
Pentester (M/F)
Job description
Penetration tester
Ready to take on this challenge?
Our Audit & Consulting division is growing! As a Penetration Testing Auditor, you will join a dynamic and versatile team and be involved in high value-added consulting assignments in IT and industrial environments. Through your actions, you will contribute to the cybersecurity of major international groups:
- You will be involved in assessing the security of network infrastructures (IT or OT) and applications (web, mobile, etc.) and will draw up reports detailing the technical impact and the level required to exploit the vulnerabilities detected. You will also contribute to all stages of intrusion testing, from familiarization to reporting findings and following up on recommendations.
- You will be able to contribute to various security activities, depending on your interests and skills (source code auditing, architecture auditing, configuration auditing, etc.).
- You will contribute to improving existing tools by benchmarking various tools on the market or developing new internal tools.
- You will represent SQUAD at various "Ethical Hacker" events and help to run the RedTeam community.
If you are motivated, you can progress towards ANSSI (FR) PASSI certification, management positions, and cybersecurity consulting assignments.
Part of your time will also be devoted to technology monitoring and training to maintain a high level of expertise.
The position can be based almost anywhere in France: Paris, Toulouse, Nice, Aix-en-Provence, Lyon, or Rennes! Like any auditor, you may be required to travel depending on the geographical location of the clients in your portfolio.
Category:
Cybersecurity managementReference:
Pentester Audit
Location
Skills
You have a two- to five-year degree in IT security.
You have 4 years of experience in performing intrusion tests on network infrastructures and/or web/mobile applications.
You are recognized as an independent person with a strong sense of priorities and enjoy working in a team.
You have solid knowledge of Windows and Linux operating systems and are proficient in at least the OWASP Top 10 (XSS, XXE, SQL Injection, CSRF, etc.) as well as discovering vulnerabilities in frontend and backend technologies.
You have strong Python/Bash scripting skills.
You have good writing skills: writing intrusion test reports, creating slides, and presenting pentest results.
Holding certifications related to penetration testing (CEH, OSCP, GPEN, etc.) is an additional asset, as is PASSI qualification in one or more technical areas.
A good command of English is essential.
Knowledge of DevSecOps and Cloud environments is a plus