7 hours, 6 minutes ago

Medior Security Pentester

Service: Cybersecurity – Offensive Security / web applications, networks, and Windows-Active Directory environments

Overview

To strengthen its offensive security capabilities, the Federal Police is seeking a Medior Security Pentester / Ethical Hacker with proven practical experience in penetration testing. The consultant will operate primarily in three areas:

  • web applications, APIs, and administration portals;
  • network infrastructures and protocols;
  • Windows and Active Directory environments.

The incumbent independently handles standard complexity assignments and contributes, under the coordination of a senior profile, to more complex assignments (cloud, containers, mobile, purple teaming).

Activities are carried out exclusively within an authorized framework, based on a defined scope and formalized rules of engagement.

Assignment

The role is responsible for the preparation and autonomous execution of penetration tests on web applications, networks, and Windows/Active Directory environments, the production of technical reports, and contribution to remediation, with support from a senior profile for complex assignments.

Deliverables

  • Complete, accurate, and reproducible technical reports per vulnerability (affected systems, exploitation conditions, evidence, impact, risk, recommendations)
  • Contribution to executive summary for management, reviewed by a senior
  • Scopes, objectives, and rules of engagement for assignments, defined in collaboration with a senior
  • Simple proof of concepts and scripts adapted as needed
  • Validation retests to confirm the effectiveness of corrections
  • Contribution to internal capitalization: methodologies, checklists, report templates, tooling

Main tasks

  • Analyze technical architectures and data flows; identify critical assets, attack surfaces, and trust relationships
  • Contribute to defining the scope, objectives, and rules of engagement for assignments
  • Conduct penetration tests (black box, grey box, white box) on web applications, APIs, and administration portals
  • Conduct internal and external penetration tests on infrastructures and network protocols
  • Conduct penetration tests on Windows and Active Directory environments (Kerberos/NTLM, GPO, ACL, lateral movement)
  • Escalate to a senior profile in risk situations, grey areas of the scope, and critical discoveries
  • Document each vulnerability and independently draft the technical report
  • Present results to technical teams and project managers
  • Perform retests to validate the effectiveness of corrections
  • Contribute, with support from a senior, to additional assignments (cloud, containers/CI-CD, mobile, purple teaming)

Key skills

  • Structured penetration testing methodology (black/grey/white box); controlled exploitation and post-exploitation
  • Web application and API testing: OWASP Top 10, modern authentication/authorization (OAuth 2.0/OIDC/SAML/JWT), targeted code review
  • Network and infrastructure testing: protocols (TCP/IP, DNS, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP), segmentation, filtering
  • Windows/Active Directory testing: domain enumeration, Kerberos/NTLM, GPO/ACL, lateral movement, PowerShell
  • Technical report writing and ability to escalate/collaborate with a senior profile

Communication and collaboration

  • Present results to technical teams and project managers; executive summary reviewed by a senior
  • Ability to seek support and escalate at the right time; teamwork and knowledge sharing
  • Preferably bilingual (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English

Level and experience

  • Autonomous execution under general supervision, with escalation to a senior for complexity (SFIA level 3 – Apply)
  • Minimum 3 years of experience (ideally 3 to 5 years); independently handles standard assignments and contributes to complex assignments under senior coordination

Degree

Higher education degree in IT, cybersecurity, or telecommunications, or equivalent professional experience.

Preferred certifications:

  • OSCP/OSCP+
  • Burp Suite Certified Practitioner (BSCP)
  • CRTP

No certification required

In practice

Level of responsibility: SFIA level 3 – Apply (medior, trajectory toward senior)

Reports to: Senior Pentester / Security Manager

Work regime: Full time; assignments carried out exclusively within an authorized scope and according to formalized rules of engagement

Work location: Brussels

Team: Security team, in collaboration with project teams and the CISO office

Apply for this Job

This position was originally posted on Pro Unity.

It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.

Newsletter signup illustration