A public utility organisation is strengthening its cybersecurity posture through independent technical assessments of its information system. As a Senior IT Security Expert, you will combine internal and external penetration testing with security reviews of Microsoft Entra ID, Microsoft Azure, Microsoft and Linux environments, while acting as a technical reference for infrastructure and transformation projects.
The mission
The organisation is reviewing its security level across Microsoft Windows Server, Active Directory, Microsoft Entra ID, Azure, Linux and network infrastructure. The programme combines technical audits, vulnerability analysis, attack-path analysis and penetration tests with reviews of architecture, authentication, privileged access and existing controls. Results will be assessed against OWASP Top 10, MITRE ATT&CK, NIST Cybersecurity Framework and CIS Benchmarks, then used to guide risk-based remediation and future infrastructure decisions.
You will independently lead complex assessments from scoping and testing to recommendations and follow-up. Your work will cover internal and external attack simulations, configuration and hardening reviews, privilege escalation and lateral movement analysis, and security input to architecture and transformation projects. You will translate technical evidence for IT teams and management, prioritising actions according to exploitability, business impact and operational feasibility. The programme is planned over 12 months at approximately 2.5 days per week.
Your responsibilities
- Assess the security of Microsoft, Azure, Linux, identity and network environments, identifying exploitable weaknesses and their business impact.
- Execute internal and external penetration tests and technical audits, documenting evidence and validating existing protection measures.
- Trace attack paths, privilege escalation and lateral movement scenarios to expose realistic routes to compromise.
- Advise on security architecture, project decisions and remediation measures that reduce risk without compromising operational continuity.
- Prioritise corrective actions and track their progression with internal technical teams.
- Produce technical and executive reports, present findings to different audiences, and transfer practical knowledge to internal teams.
Your profile
Essential skills
- Bring at least 7 years of professional cybersecurity experience in complex environments and operate independently on demanding assignments.
- Conduct internal and external penetration testing and technical audits using a structured, evidence-based approach.
- Assess and secure Microsoft environments, Microsoft Entra ID, Microsoft Azure and Linux systems.
- Analyse identities, privileged access, authentication mechanisms, vulnerabilities and attack paths, then formulate pragmatic remediation advice.
- Communicate clearly with infrastructure specialists and management, adapting technical findings to the audience.
- Hold the Offensive Security Certified Professional (OSCP) certification or an equivalent recognised offensive security certification.
Preferred skills
- Audit Active Directory and work with Microsoft Windows Server, Microsoft 365, Debian or Ubuntu.
- Evaluate TCP/IP networks, switching, routing, VLANs, enterprise Wi-Fi, firewalls, VPNs and VMware or Hyper-V environments.
- Apply the OWASP Testing Guide, OWASP Top 10, MITRE ATT&CK, NIST Cybersecurity Framework and CIS Benchmarks.
- Use Python or other scripting, Rapid7, Burp Suite for web application pentesting, Wireshark and vulnerability assessment tools.
- Hold BSCP, PNPT, CRTO, CRTP, GXPN, CISSP, Azure Security Engineer Associate or another Microsoft security certification.