WLG

Offensive Security Engineer (Application and Network Penetration Testing) for NATO with security clearance

WLG The Hague, South Holland, Netherlands

Financial Services · 2-10 employees

6 h ago
security Mid (2-5 yrs) Full-time Netherlands
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The role involves conducting web and infrastructure penetration testing while leading or participating in red and blue team military exercises. You will also provide security consultancy, design reviews, and technical briefings to senior leadership and accreditation boards.

What they look for

Penetration testing Web application security IT infrastructure security Network security architecture Red teaming Blue teaming Vulnerability assessment UNIX administration Windows administration Python Perl Ruby Shell scripting Cryptography Malware analysis Technical writing

Requirements

Candidates must have over three years of hands-on experience in penetration testing and network security architecture. Proficiency in system administration, scripting languages, and the ability to produce structured technical reports for diverse audiences is required.

Full description

You would spend the year finding what an adversary would find first.

A multinational defence organisation is looking for a penetration tester to work inside itstesting cell: leading or joining red and blue teams during military exercises, and testing thesystems the rest of the year. On-site in The Hague, Netherlands, with around ten days of travelforeseen.

What you will be doing

  • Leading, or forming part of, the red and blue teams during large multinational exercises
  • Web, infrastructure and application-level penetration testing
  • Security design reviews, checking compliance against organisational policy and directives
  • Security consultancy and advice to projects, plans and other parts of the organisation
  • Working with configuration control boards, accreditation boards and the nationalaccreditation authorities that sign systems off
  • Briefing at both technical and executive level — including the most senior officers — onfindings and remediation

What you will need

  • More than three years of hands-on depth across web application and IT infrastructurepenetration testing, and network security architecture design
  • Assessing vulnerabilities in operating systems, software, protocols and networks, andevaluating security products and technologies
  • System and network administration on both UNIX and Windows
  • Recognised testing methodologies and the tooling that goes with them
  • Scripting in at least one of Perl, Python, Ruby or shell
  • Real technical knowledge of authentication and security protocols, cryptography, applicationsecurity, malware infection techniques and the protections against them
  • The ability to evaluate risk and write a mitigation plan, not just a finding
  • Clear, structured technical writing — executive summary, technical detail and remediation, foraudiences that read very differently

Why this one is worth a look

The exercises are real, the scope is broad, and your reports get read at the top of theorganisation. Few penetration testing roles combine that reach with this much technicalfreedom.

Similar roles