> Markdown version of [/jobs/ext/1266634-senior-penetration-tester-red-team-operator](https://www.wearedevelopers.com/jobs/ext/1266634-senior-penetration-tester-red-team-operator). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Penetration Tester/Red Team Operator - **Company:** Company NTT - **Location:** (Machelen), Belgium - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Amazon Web Services, Software Applications, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Cyber Security, Web Browsers, Open Source Technology, Phishing, Red Team (Cyber Security), Google Cloud, Office365, Information Technology, Purple Team (Cyber Security) - **Published:** July 15, 2026 - **Apply:** https://dejobs.org/x/x/A41BCF20A3684A57B2FD3850998F4C7D/job/ ## About the Role * 4-5 years of proven experience in Penetration Testing/Red Team Operations. * Proven experience leading or delivering Red Team and/or adversary simulation engagements in complex enterprise environments * Deep understanding of Active Directory, hybrid identity, and cloud attack surfaces * Hands-on experience developing or adapting TTPs beyond what standard frameworks provide out of the box * Demonstrated ability to research abuse paths, misconfigurations, or novel vulnerabilities * Strong written and verbal communication skills, this means you can write a compelling attack narrative and present findings to a CISO without losing either audience (technical or non-technical) * Comfortable acting as a trusted technical advisor to clients and stakeholders * Strong teamwork abilities * Native proficiency in French or Dutch, with excellent verbal and written knowledge of English Nice to have: * Experience emulating specific real-world threat actors (APT groups, ransomware operators) * Hands-on vulnerability research or PoC development leading to CVEs or public disclosure * Contributions to open-source tooling, public research, or conference presentations (DEF CON, Black Hat, BruCon, ...) * Familiarity with regulated-sector testing frameworks (TIBER-EU, DORA, CBEST, GBEST) * Relevant certifications (CRTO, CRTE, OSED, OSEP, CCRTS or equivalent), very valued but not a prerequisite Who You Are: * Naturally curious, you read threat intel reports for fun and follow OffSec research because you want to * Motivated by real-world impact, not engagement count * Comfortable with ambiguity and complex environments * A low-ego collaborator who challenges ideas constructively * Committed to continuous learning and raising the bar for those around you * Flexible and you have a willingness to travel for limited periods if required * In possession of a valid driving license (category B) is required * You are eligible and prepared to obtain NATO security clearance ## Description After an initial onboarding into NTT Data methodologies and client environments, you will be expected to: Lead and execute technical engagements, including scoping, technical security testing, analysis, reporting, and client presentations, across: * Web, Mobile, and Desktop Applications Penetration Tests * IT Infrastructure and Network environments Penetration Tests * Active Directory and hybrid identity (AD / Entra ID) Penetration Tests * Cloud platforms (Azure, AWS, GCP, M365) Penetration Tests * Full-spectrum Red Team and Adversary Simulation operations Design and deliver adversary simulation, including: * Developing realistic, intelligence-led attack scenarios grounded in actual threat actor TTPs * Crafting phishing and social engineering campaigns * Bypassing modern defensive controls (EDR/XDR, MFA) using low-noise techniques * Developing or adapting custom tooling for delivery, evasion, and C2 * Supporting Purple Team exercises to directly improve client detection and response capabilities Drive Research & Development, including: * Becoming a recognised expert in one or more domains of your choosing (Active Directory, cloud-native environments, web browsers, OT/ICS, containers, hardware, etc.) * Researching and responsibly disclosing previously undiscovered vulnerabilities (0-days) * Publishing research through blog posts, whitepapers, CVEs, or conference talks * Developing novel attack techniques applicable to real-world Red Team engagements Contribute to the business and the team, including: * Supporting pre-sales by capturing client needs and translating them into commercial proposals * Mentoring and guiding junior consultants through projects and skill development * Maintaining a broad, up-to-date knowledge base across core information security domains * Communicating complex attacker behaviour clearly and accurately to both technical and non-technical stakeholders ## Related Videos - [How Web AI Can Power the Agentic Web - Jason Mayes (Google)](https://www.wearedevelopers.com/videos/1896-how-web-ai-can-power-the-agentic-web-jason-mayes-google) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Privacy-first in-browser Generative AI web apps: offline-ready, future-proof, standards-based](https://www.wearedevelopers.com/videos/1572-privacy-first-in-browser-generative-ai-web-apps-offline-ready-future-proof-standards-based) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [How to land a developer job in Amsterdam](https://www.wearedevelopers.com/magazine/36-how-to-land-a-developer-job-in-amsterdam) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers)