Offensive Security Engineer — Exercise Red/Blue Team For Nato With Security Clearance

Il y a 2 jours

Frameries, Wallonia, Belgique Nato Temps plein
This role sits in a penetration testing cell and covers both halves of the discipline: the testing itself, and the part that decides whether anything gets fixed — reviews, advice and briefings to people who will act on them. A distinctive element is the exercise work. You would lead or join the red or blue team during military exercises, which is testing under a clock and in front of an audience. What you would be doing Lead or take part in the red or blue team during military exercises. Deliver web, infrastructure and application-level penetration testing. Run security design reviews for compliance with the governing policies and directives. Advise projects and programmes on security, and say plainly what has to change. Build and sustain communication with the accreditation boards and the units supporting them. Brief at executive and technical level on findings and testing outcomes, up to flag-officer level. Coordinate proactively with internal and external stakeholders alongside the head of the cell. What you would bring More than three years across web application and IT infrastructure penetration testing. Network security architecture design, and assessment of vulnerabilities in operating systems, software, protocols and networks. System and network administration of both Unix and Windows. Penetration testing tools, techniques and recognised methodologies. Scripting in at least one of Perl, Python, Ruby or a shell. Technical depth in system and network security, authentication protocols, cryptography, application security and malware. The ability to evaluate risk and write the mitigation plan, not only the finding. Clear, structured technical reports with an executive summary, findings and a remediation plan — for several different audiences. The work is full time on site in Mons, with about ten days of travel within Belgium foreseen.