Senior Security Pentester

keystone-solutions

Brussel

On-site

EUR 90,000 - 120,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Keystone Solutions is seeking a Senior Security Pentester to join our consultancy at a client site. You will perform penetration testing across IoT platforms, ANPR cameras, embedded devices, cloud services, APIs, and web/mobile apps.

You will produce detailed reports, guide teams on remediation, and define scope and rules of engagement for each assignment. Strong English and Dutch/French skills are preferred, with at least 5 years in offensive security.

Qualifications

  • Minimum 5+ years in offensive security or pentesting.
  • Experience across IoT, embedded systems, cloud, and application security.
  • Ability to produce precise, reproducible reports and executive summaries.

Responsibilities

  • Lead and execute penetration tests across ANPR ecosystems (devices, network, cloud, apps).
  • Develop or customize PoCs and scripts; guide remediation.
  • Deliver formal scope, rules of engagement, and reports to client teams.

Skills

Penetration testing
IoT security
Cloud security
Network security
Reporting & remediation guidance

Education

Higher degree in CS / cybersecurity / electronics / telecommunications

Tools

Kali/Linux
Burp Suite
OWASP ZAP
Nessus/Metasploit
Wireshark

Job description

Mission Overview

Keystone Solutions is seeking a Senior Security Pentester to join our consultancy mission at a client site. The consultant will work in a complex technical environment focusing on IoT platforms, including ANPR cameras, connected devices, embedded systems, network infrastructure, cloud platforms, APIs, web applications, and central processing systems.

Responsibilities

The role involves preparing and executing penetration tests across the entire ANPR ecosystem (field equipment, network, cloud, applications, mobile), producing actionable reports, and guiding teams in addressing identified vulnerabilities. These responsibilities will be carried out under Keystone Solutions' consultancy model.

Deliverables
  • Comprehensive, precise, and reproducible technical reports for each vulnerability (involved systems, exploitation conditions, evidence, impact, risk level, recommendations)
  • Clear executive summary for management
  • Formalized scope, objectives, and rules of engagement for each assignment
  • Developed or customized proof-of-concepts and scripts as needed
  • Retests to validate the effectiveness of corrections
  • Recommendations for improving architectures, security standards, and development procedures
Main Tasks
  • Analyze technical architectures and data flows; identify critical assets, attack surfaces, and trust relationships
  • Participate in defining the scope, objectives, and rules of engagement for assignments
  • Conduct penetration tests (black box, grey box, white box) on the ANPR ecosystem: cameras, edge devices, gateways, central systems
  • Test IoT and embedded systems for security (firmware, hardware interfaces UART/JTAG/SWD, OTA updates, secure boot)
  • Analyze and test communication protocols (TCP/IP, HTTP/HTTPS, MQTT, RTSP, VPN, Wi‑Fi/BLE, TLS/mTLS/PKI, etc.)
  • Perform cloud penetration testing (IAM, virtual networks, storage, containers/Kubernetes, CI/CD pipelines) on Azure, AWS, or GCP
  • Test web applications, APIs, and backend services (authentication, authorization, OWASP Top 10, OAuth 2.0/OIDC/SAML/JWT)
  • Test mobile Android and iOS applications when within scope
  • Conduct penetration tests on Windows, Linux, and Active Directory infrastructure
  • Document and present results to technical teams and management, advising teams on remediation
Core Competencies
  • Mastery of penetration testing methodologies (black/grey/white box), controlled exploitation, post‑exploitation, and lateral movement
  • Expertise in IoT and embedded systems: firmware analysis, hardware interfaces (UART/JTAG/SWD), update mechanisms, and secure boot
  • Network, protocol, and cloud security (Azure/AWS/GCP): IAM, segmentation, containers/Kubernetes, CI/CD
  • Application, API, and mobile security (OWASP, OAuth 2.0/OIDC/SAML/JWT, Android/iOS)
  • Ability to produce technical and executive reports, guide remediation, and mentor less experienced profiles
Communication and Collaboration
  • Present results to technical teams, architects, project managers, and management
  • Ability to mentor less experienced profiles; teamwork and knowledge sharing
  • Preferably bilingual (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English, both written and spoken
Level and Experience

Authoritative advice and fully independent execution (SFIA level 5 – Ensure, advise). Minimum 5+ years of experience in offensive security; capable of leading an assignment independently, from scope definition to presentation of results; explicitly not a junior role.

Degree

Higher degree in computer science, cybersecurity, electronics, or telecommunications, or equivalent professional experience. Technical certifications in offensive security are a plus (e.g., OSCP/OSCP+, OSWE, OSEP, GPEN/GWAPT, SEC556/PIPA for IoT). No single certification is individually required - the combination of practical experience and domain coverage is decisive.

Duration

Duration: 01/11/2026 - 31/12/2026 2 months (full time)

Skills required
  • Cloud: IAM, virtuele netwerken, opslag, databases, containers/Kubernetes, CI/CD-pipelines (Azure, AW - Level: Confirmed - Most recent: Any time
  • IoT en embedded systemen: IoT-/edge-computingarchitecturen, firmware-analyse, hardware-interfaces, i - Level: Confirmed - Most recent: Any time
  • Methodologieën en referentiekaders: OWASP (WSTG, ASVS, API Security Top 10, MASVS/MSTG, IoT Security - Level: Confirmed - Most recent: Any time
  • Netwerken en protocollen: TCP/IP, DNS, HTTP/HTTPS, REST/SOAP/WebSocket/gRPC, MQTT/AMQP/CoAP, RTSP, V - Level: Confirmed - Most recent: Any time
  • Offensieve tooling: Kali/Parrot, Burp Suite/OWASP ZAP, Nmap/Wireshark/Nessus, Metasploit/Impacket, B - Level: Confirmed - Most recent: Any time
  • Scripting en automatisering: Python, PowerShell, Bash en minstens één bijkomende taal (JavaScript, C - Level: Confirmed - Most recent: Any time
Language requirements

Dutch Level Active knowledge

English Level Active knowledge

French Level Active knowledge

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Pentester
Senior Security Pentester

TiTANS België • Belgium

Remote
EUR 90,000 - 120,000
Senior Security Pentester
Senior Security Pentester

TiTans Consulting • Belgium

Remote
EUR 85,000 - 120,000
Medior Security Pentester
Medior Security Pentester

Keystone Solutions • Brussel Hoofdstad

Hybrid
EUR 60,000 - 90,000
Medior Security Pentester
Medior Security Pentester

Keystone Solutions • Brussel

On-site
EUR 60,000 - 80,000
Medior Security Pentester
Medior Security Pentester

Keystone Solutions • Brussel

On-site
EUR 60,000 - 80,000
Medior Security Pentester
Medior Security Pentester

keystone-solutions • Brussel

On-site
EUR 55,000 - 85,000
Junior Functional Security Analyst
Junior Functional Security Analyst

Keystone Solutions • Brussel

On-site
EUR 42,000 - 54,000
Senior Pentester Cybersecurity IoT (In dienst of freelance)
Senior Pentester Cybersecurity IoT (In dienst of freelance)

EngiFlex BV • Brussel Hoofdstad

Hybrid
EUR 70,000 - 100,000
Bedrijfswagen
Freelance mogelijk
Extralegale voordelen
Security Project Manager
Security Project Manager

keystone-solutions • Brussel Hoofdstad

On-site
EUR 90,000 - 120,000
Senior Cybersecurity Expert Consultant
Senior Cybersecurity Expert Consultant

Keystone Solutions • Brussel

On-site
EUR 90,000 - 130,000