EMW, Inc. logo

C004907 Penetration Tester (NS) - THU 10 Sep RELAUNCH

EMW, Inc. Mons, Wallonia, Belgium

onsitecontract
Posted Aug 28, 2026
  • Role & seniority

    • Penetration Tester (hands-on; senior-level expectation with 3+ years penetration testing experience)

    • Supports/participates in Red/Blue Team during NATO exercises; may lead

  • Stack/tools (explicit/expected)

    • Penetration testing tools & methodologies (recognized testing methods)

    • Scripting: Perl, Python, Ruby, or shell (bash/ksh/csh)

    • Operating systems/admin: UNIX/Linux, Windows

    • Security areas: authentication/security protocols, cryptography, application security, malware infection & protections

  • Top 3 responsibilities

    • Perform web, infrastructure, and application-level penetration testing

    • Participate in Red/Blue Team activities during NATO military exercises

    • Provide security design reviews and security consultancy/advice (including risk mitigation recommendations)

  • Must-have skills

    • Active NATO SECRET security clearance

3+ years hands-on in

- Web application penetration testing

- IT infrastructure penetration testing

- Network security architecture design

- Vulnerability assessment across OS/software/protocols/networks
  • Ability to write structured technical reports with exec summaries and remediation plans

  • Ability to assess risks and formulate mitigation plans

  • Technical reporting to executive/technical audiences (incl. flag officer level)

  • Nice-to-haves

    • Familiarity/experience with **NATO security accred

Full Description

Previously proposed candidates were not compliant for the following reason: The profile does not demonstrate clear, independently verifiable experience aligning with the minimum requirement of 3 years in hands-on penetration testing.

Deadline Date: Thursday 10 September 2026

Requirement: Penetration Tester

Location: Mons, BE

Full Time On-Site: Yes

Time On-Site: 100%

Total Scope of the request (hours): 697

Required Start Date: 16 October 2026

End Contract Date: 31 December 2026

Required Security Clearance: NATO SECRET

Duties & Role

The duties of the individual mainly focus on

  • Lead and/or be part of the Red/Blue Team during NATO military exercises;
  • Provide Web, infrastructure and application level penetration testing;
  • Provide security design reviews to ensure compliance with NATO policies and directives;
  • Provide security consultancy and advice to projects, plans, and other entities;
  • Build and sustain effective communications with different stakeholders; specifically, the NCIA Configuration Control Board, Security Accreditation Boards, NATO Security Accreditation Authorities, and NCI Agency organization units supporting accreditation processes.
  • Brief at both executive and technical levels on security reports and testing outcome, including at flag officer level;
  • In co-ordination with the Head of the Penetration testing Cell, ensure proactive collaboration and coordination with internal and external stakeholders.

Skill, Knowledge & Experience

  • The candidate must have a currently active NATO SECRET security clearance
  • Extensive knowledge and experience (more than 3 years) in web application penetration testing;
  • Extensive knowledge and experience (more than 3 years) in IT infrastructure penetration testing;
  • Extensive knowledge and experience (more than 3 years) in network security architecture design;
  • Extensive knowledge and experience (more than 3 years) in assessing security vulnerabilities within OS, software, protocols & networks;
  • Extensive knowledge and experience (more than 3 years) in researching and evaluating security products & technologies;
  • Knowledge in system and network administration of UNIX and Windows systems;
  • Extensive knowledge and experience (more than 3 years) in the use of penetration testing tools, techniques, and recognized testing methodologies;

Scripting skills in at least one of the following: Perl, Python, Ruby, shell (bash, ksh, csh); Technical knowledge in system and network security, authentication and security protocols, cryptography, application security, as well as, malware infection techniques and protection technologies. Ability to evaluate risks and formulate mitigation plans; Proven ability to write clear and structured technical reports including executive summary, technical findings and remediation plan for several different audiences

Penetration testingWeb application securityIT infrastructure securityNetwork security architectureVulnerability assessmentSecurity design reviewsRed teamingBlue teamingPerlPythonRubyShell scriptingCryptographyUNIXWindowsRisk evaluationmulti-location

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.