Spektrum
Tech / AI / Software
Penetrationtester
“Penetration tester at Spektrum. Skills: Penetration testing, Security assessments, Vulnerability assessment, Risk management. Provide Web, infrastructure and application-level penetration testing, including but not limited to COTS software and NOTS/GOTS software (NATO/Government off the Shelf), following clearly defined methodologies.. Participate in kick-off meetings with stakeholders and technical points of contact in order to identify requirements for testing.”
What You'll Achieve.
Contribute to its POW based on the deliverables that are described in the scope of work below.
Industry & Context.
Ability to evaluate risks and formulate mitigation plans.
Some travel to other NATO sites may be required, Valid National or NATO Secret personal security clearance
What They're Looking For.
Must Have
Web application penetration testing, IT infrastructure penetration testing, Network security architecture design, Assessing security vulnerabilities within OS, software, protocols & networks, Researching and evaluating security products & technologies, Knowledge in system and network administration of UNIX and Windows systems, Use of penetration testing tools, techniques, and recognized testing methodologies, Scripting skills in at least one of the following: Python, Go, PowerShell, shell (bash, ksh, csh), Technical knowledge in system and network security, authentication and security protocols, cryptography, application security, as well as, malware infection techniques and protection technologies., Ability to evaluate risks and formulate mitigation plans., Proven ability to brief at executive level on security findings, reports and testing outcome., Proven ability to write clear and structured technical reports including executive summary, technical findings and remediation plan for several different audiences., A thorough knowledge of one of the two NATO languages, both written and spoken, is essential and some knowledge of the other is desirable., Valid National or NATO Secret personal security clearance
Nice to Have
OSCP, OSCE, OSWE, GPEN, CREST Certified Web Application Tester, GXPN, GWAPT or equivalent, Familiarity with risk analysis methodologies., Prior experience of working in an international environment comprising both military and civilian elements., Knowledge of NATO organization, internal structure and resultant relationships., some knowledge of the other NATO language is desirable
What You'll Do.
infrastructure and application-level penetration testing
including but not limited to COTS software and NOTS/GOTS software (NATO/Government off the Shelf)
following clearly defined methodologies.
Participate in kick-off meetings with stakeholders and technical points of contact in order to identify requirements for testing.
Follow the documented procedures and workflows outlined by the technical leads
Write technical reports in fluent English
following defined templates and Reporting Tools.
Brief at both executive and technical levels on security reports and testing outcome
including at flag officer level.
In case of new vulnerabilities detected for COTS software
follow the Responsible Disclosure Process and follow-up with vendors and stakeholders.
Stay abreast of technological developments relevant to the area of work.
Perform any other duties as may be required.
How You'll Work.
Team & Collaboration
In co-ordination with the Technical Lead of the Penetration testing team, ensure proactive collaboration and coordination with internal and external stakeholders.
Communication Scope
Fluent English; Brief at both executive and technical levels on security reports and testing outcome; Write clear and structured technical reports including executive summary, technical findings and remediation plan for several different audiences.
Applying for this Penetration tester role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
ANONYMOUS · UNFILTERED
What do employees actually say about Spektrum?
Real rants from real employees. Read before you apply.