About the job Medior Security Pentester
Mission Overview:
Keystone Solutions is seeking a Medior Security Pentester to join our consultancy mission at a client site. The consultant will have confirmed practical experience in penetration testing and will primarily work in three areas: web applications, APIs, and administration portals; network infrastructures and protocols; and Windows and Active Directory environments.
The consultant will autonomously conduct standard complexity missions and contribute to more complex missions (cloud, containers, mobile, purple teaming) under the coordination of a senior profile. All activities will be performed within an authorized framework, based on a defined scope and formalized engagement rules.
Key Responsibilities:
- Prepare and conduct penetration tests on web applications, networks, and Windows/Active Directory environments, producing technical reports and contributing to remediation efforts with senior support on complex missions.
- Deliver comprehensive, precise, and reproducible technical reports by vulnerability (affected systems, exploitation conditions, evidence, impact, risk, recommendations).
- Contribute to executive summaries for management, reviewed by a senior.
- Define the scope, objectives, and engagement rules of missions in collaboration with a senior.
- Provide simple proof of concepts and scripts tailored to needs.
- Conduct retests to validate the effectiveness of corrections.
- Contribute to internal capitalization: methodologies, checklists, report templates, tooling.
Key Skills:
- Structured penetration testing methodology (black/grey/white box); controlled exploitation and post-exploitation.
- Web application and API testing: OWASP Top 10, modern authentication/authorization (OAuth 2.0/OIDC/SAML/JWT), targeted code review.
- Network and infrastructure testing: protocols (TCP/IP, DNS, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP), segmentation, filtering.
- Windows/Active Directory testing: domain enumeration, Kerberos/NTLM, GPO/ACL, lateral movement, PowerShell.
- Technical report writing and ability to escalate/collaborate with a senior.
Communication and Collaboration:
- Present results to technical teams and project managers; executive summary reviewed by a senior.
- Ability to seek support and escalate at the right time; teamwork and knowledge sharing.
- Bilingual preferred (French, Dutch) or sufficient knowledge of the second national language; excellent understanding of technical English.
Experience and Education:
- Minimum 3 years of experience (ideally 3 to 5 years); independently conducts standard missions and contributes to complex missions under senior coordination.
- Higher education degree in computer science, cybersecurity, or telecommunications, or equivalent professional experience.
- Preferred certifications: OSCP/OSCP+, Burp Suite Certified Practitioner (BSCP), CRTP; no certification is required.
Why Join Keystone Solutions:
As a consultant at Keystone Solutions, you will engage in dynamic projects that offer a variety of challenges across different client environments. Our commitment to turbo-charged learning ensures that you will have broad professional development opportunities, and we are dedicated to supporting your career growth within our framework. Being a 'K-Stone' means bringing our core values to every engagement.
If you are ready to tackle technical and strategic challenges in a dynamic consultancy environment, apply today at Keystone Solutions Career Portal.
Duration: 01/11/2026 - 31/12/2026 2 months • (full time)
Skills required:
- Applications web et API : injections, IDOR, XSS, SSRF, désérialisation, gestion de sessions/tokens, - Level: Junior - Most recent: Any time
- Méthodologies et référentiels : OWASP WSTG/ASVS/API Security Top 10, PTES, MITRE ATT&CK, CVSS, CWE/C - Level: Junior - Most recent: Any time
- Notions complémentaires (atout) : cloud (Azure/AWS/GCP), Linux, conteneurs/Kubernetes/CI-CD, applica - Level: Junior - Most recent: Any time
- Outillage : Kali/Parrot, Burp Suite/OWASP ZAP, Nmap/Wireshark/Nessus, Metasploit/Impacket/NetExec, B - Level: Junior - Most recent: Any time
- Réseaux et protocoles : TCP/IP, DNS/DHCP/NTP/SNMP, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP/WinRM, VPN - Level: Junior - Most recent: Any time
- Windows et Active Directory : objets AD, GPO, ACL, relations d’approbation, Kerberos/NTLM (Kerberoas - Level: Junior - Most recent: Any time
Language requirements:
Dutch
Level Active knowledge
English
Level Active knowledge
French
Level Active knowledge