- Location
- Brussel
- Type
- Full-time
- Department
- Security
- Seniority
- Senior
- Experience
- 5+ years
- Closing date
- Today
- Source
- CareersPage
Description
Mission Overview:
Keystone Solutions is seeking a Senior Security Pentester to join our consultancy mission at a client site. The consultant will work in a complex technical environment focusing on IoT platforms, including ANPR cameras, connected devices, embedded systems, network infrastructure, cloud platforms, APIs, web applications, and central processing systems.
Responsibilities:
The role involves preparing and executing penetration tests across the entire ANPR ecosystem (field equipment, network, cloud, applications, mobile), producing actionable reports, and guiding teams in addressing identified vulnerabilities. These responsibilities will be carried out under Keystone Solutions' consultancy model.
Deliverables:
- Comprehensive, precise, and reproducible technical reports for each vulnerability (involved systems, exploitation conditions, evidence, impact, risk level, recommendations)
- Clear executive summary for management
- Formalized scope, objectives, and rules of engagement for each assignment
- Developed or customized proof-of-concepts and scripts as needed
- Retests to validate the effectiveness of corrections
- Recommendations for improving architectures, security standards, and development procedures
Main Tasks:
- Analyze technical architectures and data flows; identify critical assets, attack surfaces, and trust relationships
- Participate in defining the scope, objectives, and rules of engagement for assignments
- Conduct penetration tests (black box, grey box, white box) on the ANPR ecosystem: cameras, edge devices, gateways, central systems
- Test IoT and embedded systems for security (firmware, hardware interfaces UART/JTAG/SWD, OTA updates, secure boot)
- Analyze and test communication protocols (TCP/IP, HTTP/HTTPS, MQTT, RTSP, VPN, Wi-Fi/BLE, TLS/mTLS/PKI, etc.)
- Perform cloud penetration testing (IAM, virtual networks, storage, containers/Kubernetes, CI/CD pipelines) on Azure, AWS, or GCP
- Test web applications, APIs, and backend services (authentication, authorization, OWASP Top 10, OAuth 2.0/OIDC/SAML/JWT)
- Test mobile Android and iOS applications when within scope
- Conduct penetration tests on Windows, Linux, and Active Directory infrastructure
- Document and present results to technical teams and management, advising teams on remediation
Core Competencies:
- Mastery of penetration testing methodologies (black/grey/white box), controlled exploitation, post-exploitation, and lateral movement
- Expertise in IoT and embedded systems: firmware analysis, hardware interfaces (UART/JTAG/SWD), update mechanisms, and secure boot
- Network, protocol, and cloud security (Azure/AWS/GCP): IAM, segmentation, containers/Kubernetes, CI/CD
- Application, API, and mobile security (OWASP, OAuth 2.0/OIDC/SAML/JWT, Android/iOS)
- Ability to produce technical and executive reports, guide remediation, and mentor less experienced profiles
Communication and Collaboration:
- Present results to technical teams, architects, project managers, and management
- Ability to mentor less experienced profiles; teamwork and knowledge sharing
- Preferably bilingual (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English, both written and spoken
Level and Experience:
Authoritative advice and fully independent execution (SFIA level 5 – Ensure, advise). Minimum 5+ years of experience in offensive security; capable of leading an assignment independently, from scope definition to presentation of results; explicitly not a junior role.
Degree:
Higher degree in computer science, cybersecurity, electronics, or telecommunications, or equivalent professional experience. Technical certifications in offensive security are a plus (e.g., OSCP/OSCP+, OSWE, OSEP, GPEN/GWAPT, SEC556/PIPA for IoT). No single certification is individually required - the combination of practical experience and domain coverage is decisive.
If you are ready to tackle technical and strategic challenges in a dynamic consultancy environment, apply today at Keystone Solutions Career Portal.
Duration: 01/11/2026 - 31/12/2026 2 months • (full time)
Skills required:
- Cloud: IAM, virtuele netwerken, opslag, databases, containers/Kubernetes, CI/CD-pipelines (Azure, AW - Level: Confirmed - Most recent: Any time
- IoT en embedded systemen: IoT-/edge-computingarchitecturen, firmware-analyse, hardware-interfaces, i - Level: Confirmed - Most recent: Any time
- Methodologieën en referentiekaders: OWASP (WSTG, ASVS, API Security Top 10, MASVS/MSTG, IoT Security - Level: Confirmed - Most recent: Any time
- Netwerken en protocollen: TCP/IP, DNS, HTTP/HTTPS, REST/SOAP/WebSocket/gRPC, MQTT/AMQP/CoAP, RTSP, V - Level: Confirmed - Most recent: Any time
- Offensieve tooling: Kali/Parrot, Burp Suite/OWASP ZAP, Nmap/Wireshark/Nessus, Metasploit/Impacket, B - Level: Confirmed - Most recent: Any time
- Scripting en automatisering: Python, PowerShell, Bash en minstens één bijkomende taal (JavaScript, C - Level: Confirmed - Most recent: Any time
Language requirements:
Dutch
Level Active knowledge
English
Level Active knowledge
French
Level Active knowledge