Senior Security Pentester

Keystone Solutions
Brussel, Belgium
1 day ago
Apply on www.adzuna.be
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Languages
Dutch, French
Job source

Tech stack

JavaScript (Programming Language) Microsoft Windows Active Directory Application Programming Interfaces (APIs) Amazon Web Services Advanced Message Queuing Protocol Automatic Number Plate Recognition IOS Applications Apple IOS Software System Penetration Testing User Authentication Microsoft Azure
+48 more
Bash Shell Burp Suite Cloud Computing Cloud Computing Security Communications Protocols Cyber Security Databases Continuous Integration Linux Domain Name System (DNS) Firmware White-Box Testing Hardware Interface Design Hypertext Transfer Protocols (HTTP) Identity and Access Management Virtual Private Networks (VPN) Joint Test Action (IEEE Standards) Python (Programming Language) Message Queuing Telemetry Transport (MQTT) Network Architecture Nmap OAuth OpenID Open Web Application Security Public Key Infrastructure Windows PowerShell Security Assertion Markup Language (SAML) Simple Object Access Protocol (SOAP) Mobile Security Data Streaming TCP/IP Wireshark Universal Asynchronous Receiver/Transmitter Web Applications WebSocket Wi-Fi Technology Scripting Software Security Backend RTSP GWAPT Kubernetes Information Technology Metasploit Nessus U-Boot Grpc IoT Security

Job description

Keystone Solutions is seeking a Senior Security Pentester to join our consultancy mission at a client site. The consultant will work in a complex technical environment focusing on IoT platforms, including ANPR cameras, connected devices, embedded systems, network infrastructure, cloud platforms, APIs, web applications, and central processing systems., The role involves preparing and executing penetration tests across the entire ANPR ecosystem (field equipment, network, cloud, applications, mobile), producing actionable reports, and guiding teams in addressing identified vulnerabilities. These responsibilities will be carried out under Keystone Solutions’ consultancy model.

Deliverables:

  • Comprehensive, precise, and reproducible technical reports for each vulnerability (involved systems, exploitation conditions, evidence, impact, risk level, recommendations)
  • Clear executive summary for management
  • Formalized scope, objectives, and rules of engagement for each assignment
  • Developed or customized proof-of-concepts and scripts as needed
  • Retests to validate the effectiveness of corrections
  • Recommendations for improving architectures, security standards, and development procedures

Main Tasks:

  • Analyze technical architectures and data flows; identify critical assets, attack surfaces, and trust relationships
  • Participate in defining the scope, objectives, and rules of engagement for assignments
  • Conduct penetration tests (black box, grey box, white box) on the ANPR ecosystem: cameras, edge devices, gateways, central systems
  • Test IoT and embedded systems for security (firmware, hardware interfaces UART/JTAG/SWD, OTA updates, secure boot)
  • Analyze and test communication protocols (TCP/IP, HTTP/HTTPS, MQTT, RTSP, VPN, Wi-Fi/BLE, TLS/mTLS/PKI, etc.)
  • Perform cloud penetration testing (IAM, virtual networks, storage, containers/Kubernetes, CI/CD pipelines) on Azure, AWS, or GCP
  • Test web applications, APIs, and backend services (authentication, authorization, OWASP Top 10, OAuth 2.0/OIDC/SAML/JWT)
  • Test mobile Android and iOS applications when within scope
  • Conduct penetration tests on Windows, Linux, and Active Directory infrastructure
  • Document and present results to technical teams and management, advising teams on remediation

Core Competencies:

  • Mastery of penetration testing methodologies (black/grey/white box), controlled exploitation, post-exploitation, and lateral movement
  • Expertise in IoT and embedded systems: firmware analysis, hardware interfaces (UART/JTAG/SWD), update mechanisms, and secure boot
  • Network, protocol, and cloud security (Azure/AWS/GCP): IAM, segmentation, containers/Kubernetes, CI/CD
  • Application, API, and mobile security (OWASP, OAuth 2.0/OIDC/SAML/JWT, Android/iOS)
  • Ability to produce technical and executive reports, guide remediation, and mentor less experienced profiles

Requirements

  • Present results to technical teams, architects, project managers, and management
  • Ability to mentor less experienced profiles; teamwork and knowledge sharing
  • Preferably bilingual (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English, both written and spoken

Level and Experience:

Authoritative advice and fully independent execution (SFIA level 5 Ensure, advise). Minimum 5+ years of experience in offensive security; capable of leading an assignment independently, from scope definition to presentation of results; explicitly not a junior role.

Degree:

Higher degree in computer science, cybersecurity, electronics, or telecommunications, or equivalent professional experience. Technical certifications in offensive security are a plus (e.g., OSCP/OSCP+, OSWE, OSEP, GPEN/GWAPT, SEC556/PIPA for IoT). No single certification is individually required - the combination of practical experience and domain coverage is decisive.

If you are ready to tackle technical and strategic challenges in a dynamic consultancy environment, apply today at Keystone Solutions Career Portal., * Cloud: IAM, virtuele netwerken, opslag, databases, containers/Kubernetes, CI/CD-pipelines (Azure, AW - Level: Confirmed - Most recent: Any time

  • IoT en embedded systemen: IoT-/edge-computingarchitecturen, firmware-analyse, hardware-interfaces, i - Level: Confirmed - Most recent: Any time
  • Methodologien en referentiekaders: OWASP (WSTG, ASVS, API Security Top 10, MASVS/MSTG, IoT Security - Level: Confirmed - Most recent: Any time
  • Netwerken en protocollen: TCP/IP, DNS, HTTP/HTTPS, REST/SOAP/WebSocket/gRPC, MQTT/AMQP/CoAP, RTSP, V - Level: Confirmed - Most recent: Any time
  • Offensieve tooling: Kali/Parrot, Burp Suite/OWASP ZAP, Nmap/Wireshark/Nessus, Metasploit/Impacket, B - Level: Confirmed - Most recent: Any time
  • Scripting en automatisering: Python, PowerShell, Bash en minstens n bijkomende taal (JavaScript, C - Level: Confirmed - Most recent: Any time

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.be
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Developer interfaces for interacting with camera hardware

Flo Pachinger · LIVE

4:56 min

Establishing internal service communication with gRPC

Florian Bader Florian Bader · World Congress 2026 Europe

7:01 min

Initial reconnaissance and port scanning execution

Antonio De Mello +1 · LIVE

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

6:24 min

Common information security tools and terminologies

Antonio De Mello +1 · LIVE

1:11 min

Evaluating architectural trade-offs between REST and gRPC

Sakshi Nasha Sakshi Nasha · Europe 2026 Virtual

Videos

See all

Related articles

See all