Security Pentester – Web Apps & Active Directory
Digital
Security
Bachelor
- Location
- Brussels, Brussels-Capital
- Work type
- Consultancy
- Work model
- Fulltime, On-site
Our client, a major public sector organization, is looking for a Security Pentester to strengthen its offensive security capabilities. The role involves performing penetration tests on web applications, networks, and Windows environments while producing technical reports to facilitate effective remediation.
Responsibilities
- Perform penetration tests in black, grey, and white box modes on web applications, APIs, and administration portals.
- Conduct internal and external network infrastructure assessments focusing on segmentation, filtering, and protocol vulnerabilities.
- Execute security tests on Windows and Active Directory environments, including Kerberos, GPO, ACL, and lateral movement analysis.
- Analyze technical architectures and data flows to identify attack surfaces and critical assets.
- Document vulnerabilities and draft technical reports with detailed reproduction steps and remediation recommendations.
- Present findings to technical teams and project managers to assist in risk management.
- Contribute to internal knowledge sharing, including methodologies, check-lists, and tooling improvements.
Requirements
- You have 3+ years of experience in offensive security with a focus on web application and API testing using OWASP methodologies.
- You bring 3+ years of experience in network security and infrastructure protocols including TCP/IP, DNS, HTTP/S, and SMB.
- You possess practical knowledge of Windows and Active Directory security, specifically regarding NTLM, Kerberos, and PowerShell.
- You're proficient with security tooling such as Kali Linux, Burp Suite, Nmap, and Metasploit.
- You have a solid understanding of modern authentication protocols like OAuth 2.0, OIDC, SAML, and JWT.
- You possess strong technical writing skills and the ability to work collaboratively with senior experts.
- You have active knowledge of French, Dutch, and English.
Nice to Haves
- Certifications such as OSCP, BSCP, or CRTP.
- Experience with cloud environments like Azure, AWS, or GCP.
- Knowledge of containers, Kubernetes, and CI/CD security.
- Experience in mobile application security testing.
Offer
- Start date: 1 November 2026
- Duration: 2 months
- Work regime: Full-time
- Location: Brussels
- Working model: Onsite
- Contract: open to both permanent employees and freelancers
# 102961
Chat with Alex
Not sure if this job is right for you? Chat with Alex, our AI career coach, and discover the vacancies that match your profile.
)