Deadline: December 31, 2026

Penetration Tester 6

Location: Braine-l’Alleud, BE (Full time on-site; includes 10 days of foreseen travel in Belgium, with future location transitioning to Brussels following the NCSC relocation)

Duties & Roles:

  • Penetration Testing & Red/Blue Teaming: Conduct comprehensive web application, infrastructure, and application-level penetration testing. Lead and/or participate as part of the Red/Blue Team during NATO military exercises.
  • Security Design & Policy Compliance: Perform security design reviews to verify full compliance with NATO security policies and directives. Provide security consultancy, technical advice, and risk assessments for ongoing projects, engineering plans, and associated entities.
  • Stakeholder Coordination: In coordination with the Head of the Penetration Testing Cell, maintain proactive communication and collaboration with internal and external stakeholders. Act as a liaison with the NCIA Configuration Control Board, Security Accreditation Boards, NATO Security Accreditation Authorities (SAAs), and NCI Agency accreditation support units.
  • Reporting & Senior Briefings: Deliver structured technical briefings and present testing outcomes and security assessment reports to both technical audiences and executive leadership, including at the flag officer level.

Skill, Knowledge & Experience:

  • Core Technical Experience: More than 3 years of extensive knowledge and hands-on experience in web application penetration testing, IT infrastructure penetration testing, and network security architecture design.
  • Vulnerability Assessment & Methodologies: Proven expertise in assessing vulnerabilities within operating systems, software, network protocols, and enterprise network architectures using recognized testing methodologies and penetration testing tools. Experience researching and evaluating emerging security products and defensive technologies.
  • Systems & Scripting: Strong knowledge of system and network administration across both UNIX and Windows environments. Practical scripting skills in at least one relevant language: Python, Perl, Ruby, or shell scripting (bash, ksh, csh).
  • Security Architecture & Protocols: In-depth technical knowledge of system and network security, cryptography, authentication and security protocols, application security, malware infection techniques, and defensive protection mechanisms.
  • Risk Evaluation & Reporting: Proven ability to evaluate cybersecurity risks, formulate pragmatic remediation and mitigation plans, and write clear, well-structured technical reports covering executive summaries, technical findings, and actionable remediation steps.
  • Clearance: A valid NATO Secret security clearance is mandatory.

    By sending this form, you agree with our Privacy Policy and Terms and Conditions.

     

    If you’re interested in this opportunity and would like to learn more, please fill out the form below, and a member of our team will get in touch with you shortly.