Ethical Hacker

Northwave Cyber Security
Utrecht, Netherlands
about 2 months ago
Apply on nl.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Open Source Intelligence Malware

Job description

As a Red Team Operator, you design and execute attack scenarios that genuinely help clients improve. You train Blue Teams during Purple Teaming sessions and confidently present your findings-whether to technical teams or executive leadership. Your toolkit includes OSINT, custom tooling, malware development, social engineering, privilege escalation, and command & control techniques. You’ll work independently and as part of a team on offensive operations and contribute to the ongoing development of our TTPs. You’ll also have opportunities to share your knowledge-both within the team and at conferences, workshops, and events.

Requirements

  • At least 3 years of experience in red teaming
  • Proven experience with Active Directory attacks (LDAP enumeration, ACL abuse, Kerberoasting, etc.)
  • Hands-on knowledge of C2 platforms such as Cobalt Strike, Mythic, Sliver, or Outflank Security Tooling
  • Strong consultancy skills: you listen, ask the right questions, and can present and report clearly
  • Capable of running operations independently and working effectively in a team

Nice-to-haves

  • Experience with adversary simulation
  • Familiarity with TIBER or ART engagements is a strong plus
  • Cloud knowledge, especially of Azure or AWS

Benefits & conditions

Pulled from the full job description Professional development assistance Pension plan Commuter assistance, * A salary aligned with the challenges of red teaming and your experience

  • Lease car or travel reimbursement
  • MacBook and iPhone
  • 25 vacation days
  • A solid pension plan
  • The possibility to work hybrid
  • Complex and challenging red team projects for major clients
  • A people-focused working environment
  • Training budget for OSCP, OSEP, CRTO, or equivalent certifications
  • Access to leading (international) cybersecurity conferences
  • A workplace with more than 275 passionate colleagues
  • Fun events and plenty of room for your own initiatives

About the company

Our mission is clear: to enable businesses to operate securely. With over 275 dedicated specialists, Northwave works daily on innovative cybersecurity solutions that truly help organizations move forward. We operate from our headquarters in Utrecht and offices in Germany, Sweden, and Belgium.

Northwave brings together ethical hacking, behavioral psychology, and top-level security management. We respond to threats-and anticipate them-through 24/7 managed security services and tailored specialist solutions. Joining Northwave means stepping into an environment where innovation and results go hand in hand. Whether you excel in technical testing or strategic client communication, you’ll have the freedom to help shape the future of digital security and make a real impact., Northwave’s Red Team lives for hacking. Our team consists of 20+ hackers from all over the world, with diverse backgrounds and expertise. We focus solely on challenging pentests and realistic red teaming operations that enhance the digital resilience of organizations across Europe. We collaborate with our Blue Team, Threat Intelligence, Reverse Engineering, and CERT to create realistic, high-value attack scenarios. In addition to our mature services, we are a highly regarded TIBER and ART provider, making our work consistently exciting and cutting-edge.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on nl.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:12 min

Recommended training platforms for developing security mindsets

Thomas Konrad ¡ World Congress 2021

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 ¡ LIVE

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea ¡ World Congress 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo ¡ World Congress 2024

2:35 min

Exploring diverse resources for continuous security learning

Stefania Chaplin ¡ World Congress 2022

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil ¡ LIVE

Videos

See all

Related articles

See all