7 hours, 37 minutes ago

Senior Security Pentester

Service: Cybersecurity – Offensive Security / IoT ecosystem (ANPR cameras, sensors, cloud, applications)

Introduction

As part of securing its IoT platforms, the Federal Police is seeking a Senior Pentester / Ethical Hacker with proven experience in offensive security. The consultant will be working in a complex technical environment with ANPR cameras, connected equipment in the field, embedded systems, network infrastructure, cloud platforms, APIs, web applications, and central processing and consultation systems.

The assignment consists of identifying, controlled exploitation, and documenting vulnerabilities that may affect the confidentiality, integrity, availability, or authenticity of the ANPR systems and data. Activities are carried out exclusively within an authorized framework, based on a defined scope and formalized rules of engagement.

Mission

The role involves the preparation and execution of penetration tests on the entire ANPR ecosystem (field equipment, network, cloud, applications, mobile), the production of actionable reports, and the guidance of teams in remedying identified vulnerabilities.

Deliverables

  • Complete, precise, and reproducible technical reports per vulnerability (involved systems, exploitation conditions, proof of concept, impact, risk level, recommendations)
  • Clear executive summary for management
  • Formalized scope, objectives and rules of engagement per assignment
  • Developed or adapted proof-of-concepts and scripts where necessary
  • Retests to validate the effectiveness of the remediations
  • Recommendations for improving architectures, security standards, and development procedures

Main Tasks

  • Analyze technical architectures and data flows; identify critical assets, attack surfaces, and trust relationships
  • Participate in defining the scope, objectives, and rules of engagement for assignments
  • Perform pentests (black box, grey box, white box) on the ANPR ecosystem: cameras, edge devices, gateways, central systems
  • Test IoT and embedded systems for security (firmware, hardware interfaces UART/JTAG/SWD, OTA updates, secure boot)
  • Analyze and test communication protocols (TCP/IP, HTTP/HTTPS, MQTT, RTSP, VPN, Wi-Fi/BLE, TLS/mTLS/PKI, etc.)
  • Perform cloud pentests (IAM, virtual networks, storage, containers/Kubernetes, CI/CD pipelines) on Azure, AWS or GCP
  • Test web applications, APIs, and backend services (authentication, authorization, OWASP Top 10, OAuth 2.0/OIDC/SAML/JWT)
  • Test mobile Android and iOS applications when within scope
  • Perform pentests on Windows, Linux, and Active Directory infrastructure
  • Document and present results to technical teams and management, and advise teams during remediation

Core Competencies

  • Mastery of penetration testing methodologies (black/grey/white box), controlled exploitation, post-exploitation, and lateral movement
  • IoT and embedded systems expertise: firmware analysis, hardware interfaces (UART/JTAG/SWD), update mechanisms and secure boot
  • Network, protocol, and cloud security (Azure/AWS/GCP): IAM, segmentation, containers/Kubernetes, CI/CD
  • Application, API, and mobile security (OWASP, OAuth 2.0/OIDC/SAML/JWT, Android/iOS)
  • Preparation of technical and executive reports, guidance during remediation, and mentoring of less experienced profiles

Communication and Collaboration

  • Present results to technical teams, architects, project managers, and management
  • Ability to guide less experienced profiles; teamwork and knowledge sharing
  • Preferably bilingual (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English, both written and spoken

Level and Experience

  • Authoritative advice and fully independent execution (SFIA level 5 – Ensure, advise)
  • Minimum 10 years of experience in offensive security; able to independently lead an assignment, from scope definition to presentation of results; explicitly not a junior

Degree

Higher degree in computer science, cybersecurity, electronics, or telecommunications, or equivalent professional experience.

Technical certifications in offensive security are an asset (e.g. OSCP/OSCP+, OSWE, OSEP, GPEN/GWAPT, SEC556/PIPA for IoT).

No certification is individually required – the combination of practical experience and domain coverage is decisive.

Apply for this Job

This position was originally posted on Pro Unity.

It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.

Newsletter signup illustration