- Company Name
- Digisourced.
- Job Title
- Penetration Tester
- Job Description
-
**Job Title**
Penetration Tester
**Role Summary**
Simulate cyberattacks to identify and remediate vulnerabilities across critical systems, networks, and cloud environments. Collaborate with incident response, threat intelligence, security operations, and cross‑functional teams to strengthen security posture and support compliance audits.
**Expectations**
- Deliver technical penetration testing and vulnerability assessments on time.
- Produce clear, actionable reports for technical and non‑technical stakeholders.
- Proactively prioritize findings in alignment with enterprise risk management and regulatory requirements.
- Maintain ethical responsibility and confidentiality in all engagements.
**Key Responsibilities**
- Conduct internal, external, and cloud (AWS, Azure, GCP) penetration tests, including IOT & OT environments.
- Perform manual and automated vulnerability assessments; evaluate business impact and exploitation likelihood.
- Apply risk‑based prioritization to remediation plans.
- Manage responsible disclosure for third‑party vulnerabilities; coordinate with vendors.
- Create technical documentation and remedial guidance; support implementation.
- Work with development, infrastructure, and risk teams to verify fixes and enhance secure coding practices.
- Lead and participate in red team/blue team exercises, purple teaming, and threat simulations.
- Develop and maintain scripts, tools, and automation frameworks to improve testing efficiency.
- Support internal and external audits, including NIS2 and GDPR compliance.
- Continuously integrate threat intelligence and stay current with emerging attack techniques.
**Required Skills**
- Proficiency with tools: Burp Suite, Metasploit, Nmap, Wireshark, Nessus, etc.
- Deep understanding of network protocols, Windows/Linux, web technologies, and cloud security.
- Scripting: Python, Bash, PowerShell.
- Knowledge of OWASP Top‑10, MITRE ATT&CK, secure coding, and application security.
- Experience with container security and cloud environments.
- Strong analytical, problem‑solving, and communication skills.
- Team collaboration and adaptability to evolving threats.
- Ethical judgment and customer‑focus mindset.
- Fluency in Dutch or French (spoken/written) and English.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent experience.
- Minimum 3–5 years in a security‑related role focusing on analysis, risk, and reporting.
- At least two recognized certifications (GPEN, GXPN, GCPN, GWAPT, OSCP, OSEP, or similar).
---