S

Penetration Tester

Spektrum Braine-l'Alleud, Wallonia, Belgium

onsite
Posted Jun 3, 2026
  • Role & seniority

    • Penetration Testing / Security Consultant (Role ID: C004908); lead and/or participate in Red/Blue Team during NATO exercises (seniority not explicitly stated, duties indicate senior technical capability)
  • Stack/tools

    • Pen testing tools & methodologies (recognized testing methods; specific tools not listed)

    • Scripting: Python / Perl / Ruby / Shell (bash/ksh/csh) (at least one)

    • Platforms: UNIX and Windows system/network administration

    • Security domains: authentication, security protocols, cryptography, application security, malware infection techniques/protection

    • Reporting: executive summaries + technical findings/remediation plans

  • Top 3 responsibilities

    • Conduct web, infrastructure, and application-level penetration testing for NATO environments

    • Perform security design reviews and provide security consultancy/advice to projects and plans

    • Coordinate and brief stakeholders (incl. executive/flag officer level) and support accreditation/security boards

  • Must-have skills

    • Web application penetration testing

    • IT infrastructure penetration testing

    • Network security architecture design

    • Vulnerability assessment across OS, software, protocols, and networks

    • Strong ability to write structured security reports for multiple audiences

    • Ability to assess risks and define mitigation plans

    • Scripting capability (

Full Description

Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent to our team and look forward to hearing from you. Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects. Who we are supporting The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO's member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium.

The NCIA provides a wide range of services, including

Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO's communication networks and information systems against cyber threats.

Command and Control Systems: The NCIA develops and maintains the systems used by NATO's military commanders to plan and execute operations.

Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.

Electronic Warfare: The NCIA provides electronic warfare services to support NATO's mission to detect, deny, and defeat threats to its communication networks.

Information Management: The NCIA manages NATO's information technology infrastructure, including its databases, applications, and servers. Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information technology capabilities. The program Assistance and Advisory Service (AAS) The NATO Communications and Information Agency (NCI Agency) is NATO’s principal C3 capability deliverer and CIS service provider. It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult together under Article IV, and, when required, stand together in the face of attack under Article V. To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI Agency workforce and make up approximately 15 percent of the total workforce. Role ID – C004908 Role Duties and Responsibilities Lead and/or be part of the Red/Blue Team during NATO military exercises; Provide Web, infrastructure and application level penetration testing; Provide security design reviews to ensure compliance with NATO policies and directives; Provide security consultancy and advice to projects, plans, and other entities; Build and sustain effective communications with different stakeholders; specifically, the NCIA Configuration Control Board, Security Accreditation Boards, NATO Security Accreditation Authorities, and NCI Agency organization units supporting accreditation processes. Brief at both executive and technical levels on security reports and testing outcome, including at flag officer level; In co-ordination with the Head of the Penetration testing Cell, ensure proactive collaboration and coordination with internal and external stakeholders. Essential Skills, Experience and Certifications Web application penetration testing; IT infrastructure penetration testing; Network security architecture design; Assessing security vulnerabilities within OS, software, protocols & networks; Researching and evaluating security products & technologies; Knowledge in system and network administration of UNIX and Windows systems; Use of penetration testing tools, techniques, and recognized testing methodologies;

Scripting skills in at least one of the following: Perl, Python, Ruby, shell (bash, ksh, csh); Technical knowledge in system and network security, authentication and security protocols, cryptography, application security, as well as, malware infection techniques and protection technologies. Ability to evaluate risks and formulate mitigation plans; Proven ability to write clear and structured technical reports including executive summary, technical findings and remediation plan for several different audiences. Working Location Braine-l’Alleud, Belgium Working Policy Onsite Travel Some travel to other NATO sites may be required Security Clearance Valid National or NATO Secret personal security clearance We never know what new opportunities might be just over the horizon. If this opportunity isn't for you, please feel free to send us your resume anyway and be the first to know if something suitable for your skills and experience comes up.

Web Application Penetration TestingInfrastructure Penetration TestingNetwork Security ArchitectureVulnerability AssessmentUNIX AdministrationWindows AdministrationPythonRubyPerlShell ScriptingCryptographyApplication SecurityMalware AnalysisRisk EvaluationTechnical ReportingSecurity Design Reviewmulti-location

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.