Consultant Pentester

Kéoni Consulting
Paris, France
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English, French
Job source

Tech stack

Bash Shell Python (Programming Language) Open Web Application Security Windows PowerShell Web Applications

Job description

Contrainte forte du projet : Connaissance nécessaire des outils de sécurité offensive (Burp, suite Kali, …)

MISSIONS

Objectif global : Réaliser des tests de sécurité applicatifs (pentest, vuln,etc.)

Description détaillée

Réalisation des tests d’intrusion applicatif et infrastructure dans l’objectif d’identifier les failles potentielles

Réalisation de tests offensifs, principalement sur des applications web & mobile

Rédaction des rapports suite aux tests

Participation et animation des restitutions auprès des métiers

Réalisation de tests de vulnérabilité en mode RUN via les scanners déployés

Maintien en condition opérationnelle de l’outillage

Participer aux projets d’amélioration du service (outillage, méthodologie)

Attitude positive, participative et constructive

Connaissance du monde défensif (monde “Blue”) sera apprécié

Les livrables sont

Compte rendu et restitution des tests de sécurité

Organisation de réunion de restitution

Suivi du planning annuel des tests de sécurité

Requirements

Outils de sécu offensive (Burp, suite Kali, ?) - Confirmé - Impératif

OWASP - Confirmé - Impératif

Programmation bash/Python/PowerShell/web - Junior - Important

Connaissances linguistiques

Français Courant (Impératif)

Anglais Professionnel (Impératif)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on fr.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

1:36 min

Running AI applications with PWAs and background web workers

Maxim Salnikov Maxim Salnikov · WWC 2025

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · WWC 2022

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

6:11 min

Overview of the 2025 OWASP Top Ten list

Christian Wenz Christian Wenz · WWC Europe 2026

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

Videos

See all

Related articles

See all