Medior Security Pentester

Brussel
|Brussel
|Penetration Tester
|Freelance |Payroll (consultancy)
# INW28271

Function

We’re looking for a Penetration Testing Analyst to join our client’s cybersecurity team and independently conduct security assessments across web applications, networks and Windows/Active Directory environments. You will be responsible for executing standard penetration testing engagements from preparation through reporting and retesting, while working closely with a senior security professional on complex or high-risk assignments.

Role & Responsibilities

  • Analyze technical architectures and data flows to identify critical assets, attack surfaces and trust relationships.

  • Contribute to defining assessment scopes, objectives and rules of engagement.

  • Conduct black-box, grey-box and white-box penetration tests on web applications, APIs and administrative portals.

  • Perform internal and external infrastructure and network penetration testing.

  • Assess Windows and Active Directory environments, including Kerberos/NTLM, GPOs, ACLs and lateral movement.

  • Carry out controlled exploitation and post-exploitation activities within agreed engagement boundaries.

  • Document vulnerabilities accurately, including affected systems, exploitation conditions, evidence, impact, risk and remediation recommendations.

  • Produce complete and reproducible technical reports and contribute to executive-level reporting.

  • Develop simple proof-of-concepts and scripts when required.

  • Present findings to technical teams and project stakeholders.

  • Conduct retests to verify the effectiveness of remediation measures.

  • Escalate critical findings, high-risk situations and scope uncertainties to a senior security specialist.

  • Contribute, with senior guidance, to complementary security assessments involving cloud, containers/CI-CD, mobile environments and purple teaming.

  • Help improve internal methodologies, checklists, reporting templates and security testing tools.

Technical Profile

The ideal candidate has solid practical knowledge of penetration testing methodologies and security assessment techniques, including:

  • Web and API security testing, including OWASP Top 10, injection vulnerabilities, IDOR, XSS, SSRF, deserialization, session/token management and modern authentication mechanisms.

  • OAuth 2.0, OIDC, SAML and JWT.

  • Network and infrastructure testing involving TCP/IP, DNS/DHCP/NTP/SNMP, HTTP/HTTPS/TLS, SMB, LDAP, Kerberos, RDP, WinRM, VPN, segmentation and filtering.

  • Windows and Active Directory security, including domain enumeration, Kerberos/NTLM, GPO, ACLs, trust relationships, Kerberoasting and lateral movement.

  • Security testing methodologies and frameworks such as OWASP WSTG, ASVS, API Security Top 10, PTES, MITRE ATT&CK, CVSS and CWE/CAPEC.

  • Common penetration testing tools including Kali/Parrot, Burp Suite, OWASP ZAP, Nmap, Wireshark, Nessus, Metasploit, Impacket, NetExec and BloodHound.

  • Knowledge of cloud platforms such as Azure, AWS or GCP, Linux, containers/Kubernetes, CI-CD and application security is considered an advantage.

Experience & Profile

  • Proven professional experience in penetration testing or offensive security, with approximately 5–8 years of relevant experience preferred.

  • Able to independently execute standard penetration testing engagements while escalating complex or critical situations to a senior specialist.

  • Structured and analytical approach, with strong attention to detail and the ability to produce clear, technically accurate documentation.

  • Comfortable presenting technical findings to security teams, engineers and project stakeholders.

  • Strong team player who knows when to seek support, escalate issues and share knowledge.

  • Excellent understanding of technical English is required; knowledge of French and Dutch is an advantage.

  • Higher education in Computer Science, Cybersecurity, Telecommunications or a related field, or equivalent professional experience.

  • Certifications such as OSCP/OSCP+, Burp Suite Certified Practitioner (BSCP) or CRTP are considered strong assets.

Contactperson & Reference

Back Print
Medior Security Pentester
In4Matic uses cookies to remember certain preferences and align jobs interests.