Security Pentester – Web Apps & Active Directory

Security Pentester voor web apps en Active Directory bij een grote publieke sector organisatie, on-site in Brussel, fulltime, open voor vaste medewerkers en freelancers.

Locatie
Brussel, BE
Werkvorm
op locatie

Mogelijk warme-stoelsignaal. Oordeel onzeker; geen bewijs dat al een kandidaat is gekozen.

De startdatum of korte looptijd valt op. Dit kan ook passen bij spoed, tijdelijke vervanging of afwijkende brongegevens; datums alleen bewijzen geen voorselectie. Dit is een aanwijzing, geen bewijs van een vooraf gekozen kandidaat.

Zo werkt de warme stoel check.

Bekijk en reageer bij Pauwels Consulting (externe link)

Eisen

  • Practical knowledge of Windows and Active Directory security, specifically regarding NTLM, Kerberos, and PowerShell
  • Active knowledge of French, Dutch, and English
  • Solid understanding of modern authentication protocols like OAuth 2.0, OIDC, SAML, and JWT
  • 3+ years of experience in offensive security with a focus on web application and API testing using OWASP methodologies
  • 3+ years of experience in network security and infrastructure protocols including TCP/IP, DNS, HTTP/S, and SMB
  • Proficiency with security tooling such as Kali Linux, Burp Suite, Nmap, and Metasploit
  • Strong technical writing skills and the ability to work collaboratively with senior experts

Wensen

  • Certifications such as OSCP, BSCP, or CRTP
  • Experience in mobile application security testing
  • Experience with cloud environments like Azure, AWS, or GCP
  • Knowledge of containers, Kubernetes, and CI/CD security
Volledige omschrijving

Pauwels Consulting is looking for a Security Pentester for our client, a major public sector organization, to strengthen its offensive security capabilities. The role involves performing penetration tests on web applications, networks, and Windows environments while producing technical reports to facilitate effective remediation. Responsibilities include performing penetration tests in black, grey, and white box modes on web applications, APIs, and administration portals; conducting internal and external network infrastructure assessments focusing on segmentation, filtering, and protocol vulnerabilities; executing security tests on Windows and Active Directory environments, including Kerberos, GPO, ACL, and lateral movement analysis; analyzing technical architectures and data flows to identify attack surfaces and critical assets; documenting vulnerabilities and drafting technical reports with detailed reproduction steps and remediation recommendations; presenting findings to technical teams and project managers to assist in risk management; and contributing to internal knowledge sharing, including methodologies, check-lists, and tooling improvements.

Requirements include 3+ years of experience in offensive security with a focus on web application and API testing using OWASP methodologies; 3+ years of experience in network security and infrastructure protocols including TCP/IP, DNS, HTTP/S, and SMB; practical knowledge of Windows and Active Directory security, specifically regarding NTLM, Kerberos, and PowerShell; proficiency with security tooling such as Kali Linux, Burp Suite, Nmap, and Metasploit; a solid understanding of modern authentication protocols like OAuth 2.0, OIDC, SAML, and JWT; strong technical writing skills and the ability to work collaboratively with senior experts; and active knowledge of French, Dutch, and English.

Nice to haves include certifications such as OSCP, BSCP, or CRTP; experience with cloud environments like Azure, AWS, or GCP; knowledge of containers, Kubernetes, and CI/CD security; and experience in mobile application security testing.

Offer: Start date 1 November 2026, duration 2 months, full-time work regime, location Brussels, on-site working model, and contract open to both permanent employees and freelancers.

Je CV en reacties