Senior Penetration Tester/Red Team Operator
Il y a 3 heures
Machelen, Flanders, Belgique
NTT America, Inc.
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
ph3Make an impact with NTT DATA /h3 pJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive. /p h3As our Technology Consulting Services department continues to expand, we are seeking a Senior Penetration Tester/Red Team Operator to join our team. /h3 pThis is a hybrid role (PT/RT) for someone who thinks like an adversary, learns and follows real-world threat actors, and cares about the quality and relevance of every engagement they touch. /p pYou will lead and execute btechnical security assessments across a broad range of environments /b and dedicate a meaningful portion of your time to bResearch Development (RD) /b , developing new tooling, novel attack techniques, and advancing your own areas of deep expertise. /p pThis is not a checkbox testing role. Our clients engage us because they want to understand how a real attacker would operate against them. Your job is to make that simulation credible, contextual, and genuinely useful to defenders. /p h3Job Description /h3 pAfter an initial onboarding into NTT Data methodologies and client environments, you will be expected to: /p h3Lead and execute /h3 ptechnical engagements, including scoping, technical security testing, analysis, reporting, and client presentations, across: /p ul lipWeb, Mobile, and Desktop Applications Penetration Tests /p /li lipIT Infrastructure and Network environments Penetration Tests /p /li lipActive Directory and hybrid identity (AD / Entra ID) Penetration Tests /p /li lipCloud platforms (Azure, AWS, GCP, M365) Penetration Tests /p /li lipFull-spectrum Red Team and Adversary Simulation operations /p /li /ul h3Design and deliver /h3 padversary simulation, including: /p ul lipDeveloping realistic, intelligence-led attack scenarios grounded in actual threat actor TTPs /p /li lipCrafting phishing and social engineering campaigns /p /li lipBypassing modern defensive controls (EDR/XDR, MFA) using low-noise techniques /p /li lipDeveloping or adapting custom tooling for delivery, evasion, and C2 /p /li lipSupporting Purple Team exercises to directly improve client detection and response capabilities /p /li /ul h3Drive /h3 pResearch Development, including: /p ul lipBecoming a recognised expert in one or more domains of your choosing (Active Directory, cloud-native environments, web browsers, OT/ICS, containers, hardware, etc.) /p /li lipResearching and responsibly disclosing previously undiscovered vulnerabilities (0-days) /p /li lipPublishing research through blog posts, whitepapers, CVEs, or conference talks /p /li lipDeveloping novel attack techniques applicable to real-world Red Team engagements /p /li /ul h3Contribute /h3 pto the business and the team, including: /p ul lipSupporting pre-sales by capturing client needs and translating them into commercial proposals /p /li lipMentoring and guiding junior consultants through projects and skill development /p /li lipMaintaining a broad, up-to-date knowledge base across core information security domains /p /li lipCommunicating complex attacker behaviour clearly and accurately to both technical and non-technical stakeholders /p /li /ul h3Here’s what we are looking for in candidates /h3 h3Must have: /h3 ul lip4-5 years of proven experience in Penetration Testing/Red Team Operations. /p /li lipProven experience leading or delivering Red Team and/or adversary simulation engagements in complex enterprise environments /p /li lipDeep understanding of Active Directory, hybrid identity, and cloud attack surfaces /p /li lipHands-on experience developing or adapting TTPs beyond what standard frameworks provide out of the box /p /li lipDemonstrated ability to research abuse paths, misconfigurations, or novel vulnerabilities /p /li lipStrong written and verbal communication skills, this means you can write a compelling attack narrative and present findings to a CISO without losing either audience (technical or non-technical) /p /li lipComfortable acting as a trusted technical advisor to clients and stakeholders /p /li lipStrong teamwork abilities /p /li lipbNative proficiency in French or Dutch, with excellent verbal and written knowledge of English /b /p /li /ul h3Nice to have: /h3 ul lipExperience emulating specific real-world threat actors (APT groups, ransomware operators) /p /li lipHands-on vulnerability research or PoC development leading to CVEs or public disclosure /p /li lipContributions to open-source tooling, public research, or conference presentations (DEF CON, Black Hat, BruCon, ...) /p /li lipFamiliarity with regulated-sector testing frameworks (TIBER-EU, DORA, CBEST, GBEST) /p /li lipRelevant certifications (CRTO, CRTE, OSED, OSEP, CCRTS or equivalent), very valued but not a prerequisite /p /li /ul h3Who You Are: /h3 ul lipNaturally curious, you r