7 hours, 2 minutes ago

Senior Security Pentester

Service: Cybersecurity – Offensive Security / IoT Ecosystem (ANPR cameras, sensors, cloud, applications)

Introduction

As part of securing its IoT platforms, the Federal Police is seeking a Senior Pentester / Ethical Hacker with proven experience in offensive security. The consultant operates in a complex technical environment with ANPR cameras, connected field equipment, embedded systems, network infrastructure, cloud platforms, APIs, web applications, and central processing and consultation systems.

The assignment consists of identifying, exploiting in a controlled manner, and documenting vulnerabilities that could impact the confidentiality, integrity, availability, or authenticity of the ANPR systems and data. Activities are carried out strictly within an authorized framework, based on a defined scope and formalized rules of engagement.

Mission

The role involves the preparation and execution of penetration tests on the entire ANPR ecosystem (field equipment, network, cloud, applications, mobile), delivering actionable reports, and assisting teams in remediating identified vulnerabilities.

Deliverables

  • Comprehensive, precise, and reproducible technical reports per vulnerability (affected systems, exploitation conditions, evidence, impact, risk level, recommendations)
  • Clear executive summary for management
  • Formalized scope, objectives, and rules of engagement per assignment
  • Developed or adapted proof-of-concepts and scripts where required
  • Retests to validate the effectiveness of remediations
  • Recommendations to improve architectures, security standards, and development procedures

Main tasks

  • Analyze technical architectures and data flows; identify critical assets, attack surfaces, and trust relationships
  • Participate in defining the scope, objectives, and rules of engagement for assignments
  • Perform penetration tests (black box, grey box, white box) on the ANPR ecosystem: cameras, edge devices, gateways, central systems
  • Test IoT and embedded systems for security (firmware, hardware interfaces UART/JTAG/SWD, OTA updates, secure boot)
  • Analyze and test communication protocols (TCP/IP, HTTP/HTTPS, MQTT, RTSP, VPN, Wi-Fi/BLE, TLS/mTLS/PKI, etc.)
  • Conduct cloud penetration tests (IAM, virtual networks, storage, containers/Kubernetes, CI/CD pipelines) on Azure, AWS, or GCP
  • Test web applications, APIs, and backend services (authentication, authorization, OWASP Top 10, OAuth 2.0/OIDC/SAML/JWT)
  • Test mobile Android and iOS applications when within scope
  • Conduct penetration tests on Windows, Linux, and Active Directory infrastructure
  • Document results and present them to technical teams and management, and advise teams on remediation

Core competencies

  • Mastery of penetration testing methodologies (black/grey/white box), controlled exploitation, post-exploitation, and lateral movement
  • IoT and embedded systems expertise: firmware analysis, hardware interfaces (UART/JTAG/SWD), update mechanisms, and secure boot
  • Network, protocol, and cloud security (Azure/AWS/GCP): IAM, segmentation, containers/Kubernetes, CI/CD
  • Application, API, and mobile security (OWASP, OAuth 2.0/OIDC/SAML/JWT, Android/iOS)
  • Drafting technical and executive reports, guiding remediation, and mentoring less experienced profiles

Communication and collaboration

  • Present results to technical teams, architects, project managers, and management
  • Ability to mentor less experienced profiles; teamwork and knowledge sharing
  • Preferably bilingual (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English, both written and spoken

Level and experience

  • Authoritative advice and fully independent execution (SFIA level 5 – Ensure, advise)
  • Minimum 5 years of experience in offensive security; able to lead an assignment independently, from scoping to presenting results; explicitly not a junior

Degree

Higher degree in computer science, cybersecurity, electronics, or telecommunications, or equivalent professional experience.

Technical certifications in offensive security are an asset (e.g., OSCP/OSCP+, OSWE, OSEP, GPEN/GWAPT, SEC556/PIPA for IoT).

No certification is individually required – the combination of practical experience and domain coverage is decisive.

Apply for this Job

This position was originally posted on Pro Unity.

It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.

Newsletter signup illustration