Senior Security Pentester
Job Summary
The role encompasses the preparation and execution of penetration tests on the entire ANPR ecosystem (field equipment network cloud applications mobile) the production of actionable reports and guiding teams in remediating identified vulnerabilities.
Deliverables:
- Complete precise and reproducible technical reports per vulnerability (involved systems operating conditions evidence impact risk level recommendations)
- Clear executive summary for management
- Formalized scope objectives and rules of engagement per assignment
- Developed or modified proof-of-concepts and scripts where necessary
- Retests to validate the effectiveness of the corrections
- Recommendations for improving architectures security standards and development procedures
Main tasks:
- Analyze technical architectures and data flows; identify critical assets attack surfaces and trust relationships
- Participate in determining the scope objectives and rules of engagement of the assignments
- Perform penetration tests (black box grey box white box) on the ANPR ecosystem: cameras edge equipment gateways central systems
- Testing IoT and embedded systems for security (firmware hardware interfaces UART/JTAG/SWD OTA updates secure boot)
- Analyzing and testing communication protocols (TCP/IP HTTP/HTTPS MQTT RTSP VPN Wi-Fi/BLE TLS/mTLS/PKI etc.)
- Perform cloud pentesting (IAM virtual networks storage containers/Kubernetes CI/CD pipelines) on Azure AWS or GCP
- Testing web applications APIs and backend services (authentication authorization OWASP Top 10 OAuth 2.0/OIDC/SAML/JWT)
- Test mobile Android and iOS applications when they fall within the scope
- Perform penetration tests on Windows Linux and Active Directory infrastructure
- Document results and present them to technical teams and management and advise teams on remediation.
Core competencies:
- Mastery of penetration testing methodologies (black/grey/white box) controlled operation post-exploitation and lateral movement
- IoT and embedded systems expertise: firmware analysis hardware interfaces (UART/JTAG/SWD) update mechanisms and secure boot
- Network protocol and cloud security (Azure/AWS/GCP): IAM segmentation containers/Kubernetes CI/CD
- Application API and mobile security (OWASP OAuth 2.0/OIDC/SAML/JWT Android/iOS)
- Drafting technical and executive reports guidance on remediation and mentoring of less experienced profiles
Level and experience
- Authoritative advice and fully independent execution (SFIA level 5 - Ensure advise)
- Minimum of 5 years of experience in offensive security; capable of independently leading an assignment from scope definition to presentation of results; expressly not a junior
Skills:
- Cloud: IAM virtual networks storage databases containers/Kubernetes CI/CD pipelines (Azure AW
- IoT en embedded systemen: IoT-/edge-computingarchitecturen firmware-analyse hardware-interfaces i
- Methodologies and reference frameworks: OWASP (WSTG ASVS API Security Top 10 MASVS/MSTG IoT Security
- Networks and protocols: TCP/IP DNS HTTP/HTTPS REST/SOAP/WebSocket/gRPC MQTT/AMQP/CoAP RTSP V
- Offensieve tooling: Kali/Parrot Burp Suite/OWASP ZAP Nmap/Wireshark/Nessus Metasploit/Impacket B
- Scripting and automation: Python PowerShell Bash and at least one additional language (JavaScript C)
Diploma:
Higher degree in computer science cybersecurity electronics or telecommunications or equivalent professional experience.
Technical certifications in offensive security are an asset (e.g. OSCP/OSCP OSWE OSEP GPEN/GWAPT SEC556/PIPA for IoT).
Required Skills:
WINDOWSAWSAZUREJTAGAPISVIRTUAL NETWORKSUARTIOSCLOUD SECURITYCI/CDSEGMENTATIONHTTPMQTTLINUXKUBERNETESVPN
About Company
30 employees
Welcome to Sansaone, a dynamic force in the realm of ICT talent acquisition. Born out of a passion for excellence and a vision for connecting outstanding professionals with forward-thinking organizations, we stand as a beacon for strategic recruitment solutions in the Information and ... View more