We're looking for a Security testing specialist / Application pentesting specialist to join our team and contribute to large-scale projects in a demanding environment.
Missions
- Security assessments of web applications
- Web applications pentesting
- Automatic and manual code analysis/review
- Architecture audit and system hardening
- Assessment and improvement of the test processes, methodology and tools
- Vulnerability and Security technology watch
- Write vulnerabilities report
- Assistance with remediation of vulnerabilities
Technologies
-
OWASP, Osstmm, NIST, Sei CERT Coding Standards, MITRE Attack Framework
-
OWASP TOP 10 & OWASP API TOP 10
-
Ptes (Penetration Testing Execution Standard)
-
Java/JEE, JavaScript, Bash, SQL
-
Chrome, Firefox, Windows, Linux
-
Burp Suite Pro or equivalent (ZAP Proxy, Caido)
-
Code analysis tool : HCL AppScan or Semgrep or HP Fortify
Profile
- You have strong analytical and problem-solving skills
- You have a first experience with security testing methodologies and tools
-
You enjoy working in a stimulating environment and on large-scale projects
-
You have certification in ethical hacking/penetration testing (e.g. CEH, OSCP, GPEN)
-
You are passionate about the security aspect of testing
-
You are familiar with development
-
You are fluent in written and spoken English
Our offer
- Working in a Great Place to Work based in Luxembourg
- Attractive salary and pretty cool benefits (meal vouchers, mobile subscription...)
- Develop your skills and ideas over a coffee, a beer or a pizza during our Neo'vations
- Evolve within a strong company culture, you'll join us for the opportunity and you'll stay because we're super cool (well according to 98% of our employees NEOFACTO Annual Survey 2024)
-
Between afterworks, innovative workshops and ski weekends, there's never a dull moment when you're part of the Neo'Squad
Recruitment process:
- The pre-qualification interview with our Recruitment Manager
- Receipt of our salary proposal / exclusivity agreement
- 2nd interview with our Business Manager
- Technical tests and / or interview with our CTO
- Proposal of your application to the client
- Interview at the client's premises, which can be conducted either by video or in person