This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As a Junior Pentester, you will perform penetration tests on our global IT infrastructure. You'll have the opportunity, under guidance, to actively contribute to testing projects and take ownership of specific components. Every task is a learning opportunity to broadly develop your skills and build a solid foundation in the field. You are part of the Randstad Global Offensive Security Team in the global CISO office. Together with 7 other Offensive Security Specialists, the team offers various security services to all Randstad countries and their IT landscape. They include a range of activities from traditional penetration testing (black/white box) to complex Red Teaming exercises, simulating real-world adversary tactics and techniques. We believe in an approach of working with developers and infrastructure teams instead of only supplying them with a report. By working closely with other IT teams we become ‘The Partner’ in identifying and resolving vulnerabilities to all Randstad countries.
Job Responsibility:
Perform penetration tests on web applications, mobile applications, and network and infrastructure assessments
Work closely with application development and infrastructure teams to support and follow up on resolving the vulnerabilities found
Contribute to the improvement of security testing processes and methodologies by actively seeking opportunities to apply new knowledge
Stay updated on the latest security best practices, technologies, threats, and vulnerabilities related to web, mobile, network and infrastructure security
Requirements:
Strong Hacker Mindset: naturally curious and analytical, think 'out-of-the-box' when approaching systems, and driven to understand how things work (and potentially how to bypass them), always with the goal of improving security
0-2 years of relevant working knowledge and experience in the pentest field
Foundational understanding of common hacking techniques, security standards, and best practices, including the basics of OWASP Top 10
Basic understanding of penetration testing methodologies in any of the following areas: network penetration testing, web application security, mobile application security, and network infrastructure
Proactive in seeking guidance to enhance understanding and skills across diverse security areas
Ability to work with an international environment and to team up with other security and development teams
Good communication skills in English
Nice to have:
Awareness of relevant industry frameworks like MITRE ATT&CK
Certificates related to competence offensive security - (e.g. OSWE, OSCP, CEH, GIAC GPEN, GIAC GXPN, EC-Council LPT)
Experience in developing applications
Knowledge of cloud security best practices for AWS and GCP
Ability to read and understand code (Java, Python, React/Angular)