Offensive Security Engineer — Exercise Red/Blue Team forNATO with security clearance
Il y a 2 jours
Wallonia, Wallonia, Belgique
WLG
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
This role sits in a penetration testing cell and
covers both halves of the discipline: the testing itself, and the
part that decides whether anything gets fixed — reviews, advice and
briefings to people who will act on them. A distinctive element is
the exercise work. You would lead or join the red or blue team
during military exercises, which is testing under a clock and in
front of an audience. What you would be doing Lead or take part in
the red or blue team during military exercises. Deliver web,
infrastructure and application-level penetration testing. Run
security design reviews for compliance with the governing policies
and directives. Advise projects and programmes on security, and say
plainly what has to change. Build and sustain communication with
the accreditation boards and the units supporting them. Brief at
executive and technical level on findings and testing outcomes, up
to flag-officer level. Coordinate proactively with internal and
external stakeholders alongside the head of the cell. What you
would bring More than three years across web application and IT
infrastructure penetration testing. Network security architecture
design, and assessment of vulnerabilities in operating systems,
software, protocols and networks. System and network administration
of both Unix and Windows. Penetration testing tools, techniques and
recognised methodologies. Scripting in at least one of Perl,
Python, Ruby or a shell. Technical depth in system and network
security, authentication protocols, cryptography, application
security and malware. The ability to evaluate risk and write the
mitigation plan, not only the finding. Clear, structured technical
reports with an executive summary, findings and a remediation plan
— for several different audiences. The work is full time on site in
Mons, with about ten days of travel within Belgium
foreseen.