Offensive Security Engineer — Exercise Red/Blue Team For Nato With Security Clearance
Il y a 2 jours
Frameries, Wallonia, Belgique
Nato
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
This role sits in a penetration testing cell and covers both halves of the discipline: the testing itself, and the part that decides whether anything gets fixed — reviews, advice and briefings to people who will act on them. A distinctive element is the exercise work. You would lead or join the red or blue team during military exercises, which is testing under a clock and in front of an audience. What you would be doing Lead or take part in the red or blue team during military exercises. Deliver web, infrastructure and application-level penetration testing. Run security design reviews for compliance with the governing policies and directives. Advise projects and programmes on security, and say plainly what has to change. Build and sustain communication with the accreditation boards and the units supporting them. Brief at executive and technical level on findings and testing outcomes, up to flag-officer level. Coordinate proactively with internal and external stakeholders alongside the head of the cell. What you would bring More than three years across web application and IT infrastructure penetration testing. Network security architecture design, and assessment of vulnerabilities in operating systems, software, protocols and networks. System and network administration of both Unix and Windows. Penetration testing tools, techniques and recognised methodologies. Scripting in at least one of Perl, Python, Ruby or a shell. Technical depth in system and network security, authentication protocols, cryptography, application security and malware. The ability to evaluate risk and write the mitigation plan, not only the finding. Clear, structured technical reports with an executive summary, findings and a remediation plan — for several different audiences. The work is full time on site in Mons, with about ten days of travel within Belgium foreseen.