Obtenez une réponse de cet employeur — un CV et une lettre de motivation adaptés exactement à ce qu’il recherche.
In4Matic seeks a Senior Penetration Testing Analyst to lead offensive security engagements across infrastructure, cloud, applications and IoT/embedded systems. You will own scoping, testing, reporting and remediation support, mentoring peers and presenting concise executive summaries to management.
The role requires senior-level expertise across Windows, Linux, AD, mobile and cloud environments and fluency in English. French/Dutch skills are valued.
We’re looking for a Senior Penetration Testing Analyst to join our client’s cybersecurity team and lead complex offensive security engagements across a diverse technology landscape. You will take ownership of penetration tests from scoping and rules of engagement through execution, reporting and remediation support, covering infrastructure, cloud, applications, mobile and connected/embedded technologies. This is a highly autonomous expert role requiring broad technical coverage and the ability to advise both technical teams and management.
Define and execute black-box, grey-box and white-box penetration tests across complex technology environments.
Analyze technical architectures and data flows to identify critical assets, attack surfaces and trust relationships.
Contribute to defining engagement scope, objectives and rules of engagement.
Assess IoT and embedded systems, including firmware, hardware interfaces such as UART/JTAG/SWD, OTA update mechanisms and secure boot.
Analyze and test communication protocols including TCP/IP, HTTP/HTTPS, MQTT, RTSP, VPN, Wi-Fi/BLE and TLS/mTLS/PKI.
Conduct cloud penetration testing across Azure, AWS and GCP, covering IAM, virtual networks, storage, databases, containers/Kubernetes and CI/CD pipelines.
Test web applications, APIs and backend services, including authentication, authorization, OWASP Top 10 and OAuth 2.0/OIDC/SAML/JWT.
Perform mobile application security assessments on Android and iOS environments.
Conduct penetration testing on Windows, Linux and Active Directory infrastructures.
Use controlled exploitation, post-exploitation and lateral movement techniques within agreed engagement boundaries.
Develop or adapt proof-of-concepts and scripts where required.
Produce complete, accurate and reproducible technical reports, together with clear executive summaries for management.
Present findings to technical teams, architects, project stakeholders and management.
Advise teams on vulnerability remediation and recommend improvements to architectures, security standards and development practices.
Retest identified vulnerabilities to validate the effectiveness of remediation.
Mentor less experienced security professionals and contribute to internal knowledge sharing.
The ideal candidate combines deep offensive security expertise with broad knowledge across multiple technology domains:
Cloud security: IAM, virtual networks, storage, databases, containers/Kubernetes and CI/CD pipelines across Azure, AWS and GCP.
IoT and embedded security: IoT/edge architectures, firmware analysis, hardware interfaces, update mechanisms and secure boot.
Application, API and mobile security, including OWASP WSTG, ASVS, API Security Top 10, MASVS/MSTG and relevant IoT security frameworks.
Network and protocol security covering TCP/IP, DNS, HTTP/HTTPS, REST, SOAP, WebSocket, gRPC, MQTT, AMQP, CoAP, RTSP, VPN and related technologies.
Offensive security tooling such as Kali/Parrot, Burp Suite, OWASP ZAP, Nmap, Wireshark, Nessus, Metasploit, Impacket and BloodHound.
Scripting and automation using Python, PowerShell and Bash, plus at least one additional programming language such as JavaScript, C, C++ or Java.
Minimum 10 years of experience in offensive security, with a proven ability to independently lead engagements from initial scoping through final presentation.
Expert-level technical autonomy and the ability to provide authoritative security advice.
Strong experience across multiple offensive security domains rather than specialization in a single technology.
Excellent analytical, reporting and communication skills, with the ability to translate complex technical findings into actionable recommendations for both technical and management audiences.
Comfortable mentoring less experienced profiles and sharing knowledge within a security team.
Excellent written and spoken technical English is required; knowledge of French and Dutch is highly valued.
Higher education in Computer Science, Cybersecurity, Electronics, Telecommunications or a related discipline, or equivalent professional experience.
Offensive security certifications such as OSCP/OSCP+, OSWE, OSEP, GPEN/GWAPT or IoT-focused certifications are considered an advantage. No individual certification is mandatory; practical experience and breadth of expertise are the key criteria.