
• OAuth 2.0, OIDC, SAML and JWT.
• Network and infrastructure testing involving TCP/IP, DNS/DHCP/NTP/SNMP, HTTP/HTTPS/TLS, SMB, LDAP, Kerberos, RDP, WinRM, VPN, segmentation and filtering.
• Windows and Active Directory security, including domain enumeration, Kerberos/NTLM, GPO, ACLs, trust relationships, Kerberoasting and lateral movement.
• Security testing methodologies and frameworks such as OWASP WSTG, ASVS, API Security Top 10, PTES, MITRE ATT&CK, CVSS and CWE/CAPEC.
• Common penetration testing tools including Kali/Parrot, Burp Suite, OWASP ZAP, Nmap, Wireshark, Nessus, Metasploit, Impacket, NetExec and BloodHound.
• Knowledge of cloud platforms such as Azure, AWS or GCP, Linux, containers/Kubernetes, CI-CD and application security is considered an advantage. Experience & Profile
• Proven professional experience in penetration testing or offensive security, with approximately 5-8 years of relevant experience preferred.
• Able to independently execute standard penetration testing engagements while escalating complex or critical situations to a senior specialist.
• Structured and analytical approach, with strong attention to detail and the ability to produce clear, technically accurate documentation.
• Comfortable presenting technical findings to security teams, engineers and project stakeholders.
• Strong team player who knows when to seek support, escalate issues and share knowledge.
• Excellent understanding of technical English is required; knowledge of French and Dutch is an advantage.
• Higher education in Computer Science, Cybersecurity, Telecommunications or a related field, or equivalent professional experience.
• Certifications such as OSCP/OSCP+, Burp Suite Certified Practitioner (BSCP) or CRTP are considered strong assets. Contactperson & Reference
• Reference #: INW28271
• Pieter Messely
• pieter.messely@i4m.be