Web Application Penetration Tester

Deloitte
Zaventem, Belgium
3 months ago

Role details

Contract type
Permanent contract
Employment type
Part-time / full-time
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Languages
Dutch, English
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Software System Penetration Testing Authentication Protocols Microsoft Azure Bash Shell Burp Suite Continuous Integration Data Validation White-Box Testing HTTP Secure Mobile Application Software
+16 more
Python (Programming Language) Nmap Open Web Application Security Cloud Services Red Team (Cyber Security) Reverse Engineering Web Application Security Web Applications Scripting Google Cloud Postman Software Security GWAPT Graphql Devsecops Vulnerability Analysis

Job description

As a medior penetration tester, you’ll be responsible for delivering high-quality web application security assessments. You’ll work on a range of technical environments, supporting senior consultants, collaborating with clients, and mentoring junior colleagues. You have a solid understanding of offensive security and are passionate about identifying and exploiting vulnerabilities in complex applications., * Perform manual and automated penetration tests on web applications, APIs, and related infrastructure.

  • Identify, exploit, and document security vulnerabilities in accordance with OWASP, NIST, and other standards.
  • Develop custom exploits or proof-of-concept code where applicable.
  • Analyze and present assessment results clearly to technical and non-technical stakeholders.
  • Write concise, actionable, and technically accurate reports and recommendations.
  • Collaborate with red team or infrastructure testing teams on hybrid assessments.
  • Contribute to the continuous improvement of tools, methodologies, and internal documentation.
  • Support junior team members through peer review and mentoring.
  • Stay current with the latest attack techniques, tooling, and security advisories.
  • Participate in client meetings, kick-offs, and debriefings., * Flexible work arrangements for all and initiatives supported by Parents & Caregivers @Deloitte
  • Wellbeing tips and activities powered by Energise@Deloitte
  • Topped off with other health benefits and insurance opportunities

Empowering our employees with flexible work arrangements remains essential in today’s reality:

  • Hybrid workplace: combination of home office and on-site (+10 offices in Belgium or client’s premises).
  • Part-time employment: all our jobs are open to full-time or part-time work under a 90% or 80% regime.

Requirements

Do you have experience in iOS?, * 3-6 years of hands-on experience in web application penetration testing.

  • Familiarity with offensive security methodologies and common vulnerability classes (e.g., OWASP Top 10, SSRF, RCE, deserialization, logic flaws).
  • Solid experience with manual testing and tools such as Burp Suite, OWASP ZAP, Postman, Nmap, etc.
  • Comfortable with scripting (Python, Bash, etc.) for automation and exploitation.
  • Strong understanding of HTTP(S), authentication mechanisms, session handling, input validation, etc.
  • Experience in reviewing source code or conducting white-box assessments is a plus.
  • Familiarity with cloud services (AWS, Azure, GCP) and associated security models is a plus.
  • Able to communicate clearly in Dutch + English (spoken and written); other languages a plus.
  • Hold or pursuing certifications such as OSCP, eWPT, GWAPT, OSEP (OSWE or OSED is a plus).
  • Eligible to work in Belgium; security clearance may be required depending on project.

Nice to haves:

  • Participation in bug bounty programs or public CTFs.
  • Familiarity with CI/CD security and DevSecOps principles.
  • Experience with API security, especially REST.
  • Experience with GraphQL.
  • Experience working with clients in regulated industries (finance, healthcare, etc.).
  • Experience in testing mobile applications on both iOS and Android, including reverse engineering and mobile-specific attack vectors.

About the company

Everybody’s talking about it. Every organisation in every sector is concerned by it. At Deloitte, we’re shaping strategies and transforming technology to minimise Cyber Risk for organisations, and we need you to join us. You’ll build strong relationships within the Belgian Cyber practice with over 100 highly talented individuals. Our team brings together people who graduated in everything from Law, Maths, Computer Science, Cyber Security and Information Management within one team. You will help clients prevent cyber attacks and advise them on how to protect their most valuable assets Cyber Defense & Resilience is part of the Cyber team. Who is Deloitte? We provide industry-leading audit and assurance, tax and legal, consulting and related services. We are committed to driving innovation across offerings to help our clients address their challenges, while giving our professionals opportunities to learn and grow in this era of transformation. In Belgium, +5000 dedicated professionals active in +10 offices, take great pride in bringing multidisciplinary expertise to a wide variety of clients, from national and international companies, small, fast-growing and large organizations to public institutions and governmental authorities. Why Deloitte? Be the true you! We foster diversity and inclusion and encourage you to bring your authentic self to work. Explore, question and collaborate while building a career that inspires and energises you. Never stop growing! Diversity of thought makes us stronger. At Deloitte, we tailor a personalized learning experience, offering you the opportunity to grow at your own pace and achieve maximum impact. We practice what we preach! As a Purpose-led organisation, at the heart of everything we do is a set of timeless principles and unifying values. Life looks different for each of us, so we created a varied benefits package that you can tap into

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

2:37 min

Why handwritten types and documentation fail to scale

Violina Popova Violina Popova · Europe 2026 Virtual

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · WWC Europe 2026

4:15 min

Scaling DevSecOps and researching mobile application security standards

Moataz Nabil Moataz Nabil · LIVE

1:16 min

Automating documentation and code generation with OpenAPI standards

James Seconde · WWC 2023

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all