Medior Security Pentester
Function
We’re looking for a Penetration Testing Analyst to join our client’s cybersecurity team and independently conduct security assessments across web applications, networks and Windows/Active Directory environments. You will be responsible for executing standard penetration testing engagements from preparation through reporting and retesting, while working closely with a senior security professional on complex or high-risk assignments.
Role & Responsibilities
-
Analyze technical architectures and data flows to identify critical assets, attack surfaces and trust relationships.
-
Contribute to defining assessment scopes, objectives and rules of engagement.
-
Conduct black-box, grey-box and white-box penetration tests on web applications, APIs and administrative portals.
-
Perform internal and external infrastructure and network penetration testing.
-
Assess Windows and Active Directory environments, including Kerberos/NTLM, GPOs, ACLs and lateral movement.
-
Carry out controlled exploitation and post-exploitation activities within agreed engagement boundaries.
-
Document vulnerabilities accurately, including affected systems, exploitation conditions, evidence, impact, risk and remediation recommendations.
-
Produce complete and reproducible technical reports and contribute to executive-level reporting.
-
Develop simple proof-of-concepts and scripts when required.
-
Present findings to technical teams and project stakeholders.
-
Conduct retests to verify the effectiveness of remediation measures.
-
Escalate critical findings, high-risk situations and scope uncertainties to a senior security specialist.
-
Contribute, with senior guidance, to complementary security assessments involving cloud, containers/CI-CD, mobile environments and purple teaming.
-
Help improve internal methodologies, checklists, reporting templates and security testing tools.
Technical Profile
The ideal candidate has solid practical knowledge of penetration testing methodologies and security assessment techniques, including:
-
Web and API security testing, including OWASP Top 10, injection vulnerabilities, IDOR, XSS, SSRF, deserialization, session/token management and modern authentication mechanisms.
-
OAuth 2.0, OIDC, SAML and JWT.
-
Network and infrastructure testing involving TCP/IP, DNS/DHCP/NTP/SNMP, HTTP/HTTPS/TLS, SMB, LDAP, Kerberos, RDP, WinRM, VPN, segmentation and filtering.
-
Windows and Active Directory security, including domain enumeration, Kerberos/NTLM, GPO, ACLs, trust relationships, Kerberoasting and lateral movement.
-
Security testing methodologies and frameworks such as OWASP WSTG, ASVS, API Security Top 10, PTES, MITRE ATT&CK, CVSS and CWE/CAPEC.
-
Common penetration testing tools including Kali/Parrot, Burp Suite, OWASP ZAP, Nmap, Wireshark, Nessus, Metasploit, Impacket, NetExec and BloodHound.
-
Knowledge of cloud platforms such as Azure, AWS or GCP, Linux, containers/Kubernetes, CI-CD and application security is considered an advantage.
Experience & Profile
-
Proven professional experience in penetration testing or offensive security, with approximately 5–8 years of relevant experience preferred.
-
Able to independently execute standard penetration testing engagements while escalating complex or critical situations to a senior specialist.
-
Structured and analytical approach, with strong attention to detail and the ability to produce clear, technically accurate documentation.
-
Comfortable presenting technical findings to security teams, engineers and project stakeholders.
-
Strong team player who knows when to seek support, escalate issues and share knowledge.
-
Excellent understanding of technical English is required; knowledge of French and Dutch is an advantage.
-
Higher education in Computer Science, Cybersecurity, Telecommunications or a related field, or equivalent professional experience.
-
Certifications such as OSCP/OSCP+, Burp Suite Certified Practitioner (BSCP) or CRTP are considered strong assets.
Contactperson & Reference
- Reference #: INW28271
- Pieter Messely
- pieter.messely@i4m.be