Penetration Tester

Spektrum
Hoek van Holland, Netherlands
26 days ago
Apply on nl.indeed.com
Prepare application

Role details

Contract type
Contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Software System Penetration Testing User Authentication Bash Shell Unix Configuration Management Perl (Programming Language) Python (Programming Language) Network Security Network Administration Red Team (Cyber Security) Ruby
+8 more
Shell Script Strategies of Testing Web Applications Scripting Software Security Malware Information Technology Blue Team (Cyber Security)

Job description

The Penetration Tester will support NATO security activities by performing penetration testing, security assessments, and security design reviews across web applications, IT infrastructure, networks, and applications. The role also supports NATO military exercises through Red and Blue Team activities and provides security advice to technical teams, projects, and senior stakeholders. Role Duties and Responsibilities

  • Lead or participate in Red Team and Blue Team activities during NATO military exercises.

  • Perform web application, infrastructure, and application-level penetration testing.

  • Conduct security design reviews to ensure compliance with NATO security policies and directives.

  • Provide cybersecurity consultancy and technical security advice to projects, plans, and other stakeholders.

  • Identify and assess security vulnerabilities across operating systems, software, protocols, applications, and networks.

  • Evaluate cybersecurity risks and recommend appropriate mitigation and remediation actions.

  • Research and assess security products, tools, and technologies.
  • Work closely with internal and external stakeholders involved in security accreditation.

  • Coordinate with the NCIA Configuration Control Board, Security Accreditation Boards, NATO Security Accreditation Authorities, and relevant NCI Agency teams.

  • Prepare clear and structured penetration testing and security assessment reports.

  • Present security findings and testing outcomes to both technical and executive audiences, including senior leadership.

  • Coordinate closely with the Head of the Penetration Testing Cell and maintain effective stakeholder collaboration.

Requirements

  • Strong knowledge of web application penetration testing.
  • Strong knowledge of IT infrastructure penetration testing.
  • Knowledge of network security architecture and design.
  • Ability to identify and assess vulnerabilities in operating systems, software, protocols, and networks.

  • Experience using penetration testing tools, techniques, and recognized testing methodologies.

  • Knowledge of UNIX and Windows system and network administration.

  • Scripting skills in at least one of the following: o Python o Perl o Ruby o Bash or other shell scripting

  • Strong technical knowledge of: o System and network security o Authentication and security protocols o Cryptography o Application security o Malware infection techniques o Malware protection technologies

  • Ability to evaluate cybersecurity risks and develop mitigation plans.
  • Strong technical reporting skills, including writing executive summaries, technical findings, and remediation plans for different audiences.

  • Strong stakeholder communication and presentation skills. Experience

  • More than 3 years of relevant professional experience in penetration testing and the required cybersecurity areas.

  • Hands-on experience with web application and infrastructure penetration testing.

  • Experience assessing security vulnerabilities across networks, systems, applications, software, and protocols.

  • Experience using established penetration testing methodologies and security testing tools.

  • Experience researching and evaluating cybersecurity technologies and products.

  • Experience communicating technical security findings to both technical and senior/executive stakeholders.

About the company

Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects., The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO’s member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium.

The NCIA provides a wide range of services, including:

  • Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO’s communication networks and information systems against cyber threats.
  • Command and Control Systems: The NCIA develops and maintains the systems used by NATO’s military commanders to plan and execute operations.
  • Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.
  • Electronic Warfare: The NCIA provides electronic warfare services to support NATO’s mission to detect, deny, and defeat threats to its communication networks.
  • Information Management: The NCIA manages NATO’s information technology infrastructure, including its databases, applications, and servers.

Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO’s communication and information technology capabilities.

The program

Assistance and Advisory Service (AAS)

The NATO Communications and Information Agency (NCI Agency) is NATO’s principal C3 capability deliverer and CIS service provider. It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult together under Article IV, and, when required, stand together in the face of attack under Article V.

To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise’s: NATO International Civilians (NIC)’s, Military (Mil), and Interim Workforce Consultants (IWC)’s. The IWCs are a critical part of the overall NCI Agency workforce and make up approximately 15 percent of the total workforce.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on nl.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

2:04 min

Defining timestamps and the international standard format

Denny Biasiolli Denny Biasiolli · Europe 2026 Virtual

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

Videos

See all

Related articles

See all