Rhox

Medior Security Pentester

Closes on 07/10/2026
Brussels
On site
Starts on 01/11/2026
Remuneration: 2.900 - 3.200 EUR/mo gross+ extralegal advantages ·Freelance also possible

Apply for this role

or apply with email & CV

Drag & drop your CV here, or click to browse

PDF, DOC, DOCX, or TXT (max 4MB)

By applying, you agree to our Terms of Service and Privacy Policy.

We're looking for a Medior Security Pentester and ethical hacker to test web applications and APIs, networks, and Windows/Active Directory environments. You’ll handle standard tests independently and work with senior support on complex assignments.

What you'll do

  • Analyse architectures, data flows, critical assets and trust relationships.
  • Define scopes and engagement rules with a senior pentester.
  • Test web applications, APIs, networks and Windows/Active Directory environments.
  • Document vulnerabilities with evidence, impact, risk and remediation guidance.
  • Present findings and retest fixes to verify their effectiveness.

What you bring

  • At least three years of practical experience in penetration testing, handling standard tests independently and escalating complex or critical findings.
  • Structured black-, grey- and white-box testing, controlled exploitation and post-exploitation.
  • Web/API security: OWASP Top 10, WSTG, ASVS, API Security Top 10; injections, IDOR, XSS, SSRF, deserialisation, session and token handling, OAuth 2.0, OIDC, SAML and JWT.
  • Network knowledge: TCP/IP, DNS/DHCP/NTP/SNMP, HTTP/HTTPS/TLS, SMB/LDAP/Kerberos/RDP/WinRM and VPN.
  • Windows and Active Directory: domain enumeration, GPOs, ACLs, Kerberos/NTLM, lateral movement and PowerShell.
  • PTES, MITRE ATT&CK, CVSS and CWE; Kali/Parrot, Burp Suite/OWASP ZAP, Nmap, Wireshark, Nessus, Metasploit, Impacket and NetExec.
  • Clear technical reporting, reproducible evidence, remediation advice and presentation of findings.
  • Higher education in computer science, cybersecurity or telecommunications, or equivalent professional experience.
  • English, French and Dutch, B2 each.

Nice to have

  • Cloud (Azure, AWS or GCP), Linux, containers/Kubernetes, CI/CD, mobile testing or purple teaming.
  • OSCP/OSCP+, Burp Suite Certified Practitioner (BSCP) or CRTP certification.

Good to know

  • Testing takes place only within an authorised scope and documented rules of engagement.

What's next?

The people who do well here are the ones who saw themselves in this description. Not because they match every line, but because the mission felt right for them.

We are actively hiring for this position. Applications are reviewed by our team, and matching profiles receive a call to discuss the role in detail.

It takes under a minute to apply. Your email, your CV. That is all we need to start the conversation.