Penetration Tester / Security Tester

AlmavivA de Belgique
Mons, Belgium
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate

Job location

Mons, Belgium

Tech stack

Software System Penetration Testing
User Authentication
Bash
Python
Korn Shell
Network Security
Powershell
Web Applications
Software Security
Malware
GWAPT
Information Technology
Tools for Reporting
Go

Requirements

Provide Web, infrastructure and application-level penetration testing, including but not limited to COTS software and NOTS/GOTS software (NATO/Government off the Shelf), following clearly defined methodologies. Participate in kick-off meetings with stakeholders and technical points of contact in order to identify requirements for testing. Attend team meetings if required. Write technical reports in fluent English, following defined templates and Reporting Tools. Brief at both executive and technical levels on security reports and testing outcome, including at flag officer level. In case of new vulnerabilities detected for COTS software, follow the Responsible Disclosure Process and follow-up with vendors and stakeholders. In co-ordination with the Technical Lead of the Penetration testing team, ensure proactive collaboration and coordination with internal and external stakeholders. The contractor shall participate in daily status update meetings, activity planning and other meetings as instructed, physically in the office, or in person via digital means using conference call capabilities, according to the manager's / team leader's instructions. For each sprint to be considered as complete and payable, the contractor must report the outcome of his/her work during the sprint, first verbally during the retrospective meeting and then in written within three (3) days after the sprint's end date. At the end of the project, the Contractor shall provide a Project Closure Report that is summarizing the activities during the period of performance at high level. The contractor is required to follow the rules and regulations applicable for the operations of NATO CIS. The service contractor will be required to have a Bachelor of Science (BSc) degree at a nationally recognised/certified university in a technical subject with substantial Information Technology (IT) content and 3 years post-related experience. Web application penetration testing IT infrastructure penetration testing Assessing security vulnerabilities within OS, software, protocols & networks Use of penetration testing tools, techniques, and recognized testing methodologies Python, Go, PowerShell, shell (bash, ksh, csh) Technical knowledge in system and network security, authentication and security protocols, cryptography, application security, as well as, malware infection techniques and protection technologies. Proven ability to brief at executive level on security findings, reports and testing outcome. It is mandatory to have the candidate be in possession of a NATO SECRET security clearance to facilitate follow-on engagements and coordination at NATO venues. A thorough knowledge of one of the two NATO languages, both written and spoken, is essential and some knowledge of the other is desirable. OSCP, OSCE, OSWE, GPEN, CREST Certified Web Application Tester, GXPN, GWAPT or equivalent Familiarity with risk analysis methodologies. Prior experience of working in an international environment comprising both military and civilian elements. A thorough knowledge of one of the two NATO languages, both written and spoken, is essential and some knowledge of the other is desirable. Type of Clearance: NATO SECRET

Apply for this position