Pentester Senior - Active Directory / Azure / Entra ID (F/H)

Collective
Paris, France
5 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Microsoft Windows Active Directory Software System Penetration Testing Microsoft Azure Microsoft Online Services Identity and Access Management Kerberos (Protocol) NT LAN Manager OAuth Role-Based Access Control Microsoft SharePoint

Job description

Nous recherchons un Pentester Senior spĂ©cialisĂ© dans les environnements Microsoft pour intervenir sur des sujets de sĂ©curitĂ© offensive autour d’Active Directory, Azure et Entra ID, dans un contexte d’infrastructures hybrides.

Vous interviendrez notamment sur :

  • La rĂ©alisation de tests d’intrusion sur des environnements Active Directory et Microsoft Cloud ;
  • L’identification et l’exploitation de vulnĂ©rabilitĂ©s sur des environnements AD on-premise, Azure et Entra ID ;
  • L’analyse de chemins d’attaque et scĂ©narios de compromission dans des architectures hybrides AD / Entra ID ;
  • La rĂ©alisation de tests sur les mĂ©canismes d’authentification, de gestion des identitĂ©s, des privilĂšges et des accĂšs ;
  • L’évaluation de la sĂ©curitĂ© des environnements Microsoft 365 selon les pĂ©rimĂštres concernĂ©s ;
  • La restitution des vulnĂ©rabilitĂ©s identifiĂ©es et la formulation de recommandations de remĂ©diation

Requirements

Vous disposez d’une expĂ©rience confirmĂ©e en pentest / sĂ©curitĂ© offensive, avec une expertise particuliĂšre des environnements Microsoft.

Nous recherchons idéalement une expérience concrÚte sur plusieurs des sujets suivants :

Active Directory offensif : Kerberos, NTLM, délégations, ADCS, mouvements latéraux, élévation de privilÚges, BloodHound, Impacket, Mimikatz, NetExec/CrackMapExec, Rubeus


Azure / Entra ID : identités et privilÚges, Azure RBAC, Conditional Access, Service Principals, App Registrations, Managed Identities, OAuth/tokens, Microsoft Graph


Une expérience de pentest M365 (Exchange Online, SharePoint Online, Teams
) constitue un vrai plus.

Les certifications OSCP, OSEP, CRTP, CRTE ou équivalentes sont appréciées.

Benefits & conditions

Taux journalier (TJM): 680 EUR

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · World Congress 2022

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:51 min

Leveraging continuous penetration testing via red teams

Reto Kaeser · LIVE

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi · World Congress 2022

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all