Penetration tester
C004909, C004908 Penetration Tester
The Penetration Tester will support NATO cyber security activities by:
- Conducting web application, infrastructure, and application penetration testing.
- Participating in and leading Red Team and Blue Team activities during NATO military exercises.
- Performing security design reviews to ensure compliance with NATO security policies and directives.
- Providing cyber security consultancy and technical advice to projects and operational entities.
- Identifying security vulnerabilities and recommending remediation measures.
- Coordinating with security and accreditation stakeholders, including:
- NCIA Configuration Control Board (CCB)
- Security Accreditation Boards (SABs)
- NATO Security Accreditation Authorities
- Other NCIA organizational units
- Preparing and presenting security assessment results to both technical and executive audiences, including senior military leadership.
- Supporting collaboration between internal and external stakeholders under the direction of the Head of the Penetration Testing Cell.
Required Skills & Experience
Technical Expertise
Minimum 3 years of experience in:
- Web application penetration testing
- IT infrastructure penetration testing
- Network security architecture
- Security vulnerability assessment (operating systems, software, protocols, and networks)
- Security tools and technologies evaluation
- UNIX/Linux and Windows system administration
- Penetration testing methodologies, tools, and techniques
Programming / Scripting
Experience with at least one of:
- Python
- Perl
- Ruby
- Shell scripting (Bash, KSH, CSH)
Security Knowledge
Strong understanding of:
- System and network security
- Authentication and security protocols
- Cryptography
- Application security
- Malware techniques and protection mechanisms
Analytical & Communication Skills
Ability to:
- Assess risks and develop mitigation plans
- Produce high-quality technical reports
- Write executive summaries and remediation plans
- Present findings to both technical and non-technical stakeholders
Working Conditions
- Location: Braine-l'Alleud, Belgium (later moving to Brussels)
- Work Mode: Full-time on-site
- Duration: July–December 2026
- Travel: Approximately 10 days within Belgium
- Security Clearance: NATO Secret