Senior Penetration Tester/Red Team Operator

Il y a 3 heures

Machelen, Flanders, Belgique NTT America, Inc. Temps plein
ph3Make an impact with NTT DATA /h3 pJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive. /p h3As our Technology Consulting Services department continues to expand, we are seeking a Senior Penetration Tester/Red Team Operator to join our team. /h3 pThis is a hybrid role (PT/RT) for someone who thinks like an adversary, learns and follows real-world threat actors, and cares about the quality and relevance of every engagement they touch. /p pYou will lead and execute btechnical security assessments across a broad range of environments /b and dedicate a meaningful portion of your time to bResearch Development (RD) /b , developing new tooling, novel attack techniques, and advancing your own areas of deep expertise. /p pThis is not a checkbox testing role. Our clients engage us because they want to understand how a real attacker would operate against them. Your job is to make that simulation credible, contextual, and genuinely useful to defenders. /p h3Job Description /h3 pAfter an initial onboarding into NTT Data methodologies and client environments, you will be expected to: /p h3Lead and execute /h3 ptechnical engagements, including scoping, technical security testing, analysis, reporting, and client presentations, across: /p ul lipWeb, Mobile, and Desktop Applications Penetration Tests /p /li lipIT Infrastructure and Network environments Penetration Tests /p /li lipActive Directory and hybrid identity (AD / Entra ID) Penetration Tests /p /li lipCloud platforms (Azure, AWS, GCP, M365) Penetration Tests /p /li lipFull-spectrum Red Team and Adversary Simulation operations /p /li /ul h3Design and deliver /h3 padversary simulation, including: /p ul lipDeveloping realistic, intelligence-led attack scenarios grounded in actual threat actor TTPs /p /li lipCrafting phishing and social engineering campaigns /p /li lipBypassing modern defensive controls (EDR/XDR, MFA) using low-noise techniques /p /li lipDeveloping or adapting custom tooling for delivery, evasion, and C2 /p /li lipSupporting Purple Team exercises to directly improve client detection and response capabilities /p /li /ul h3Drive /h3 pResearch Development, including: /p ul lipBecoming a recognised expert in one or more domains of your choosing (Active Directory, cloud-native environments, web browsers, OT/ICS, containers, hardware, etc.) /p /li lipResearching and responsibly disclosing previously undiscovered vulnerabilities (0-days) /p /li lipPublishing research through blog posts, whitepapers, CVEs, or conference talks /p /li lipDeveloping novel attack techniques applicable to real-world Red Team engagements /p /li /ul h3Contribute /h3 pto the business and the team, including: /p ul lipSupporting pre-sales by capturing client needs and translating them into commercial proposals /p /li lipMentoring and guiding junior consultants through projects and skill development /p /li lipMaintaining a broad, up-to-date knowledge base across core information security domains /p /li lipCommunicating complex attacker behaviour clearly and accurately to both technical and non-technical stakeholders /p /li /ul h3Here’s what we are looking for in candidates /h3 h3Must have: /h3 ul lip4-5 years of proven experience in Penetration Testing/Red Team Operations. /p /li lipProven experience leading or delivering Red Team and/or adversary simulation engagements in complex enterprise environments /p /li lipDeep understanding of Active Directory, hybrid identity, and cloud attack surfaces /p /li lipHands-on experience developing or adapting TTPs beyond what standard frameworks provide out of the box /p /li lipDemonstrated ability to research abuse paths, misconfigurations, or novel vulnerabilities /p /li lipStrong written and verbal communication skills, this means you can write a compelling attack narrative and present findings to a CISO without losing either audience (technical or non-technical) /p /li lipComfortable acting as a trusted technical advisor to clients and stakeholders /p /li lipStrong teamwork abilities /p /li lipbNative proficiency in French or Dutch, with excellent verbal and written knowledge of English /b /p /li /ul h3Nice to have: /h3 ul lipExperience emulating specific real-world threat actors (APT groups, ransomware operators) /p /li lipHands-on vulnerability research or PoC development leading to CVEs or public disclosure /p /li lipContributions to open-source tooling, public research, or conference presentations (DEF CON, Black Hat, BruCon, ...) /p /li lipFamiliarity with regulated-sector testing frameworks (TIBER-EU, DORA, CBEST, GBEST) /p /li lipRelevant certifications (CRTO, CRTE, OSED, OSEP, CCRTS or equivalent), very valued but not a prerequisite /p /li /ul h3Who You Are: /h3 ul lipNaturally curious, you r