Turn this role into an interview — a resume and cover letter built around what this employer wants.
In4Matic is seeking a Penetration Testing Analyst to join its cybersecurity team and independently conduct security assessments across web applications, networks and Windows/Active Directory environments.
You will execute standard penetration testing engagements from preparation through reporting and retesting, while collaborating with a senior security professional on complex or high-risk assignments, and present findings to technical teams and stakeholders.
We’re looking for a Penetration Testing Analyst to join our client’s cybersecurity team and independently conduct security assessments across web applications, networks and Windows/Active Directory environments. You will be responsible for executing standard penetration testing engagements from preparation through reporting and retesting, while working closely with a senior security professional on complex or high-risk assignments.
Analyze technical architectures and data flows to identify critical assets, attack surfaces and trust relationships.
Contribute to defining assessment scopes, objectives and rules of engagement.
Conduct black-box, grey-box and white-box penetration tests on web applications, APIs and administrative portals.
Perform internal and external infrastructure and network penetration testing.
Assess Windows and Active Directory environments, including Kerberos/NTLM, GPOs, ACLs and lateral movement.
Carry out controlled exploitation and post-exploitation activities within agreed engagement boundaries.
Document vulnerabilities accurately, including affected systems, exploitation conditions, evidence, impact, risk and remediation recommendations.
Produce complete and reproducible technical reports and contribute to executive-level reporting.
Develop simple proof-of-concepts and scripts when required.
Present findings to technical teams and project stakeholders.
Conduct retests to verify the effectiveness of remediation measures.
Escalate critical findings, high-risk situations and scope uncertainties to a senior security specialist.
Contribute, with senior guidance, to complementary security assessments involving cloud, containers/CI-CD, mobile environments and purple teaming.
Help improve internal methodologies, checklists, reporting templates and security testing tools.
The ideal candidate has solid practical knowledge of penetration testing methodologies and security assessment techniques, including:
Web and API security testing, including OWASP Top 10, injection vulnerabilities, IDOR, XSS, SSRF, deserialization, session/token management and modern authentication mechanisms.
OAuth 2.0, OIDC, SAML and JWT.
Network and infrastructure testing involving TCP/IP, DNS/DHCP/NTP/SNMP, HTTP/HTTPS/TLS, SMB, LDAP, Kerberos, RDP, WinRM, VPN, segmentation and filtering.
Windows and Active Directory security, including domain enumeration, Kerberos/NTLM, GPO, ACLs, trust relationships, Kerberoasting and lateral movement.
Security testing methodologies and frameworks such as OWASP WSTG, ASVS, API Security Top 10, PTES, MITRE ATT&CK, CVSS and CWE/CAPEC.
Common penetration testing tools including Kali/Parrot, Burp Suite, OWASP ZAP, Nmap, Wireshark, Nessus, Metasploit, Impacket, NetExec and BloodHound.
Knowledge of cloud platforms such as Azure, AWS or GCP, Linux, containers/Kubernetes, CI-CD and application security is considered an advantage.
Proven professional experience in penetration testing or offensive security, with approximately 5-8 years of relevant experience preferred.
Able to independently execute standard penetration testing engagements while escalating complex or critical situations to a senior specialist.
Structured and analytical approach, with strong attention to detail and the ability to produce clear, technically accurate documentation.
Comfortable presenting technical findings to security teams, engineers and project stakeholders.
Strong team player who knows when to seek support, escalation and share knowledge.
Excellent understanding of technical English is required; knowledge of French and Dutch is an advantage.
Higher education in Computer Science, Cybersecurity, Telecommunications or a related field, or equivalent professional experience.
Certifications such as OSCP/OSCP+, Burp Suite Certified Practitioner (BSCP) or CRTP are considered strong assets.