Junior Pentester - Global

Descrição do trabalho

the world around us
We live in extraordinary times. Technology, society, the job market - they’re all rapidly advancing, and opening up previously unimagined opportunities. With innovation driving the world of work even faster, many of us are left wondering: how can I find a job that works for me?

people at the heart of everything we do
Working at Randstad is unlike working at any organization. Because at Randstad we put people at the heart of everything we do; this goes for our clients, our candidates, our employees and society. By combining our passion for people with the power of today’s technologies, we support people and organizations in realizing their true potential.

about Randstad
The Randstad Group is a global leader in the HR services industry and specialized in solutions in the field of flexible work and human resources services. Our services range from regular temporary Staffing and permanent placements to Inhouse Services, Professionals, and HR Solutions (including Recruitment Process Outsourcing, Managed Services Programs, and outplacement). In 2017, Randstad generated revenue of € 23.3 billion. Randstad was founded in 1960 and is headquartered in Diemen, the Netherlands. Randstad N.V. is listed on the NYSE Euronext Amsterdam, where options for stocks in Randstad are also traded. For more information, see www.randstad.com.

responsabilidades chave

your typical day includes
As a Junior Pentester, you will perform penetration tests on our global IT infrastructure. You'll have the opportunity, under guidance, to actively contribute to testing projects and take ownership of specific components. Every task is a learning opportunity to broadly develop your skills and build a solid foundation in the field.
You are part of the Randstad Global Offensive Security Team in the global CISO office. Together with 7 other Offensive Security Specialists, the team offers various security services to all Randstad countries and their IT landscape. They include a range of activities from traditional penetration testing (black/white box) to complex Red Teaming exercises, simulating real-world adversary tactics and techniques. We believe in an approach of working with developers and infrastructure teams instead of only supplying them with a report. By working closely with other IT teams we become ‘The Partner’ in identifying and resolving vulnerabilities to all Randstad countries.

  • you will be responsible for the following:
  • Under the guidance of senior team members, you will perform penetration tests on web applications, mobile applications, and network and infrastructure assessments. The focus will be on thoroughly learning each step and understanding its context within the broader security landscape.strategies and security requirements
  • On a day-to-day basis, you will work closely with application development and infrastructure teams to support and follow up on resolving the vulnerabilities found. Additionally, you will be encouraged to contribute to the improvement of our security testing processes and methodologies by actively seeking opportunities to apply new knowledge.
  • Driven by a strong drive and curiosity, you will actively stay updated on the latest security best practices, technologies, threats, and vulnerabilities related to web, mobile, network and infrastructure security. You will enthusiastically apply learned concepts to tasks under supervision.

competências

  • your background / profile
  • You have a strong Hacker Mindset: you are naturally curious and analytical, think 'out-of-the-box' when approaching systems, and are driven to understand how things work (and potentially how to bypass them), always with the goal of improving security.
  • 0-2 years of relevant working knowledge and experience in the pentest field.
  • You have a foundational understanding of common hacking techniques, security standards, and best practices, including the basics of OWASP Top 10. Awareness of relevant industry frameworks like MITRE ATT&CK is considered a plus.
  • Basic understanding of penetration testing methodologies in any of the following areas: network penetration testing, web application security, mobile application security, and network infrastructure.
  • You are proactive in seeking guidance to enhance your understanding and skills across diverse security areas. You enjoy thoroughly understanding fundamental concepts and explaining them clearly, and you see it as a plus to potentially support new team members in this regard in the future.
  • Ability to work with an international environment and to team up with other security and development teams.
  • Good communication skills in English.
  • Nice-to-have: Certificates related to competence offensive security - (e.g. OSWE, OSCP, CEH, GIAC GPEN, GIAC GXPN, EC-Council LPT).