- Location
- Brussel
- Type
- Full-time
- Department
- Security
- Experience
- 8+ years
- Closing date
- Today
- Source
- CareersPage
Description
Mission Overview:
Keystone Solutions is seeking a Medior Security Pentester / Ethical Hacker to join our consultancy mission at a client site. The consultant will have confirmed practical experience in penetration testing and will primarily work in three areas: web applications, APIs, and administration portals; network infrastructures and protocols; and Windows and Active Directory environments.
The consultant will autonomously conduct standard complexity missions and contribute, under the coordination of a senior profile, to more complex missions (cloud, containers, mobile, purple teaming). All activities will be performed exclusively within an authorized framework, based on a defined scope and formalized engagement rules.
Key Responsibilities:
- Prepare and conduct autonomous penetration tests on web applications, networks, and Windows/Active Directory environments, producing technical reports and contributing to remediation, with support from a senior profile on complex missions.
- Deliver comprehensive, precise, and reproducible technical reports by vulnerability (affected systems, exploitation conditions, evidence, impact, risk, recommendations).
- Contribute to the executive summary for management, reviewed by a senior.
- Define the scope, objectives, and engagement rules of missions in collaboration with a senior.
- Provide simple proof of concepts and scripts tailored to needs.
- Conduct retests to validate the effectiveness of corrections.
- Contribute to internal capitalization: methodologies, checklists, report templates, tooling.
Key Skills:
- Structured penetration testing methodology (black/grey/white box); controlled exploitation and post-exploitation.
- Web application and API testing: OWASP Top 10, modern authentication/authorization (OAuth 2.0/OIDC/SAML/JWT), targeted code review.
- Network and infrastructure testing: protocols (TCP/IP, DNS, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP), segmentation, filtering.
- Windows/Active Directory testing: domain enumeration, Kerberos/NTLM, GPO/ACL, lateral movement, PowerShell.
- Technical report writing and ability to escalate/collaborate with a senior profile.
Communication and Collaboration:
- Present results to technical teams and project managers; executive summary reviewed by a senior.
- Ability to seek support and escalate at the right moment; teamwork and knowledge sharing.
- Bilingual preferred (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English.
Experience and Education:
- Autonomous execution under general supervision, escalating to a senior on complexity (SFIA level 3 – Apply).
- Minimum 8 years of experience (ideally 5 to 8 years); independently conducts standard missions and contributes to complex missions under senior coordination.
- Higher education degree in computer science, cybersecurity, or telecommunications, or equivalent professional experience.
Certifications:
- Preferred: OSCP/OSCP+, Burp Suite Certified Practitioner (BSCP), CRTP; no certification is required.
Work Environment:
- Responsibility level: SFIA level 3 – Apply (medior, trajectory towards senior).
- Reports to: Senior Pentester/Security Manager.
- Work regime: Full-time; interventions conducted exclusively within an authorized scope and according to formalized engagement rules.
- Location: Brussels.
- Team: Security team, in collaboration with project teams and the CISO office.
If you are ready to tackle technical and strategic challenges in a dynamic consultancy environment, apply today at Keystone Solutions Career Portal.
Duration: 01/11/2026 - 31/12/2026 2 months • (full time)
Skills required:
- Applications web et API : injections, IDOR, XSS, SSRF, désérialisation, gestion de sessions/tokens, - Level: Confirmed - Most recent: Any time
- Méthodologies et référentiels : OWASP WSTG/ASVS/API Security Top 10, PTES, MITRE ATT&CK, CVSS, CWE/C - Level: Confirmed - Most recent: Any time
- Notions complémentaires (atout) : cloud (Azure/AWS/GCP), Linux, conteneurs/Kubernetes/CI-CD, applica - Level: Confirmed - Most recent: Any time
- Outillage : Kali/Parrot, Burp Suite/OWASP ZAP, Nmap/Wireshark/Nessus, Metasploit/Impacket/NetExec, B - Level: Confirmed - Most recent: Any time
- Réseaux et protocoles : TCP/IP, DNS/DHCP/NTP/SNMP, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP/WinRM, VPN - Level: Confirmed - Most recent: Any time
- Windows et Active Directory : objets AD, GPO, ACL, relations d’approbation, Kerberos/NTLM (Kerberoas - Level: Confirmed - Most recent: Any time
Language requirements:
Dutch
Level Active knowledge
English
Level Active knowledge
French
Level Active knowledge