> Markdown version of [/jobs/ext/18668-web-application-penetration-tester](https://www.wearedevelopers.com/jobs/ext/18668-web-application-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Web Application Penetration Tester - **Company:** Deloitte - **Location:** Zaventem, Belgium - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Authentication Protocols, Microsoft Azure, Bash Shell, Burp Suite, Continuous Integration, Data Validation, White-Box Testing, HTTP Secure, Mobile Application Software, Python (Programming Language), Nmap, Open Web Application Security, Cloud Services, Red Team (Cyber Security), Reverse Engineering, Web Application Security, Web Applications, Scripting, Google Cloud, Postman, Software Security, GWAPT, Graphql, Devsecops, Vulnerability Analysis - **Published:** May 23, 2026 - **Apply:** https://be.indeed.com/viewjob?jk=e8b03067407a0208 ## About the Role Do you have experience in iOS?, * 3-6 years of hands-on experience in web application penetration testing. * Familiarity with offensive security methodologies and common vulnerability classes (e.g., OWASP Top 10, SSRF, RCE, deserialization, logic flaws). * Solid experience with manual testing and tools such as Burp Suite, OWASP ZAP, Postman, Nmap, etc. * Comfortable with scripting (Python, Bash, etc.) for automation and exploitation. * Strong understanding of HTTP(S), authentication mechanisms, session handling, input validation, etc. * Experience in reviewing source code or conducting white-box assessments is a plus. * Familiarity with cloud services (AWS, Azure, GCP) and associated security models is a plus. * Able to communicate clearly in Dutch + English (spoken and written); other languages a plus. * Hold or pursuing certifications such as OSCP, eWPT, GWAPT, OSEP (OSWE or OSED is a plus). * Eligible to work in Belgium; security clearance may be required depending on project. Nice to haves: * Participation in bug bounty programs or public CTFs. * Familiarity with CI/CD security and DevSecOps principles. * Experience with API security, especially REST. * Experience with GraphQL. * Experience working with clients in regulated industries (finance, healthcare, etc.). * Experience in testing mobile applications on both iOS and Android, including reverse engineering and mobile-specific attack vectors. ## Description As a medior penetration tester, you'll be responsible for delivering high-quality web application security assessments. You'll work on a range of technical environments, supporting senior consultants, collaborating with clients, and mentoring junior colleagues. You have a solid understanding of offensive security and are passionate about identifying and exploiting vulnerabilities in complex applications., * Perform manual and automated penetration tests on web applications, APIs, and related infrastructure. * Identify, exploit, and document security vulnerabilities in accordance with OWASP, NIST, and other standards. * Develop custom exploits or proof-of-concept code where applicable. * Analyze and present assessment results clearly to technical and non-technical stakeholders. * Write concise, actionable, and technically accurate reports and recommendations. * Collaborate with red team or infrastructure testing teams on hybrid assessments. * Contribute to the continuous improvement of tools, methodologies, and internal documentation. * Support junior team members through peer review and mentoring. * Stay current with the latest attack techniques, tooling, and security advisories. * Participate in client meetings, kick-offs, and debriefings., * Flexible work arrangements for all and initiatives supported by Parents & Caregivers @Deloitte * Wellbeing tips and activities powered by Energise@Deloitte * Topped off with other health benefits and insurance opportunities Empowering our employees with flexible work arrangements remains essential in today's reality: * Hybrid workplace: combination of home office and on-site (+10 offices in Belgium or client's premises). * Part-time employment: all our jobs are open to full-time or part-time work under a 90% or 80% regime. ## Related Videos - [Are Your APIs Ready for AI Agents](https://www.wearedevelopers.com/videos/2004-are-your-apis-ready-for-ai-agents) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [How to land a developer job in Amsterdam](https://www.wearedevelopers.com/magazine/36-how-to-land-a-developer-job-in-amsterdam) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)