Senior Security Pentester

HumanInTech

Brussel Hoofdstad

Hybride

EUR 85 000 - 110 000

Plein temps

Il y a 2 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Obtenez une réponse de cet employeur — un CV et une lettre de motivation adaptés exactement à ce qu’on recherche pour ce poste.

Passez les filtres ATS

Avantages offerts par ce poste

Freelance option
Full-time work

Résumé du poste

HumanInTech in Brussels seeks an senior offensive security consultant to lead IoT/security assessments across devices, networks and cloud. You will identify vulnerabilities, define scope, and document results with remediation guidance.

The role requires extensive expertise in IoT, embedded systems, cloud security and secure software development practices, with strong English and ideally French/Dutch. Freelance or employee engagement offered.

Qualifications

  • Minimum 5 years of offensive security experience and ability to lead assignments end-to-end.
  • Expertise in IoT and embedded systems security, firmware analysis, and hardware interfaces.
  • Strong cloud security knowledge (Azure/AWS/GCP) and CI/CD security.
  • Fluent technical English; bilingual French/Dutch preferred.
  • Formal education in CS/cybersecurity; relevant certifications assets.

Responsabilités

  • Prepare and execute penetration tests across IoT ecosystem including field devices, networks, and cloud.
  • Identify, exploit and document vulnerabilities affecting confidentiality, integrity, availability, or authenticity.
  • Define scope, objectives and rules of engagement for assignments.
  • Perform tests on cameras, edge devices, gateways, central systems.
  • Test IoT/embedded firmware, hardware interfaces, OTA updates, secure boot.
  • Test protocols and cloud security (Azure/AWS/GCP).
  • Test web apps, APIs and mobile apps when in scope.
  • Present results to teams and management with remediation guidance.

Connaissances

Penetration testing
IoT security
Cloud security
Written reports
Team mentoring

Formation

Bachelor's or higher in CS or related

Outils

Kali/Parrot
Burp Suite
Nessus
Mimikatz
Nmap
Wireshark

Description du poste

What you will do

You will prepare and execute penetration tests on a complete IoT ecosystem, covering field equipment, network infrastructure, cloud platforms, applications and mobile components. The work involves identifying, exploiting and documenting vulnerabilities that could affect the confidentiality, integrity, availability or authenticity of systems and data.

Your main tasks:

  • Analyse technical architectures and data flows; identify critical assets, attack surfaces and trust relationships
  • Participate in defining scope, objectives and rules of engagement for each assignment
  • Perform penetration tests (black box, grey box, white box) on cameras, edge equipment, gateways and central systems
  • Test IoT and embedded systems security: firmware, hardware interfaces (UART/JTAG/SWD), OTA updates, secure boot
  • Analyse and test communication protocols (TCP/IP, HTTP/HTTPS, MQTT, RTSP, VPN, Wi‑Fi/BLE, TLS/mTLS/PKI)
  • Conduct cloud penetration tests (IAM, virtual networks, storage, containers/Kubernetes, CI/CD pipelines) on Azure, AWS or GCP
  • Test web applications, APIs and backend services (authentication, authorisation, OWASP Top 10, OAuth 2.0/OIDC/SAML/JWT)
  • Test Android and iOS mobile applications when in scope
  • Perform penetration tests on Windows, Linux and Active Directory infrastructure
  • Document and present results to technical teams and management; advise teams on remediation
What we are looking for

You have at least 5 years of experience in offensive security and can lead an assignment independently, from scope definition to presenting results. You are explicitly not a junior.

Core competencies:

  • Mastery of penetration testing methodologies (black/grey/white box), controlled exploitation, post-exploitation and lateral movement
  • IoT and embedded systems expertise: firmware analysis, hardware interfaces (UART/JTAG/SWD), update mechanisms and secure boot
  • Network, protocol and cloud security (Azure/AWS/GCP): IAM, segmentation, containers/Kubernetes, CI/CD
  • Application, API and mobile security (OWASP, OAuth 2.0/OIDC/SAML/JWT, Android/iOS)
  • Writing technical and executive reports, guiding remediation and mentoring less experienced profiles

Technical skills (confirmed level):

  • Offensive tooling: Kali/Parrot, Burp Suite/OWASP ZAP, Nmap/Wireshark/Nessus, Metasploit/Impacket, Bloodhound/Mimikatz
  • Scripting and automation: Python, PowerShell, Bash and at least one additional language (JavaScript, C, Go, Ruby)
  • Methodologies and frameworks: OWASP (WSTG, ASVS, API Security Top 10, MASVS/MSTG, IoT Security Top 10)

Communication:

  • Present results to technical teams, architects, project managers and management
  • Able to guide less experienced profiles; teamwork and knowledge sharing
  • Preferably bilingual (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English, both written and spoken

Education:

Higher degree in computer science, cybersecurity, electronics or telecommunications, or equivalent professional experience. Technical certifications in offensive security are an asset (e.g. OSCP/OSCP+, OSWE, OSEP, GPEN/GWAPT, SEC556/PIPA for IoT). No single certification is individually required; the combination of practical experience and domain coverage is decisive.

Deliverables
  • Complete, precise and reproducible technical reports per vulnerability (affected systems, exploitation conditions, evidence, impact, risk level, recommendations)
  • Clear executive summary for management
  • Formalised scope, objectives and rules of engagement per assignment
  • Developed or adapted proof‑of‑concepts and scripts where needed
  • Retests to validate the effectiveness of corrections
  • Recommendations to improve architectures, security standards and development procedures
The setting

This assignment runs from 1 November 2026 to 31 December 2026. The location is Brussels, with no remote option. You will work within the cybersecurity service, focusing on offensive security for IoT ecosystems. All activities are carried out exclusively within an authorised framework, based on defined scope and formalised rules of engagement.

You can join us for this assignment as a freelancer or as an employee of HumanInTech. Same role, same team. If you join as an employee, your employment continues beyond this assignment. When it ends, we’ll work together to find your next assignment.

Location: Brussels

Work address: Belgium

Employer / contracting party: HumanInTech

Applications close (Brussels time): October 7, 2026 at 2:00 AM

Engagement: Freelance or employed by HumanInTech

Working hours: Full‑time

Experience: 6–10 years or more

Education: Bachelor's or more

Published: October 2026

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Senior Security Pentester
Senior Security Pentester

HumanInTech • Brussel

Sur place
EUR 90 000 - 130 000
Rémunération compétitive
Contrat freelance ou salarié
Formation et mentoring
Medior Security Pentester
Medior Security Pentester

HumanInTech • Brussel Hoofdstad

Hybride
EUR 55 000 - 75 000
Lead IoT Security Pentester
Lead IoT Security Pentester

HumanInTech • Brussel Hoofdstad

Hybride
EUR 85 000 - 110 000
Freelance option
Full-time work
IoT Security Pentester — Senior Offensive Tester
IoT Security Pentester — Senior Offensive Tester

HumanInTech • Brussel

Sur place
EUR 90 000 - 130 000
Rémunération compétitive
Contrat freelance ou salarié
Formation et mentoring
Medior Security Pentester
Medior Security Pentester

HumanInTech • Brussel

Sur place
EUR 60 000 - 90 000
Senior Security Pentester
Senior Security Pentester

Keystone Solutions • Belgique

À distance
EUR 90 000 - 130 000
Senior Security Pentester
Senior Security Pentester

Keystone Solutions • Brussel

Sur place
EUR 75 000 - 110 000
Application Architect with Security Focus
Application Architect with Security Focus

HumanInTech • Brussel Hoofdstad

Hybride
EUR 75 000 - 95 000
Hybrid working model
Brussels-based assignment
Freelance or employee
Senior Cybersecurity Architect
Senior Cybersecurity Architect

HumanInTech • Brussel Hoofdstad

Hybride
EUR 90 000 - 120 000
Senior Cybersecurity Expert Consultant
Senior Cybersecurity Expert Consultant

Keystone Solutions • Brussel

Sur place
EUR 90 000 - 130 000