> Markdown version of [/jobs/ext/2812370-senior-penetration-tester](https://www.wearedevelopers.com/jobs/ext/2812370-senior-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Penetration Tester - **Company:** Aegis Vision - **Location:** Henegouwen, Belgium - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, JIRA, Authentication Protocols, Unix, Python (Programming Language), Network Security, Windows PowerShell, Web Applications, Scripting, Software Security, Malware, GWAPT, Information Technology, Golang - **Published:** September 10, 2026 - **Apply:** https://www.collegerecruiter.com/job/2858146160-senior-penetration-tester ## About the Role Education & Experience: Bachelor's degree in an IT-heavy technical subject with 3 years of post-related experience . Alternatively, 10 years of extensive and progressive penetration testing experience can compensate for a degree . Core Technical Expertise: Minimum 3 years of deep experience in web application and infrastructure penetration testing, network security architecture design, and UNIX/Windows system administration . Tooling & Scripting: Strong proficiency with industry-recognized penetration testing tools and scripting skills in at least one language (Python, Go, PowerShell, or Shell) . Advanced Security Concepts: Solid understanding of authentication protocols, cryptography, application security, malware infection techniques, and defensive technologies . Desirable Certifications: Professional certifications such as OSCP, OSCE, OSWE, GPEN, CREST Certified Web Application Tester, GXPN, or GWAPT . Language & Environment: Thorough proficiency in English is required . Prior experience in an international military/civilian environment or knowledge of NATO structures is highly beneficial . Security Clearance: Must possess a valid, active NATO Secret security clearance . ## Description Penetration Testing Execution: Provide comprehensive web application, IT infrastructure, and application-level testing (including COTS and GOTS software) using defined methodologies . Vulnerability & Risk Analysis: Assess security vulnerabilities within operating systems, software, protocols, and networks; evaluate risks and formulate actionable mitigation plans . Stakeholder Alignment: Lead and participate in kick-off meetings to define testing requirements, scope, and rules of engagement . Reporting & Responsible Disclosure: Write high-quality, structured technical reports in English . Follow the Responsible Disclosure Process for newly detected COTS vulnerabilities with vendors . Executive Briefings: Brief stakeholders, technical teams, and high-level leadership (up to flag officer level) on security findings and assessment outcomes . Agile Sprint Delivery: Execute tasks and report outcomes within a 1-week sprint framework, tracking activities inside JIRA . ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [11 Best Practices For PHP Security](https://www.wearedevelopers.com/magazine/90-11-best-practices-for-php-security)