Medior Security Pentester
Service: Cybersecurity – Offensive Security / web applications, networks, and Windows-Active Directory environments
Overview
As part of strengthening its offensive security capabilities, the Federal Police is seeking a Medior Security Pentester / Ethical Hacker with proven hands-on experience in penetration testing. The consultant will mainly work in three areas:
- web applications, APIs, and administration portals;
- network infrastructures and protocols;
- Windows and Active Directory environments.
The position holder independently conducts standard-complexity assignments and contributes, under the coordination of a senior profile, to more complex missions (cloud, containers, mobile, purple teaming).
All activities are carried out exclusively within an authorized framework, based on a defined scope and formalized rules of engagement.
Mission
The role ensures the preparation and autonomous execution of penetration tests on web applications, networks, and Windows/Active Directory environments, the production of technical reports, and contribution to remediation, with support from a senior profile on complex assignments.
Deliverables
- Complete, accurate, and reproducible technical reports per vulnerability (affected systems, exploitation conditions, evidence, impact, risk, recommendations)
- Contribution to the executive summary for management, reviewed by a senior
- Scopes, objectives, and rules of engagement for assignments, defined in collaboration with a senior
- Simple proof-of-concepts and tailored scripts as needed
- Retests to validate the effectiveness of fixes
- Contribution to internal knowledge management: methodologies, checklists, report templates, tooling
Main tasks
- Analyze technical architectures and data flows; identify critical assets, attack surfaces, and trust relationships
- Contribute to defining the scope, objectives, and rules of engagement for assignments
- Conduct penetration tests (black box, grey box, white box) on web applications, APIs, and administration portals
- Conduct internal and external penetration tests on network infrastructures and protocols
- Conduct penetration tests on Windows and Active Directory environments (Kerberos/NTLM, GPO, ACL, lateral movement)
- Escalate risky situations, grey areas in scope, and critical findings to a senior profile
- Document each vulnerability and independently draft the technical report
- Present results to technical teams and project managers
- Conduct retests to validate the effectiveness of fixes
- Contribute, in support of a senior, to complementary assignments (cloud, containers/CI-CD, mobile, purple teaming)
Key skills
- Structured penetration testing methodology (black/grey/white box); controlled exploitation and post-exploitation
- Web application and API testing: OWASP Top 10, modern authentication/authorization (OAuth 2.0/OIDC/SAML/JWT), targeted code review
- Network and infrastructure testing: protocols (TCP/IP, DNS, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP), segmentation, filtering
- Windows/Active Directory testing: domain enumeration, Kerberos/NTLM, GPO/ACL, lateral movement, PowerShell
- Technical report writing and ability to escalate/collaborate with a senior profile
Communication and collaboration
- Present results to technical teams and project managers; executive summary reviewed by a senior
- Ability to request support and escalate at the right time; teamwork and knowledge sharing
- Preferably bilingual (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English
Level and experience
- Autonomous execution under general supervision, with escalation to a senior on complex issues (SFIA level 3 – Apply)
- Minimum 8 years of experience (ideally 5 to 8 years); independently handles standard assignments and contributes to complex assignments under a senior’s coordination
Degree
Advanced degree in IT, cybersecurity, or telecommunications, or equivalent professional experience.
Valued certifications:
- OSCP/OSCP+,
- Burp Suite Certified Practitioner (BSCP),
- CRTP;
no certification is required
In practice
Level of responsibility: SFIA level 3 – Apply (medior, trajectory towards senior)
Reports to: Senior Pentester / Security Lead
Work arrangement: Full-time; assignments conducted exclusively within an authorized scope and according to formalized rules of engagement
Work location: Brussels
Team: Security team, in collaboration with project teams and the CISO office
Apply for this Job
This position was originally posted on Pro Unity.
It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.
Search jobs by category
- AI Engineer
- Application Support Analyst
- Business Analyst
- Business Intelligence Analyst
- CRM Developer
- Cybersecurity Analyst
- Data Analyst
- Database Administrator
- Data Engineer
- Data Scientist
- Developer
- DevOps Engineer
- Embedded Systems Engineer
- ERP Consultant
gofreelance
© 2026 gofreelance.be