About the job Security/Penetration Test Engineer (Information Technology/Software)
Our client, a leading Software, Information and Communication Technologies company, operates internationally (Athens, Brussels, Luxembourg, Copenhagen, Stockholm, London, Nicosia, Hong-Kong, Valetta, etc). Our client is a renowned supplier of IT services to government institutions, multinational corporations, public administrations and multinational companies, research and academic institutes.
Role Overview
Our client currently has a vacancy for a Security/Penetration Test Engineer fluent in English, to offer his/her services as an expert who will be based in France. The work will be carried out either in the company’s premises or on site at customer premises. In the context of the first assignment, the successful candidate will be integrated in the Development team of the company that will closely cooperate with a major client’s IT team.
Location: Strasbourg, France
Workplace: Onsite
Deadline for submission: 12/10/2026
Please note that we can consider only EU candidates for this position due to security clearance.
Requirements
- University degree in IT combined with relevant professional experience of at least 7 years in providing IT and Information security services;
- Experience with penetration testing against a wide variety of applications including web, mobile, and thick client above and beyond running automated tools required;
- Experience providing consulting services in a highly confidential environment;
- Experience with SAST: SonarQube, OWASP, FortifySCA, NVD;
- Experience with DAST, Web Application and Penetration Tests: Fortify WebInspect, OWASP ZAP, Burp Suite, Kali Linux;
- Experience with dependencies and containers tests: GitHub Advanced Security, JFrog XRay, JFrog Curation, Advanced Cluster Security;
- Experience in technical analysis, reporting and writing documents;
- Experience in decomposing and analysing systems to identify weaknesses and ineffective controls;
- Experience in reviewing codes assess their security;
- Industry certifications or similar qualifications appropriate to the services provided, such those listed below, will be considered a plus: GIAC Certified Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), Certified Ethical Hacker (CEH), GIAC Systems and Network Auditor (GSNA), Certified Penetration Tester (CPT), Certified Expert Penetration Tester (CEPT), GIAC Certified Web Application Defender (GWEB), ISC2 Certified Secure Software Lifecycle Professional (CSSLP), Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), CREST Penetration Testing Certifications.
- Excellent command of the English language.
Responsibilities
- Identify, analyse and assess technical and organisational cybersecurity vulnerabilities;
- Identify attack vectors, uncover and demonstrate exploitation of technical cybersecurity vulnerabilities;
- Test systems and operations compliance with regulatory standards;
- Select and develop appropriate penetration testing techniques;
- Organise test plans and procedures for penetration testing;
- Establish procedures for penetration testing result analysis and reporting;
- Document and report penetration testing results to stakeholders;
- Deploy penetration testing tools and test programs;
- Security source code review or development experience at least in C/C++, C#, VB.NET, ASP, or Java;
- Identify the security risk level, business impact and provide the remediation plan;
- Use tools and manual testing to perform code security analysts to identify vulnerabilities and attack vectors in applications and infrastructure. Execute SAST, DAST, vulnerability scans and penetration tests;
- Draft security test cases based on the requirements.