Job Openings Medior Security Pentester

About the job Medior Security Pentester

Mission Overview:


Keystone Solutions is seeking a Medior Security Pentester to join our consultancy mission at a client site. The consultant will have confirmed practical experience in penetration testing and will primarily work in three areas: web applications, APIs, and administration portals; network infrastructures and protocols; and Windows and Active Directory environments.


The consultant will autonomously conduct standard complexity missions and contribute to more complex missions (cloud, containers, mobile, purple teaming) under the coordination of a senior profile. All activities will be performed within an authorized framework, based on a defined scope and formalized engagement rules.


Key Responsibilities:


  • Prepare and conduct penetration tests on web applications, networks, and Windows/Active Directory environments, producing technical reports and contributing to remediation efforts with senior support on complex missions.
  • Deliver comprehensive, precise, and reproducible technical reports by vulnerability (affected systems, exploitation conditions, evidence, impact, risk, recommendations).
  • Contribute to executive summaries for management, reviewed by a senior.
  • Define the scope, objectives, and engagement rules of missions in collaboration with a senior.
  • Provide simple proof of concepts and scripts tailored to needs.
  • Conduct retests to validate the effectiveness of corrections.
  • Contribute to internal capitalization: methodologies, checklists, report templates, tooling.

Key Skills:


  • Structured penetration testing methodology (black/grey/white box); controlled exploitation and post-exploitation.
  • Web application and API testing: OWASP Top 10, modern authentication/authorization (OAuth 2.0/OIDC/SAML/JWT), targeted code review.
  • Network and infrastructure testing: protocols (TCP/IP, DNS, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP), segmentation, filtering.
  • Windows/Active Directory testing: domain enumeration, Kerberos/NTLM, GPO/ACL, lateral movement, PowerShell.
  • Technical report writing and ability to escalate/collaborate with a senior.

Communication and Collaboration:


  • Present results to technical teams and project managers; executive summary reviewed by a senior.
  • Ability to seek support and escalate at the right time; teamwork and knowledge sharing.
  • Bilingual preferred (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English.

Experience and Education:


  • Minimum 3 years of experience (ideally 3 to 5 years); independently conducts standard missions and contributes to complex missions under senior coordination.
  • Higher education degree in computer science, cybersecurity, or telecommunications, or equivalent professional experience.
  • Preferred certifications: OSCP/OSCP+, Burp Suite Certified Practitioner (BSCP), CRTP; no certification is required.

Why Join Keystone Solutions:


As a consultant at Keystone Solutions, you will engage in dynamic projects that offer a variety of challenges across different client environments. Our commitment to turbo-charged learning ensures that you will have broad professional development opportunities, and we are dedicated to supporting your career growth within our framework. Being a 'K-Stone' means bringing our core values to every engagement.


If you are ready to tackle technical and strategic challenges in a dynamic consultancy environment, apply today at Keystone Solutions Career Portal.


Duration: 01/11/2026 - 31/12/2026 2 months • (full time)


Skills required:

  • Applications web et API : injections, IDOR, XSS, SSRF, désérialisation, gestion de sessions/tokens, - Level: Junior - Most recent: Any time
  • Méthodologies et référentiels : OWASP WSTG/ASVS/API Security Top 10, PTES, MITRE ATT&CK, CVSS, CWE/C - Level: Junior - Most recent: Any time
  • Notions complémentaires (atout) : cloud (Azure/AWS/GCP), Linux, conteneurs/Kubernetes/CI-CD, applica - Level: Junior - Most recent: Any time
  • Outillage : Kali/Parrot, Burp Suite/OWASP ZAP, Nmap/Wireshark/Nessus, Metasploit/Impacket/NetExec, B - Level: Junior - Most recent: Any time
  • Réseaux et protocoles : TCP/IP, DNS/DHCP/NTP/SNMP, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP/WinRM, VPN - Level: Junior - Most recent: Any time
  • Windows et Active Directory : objets AD, GPO, ACL, relations d’approbation, Kerberos/NTLM (Kerberoas - Level: Junior - Most recent: Any time

Language requirements:

Dutch
Level Active knowledge
English
Level Active knowledge
French
Level Active knowledge