job https://www.gremwell.com/ en We are hiring yet again - pentester job https://www.gremwell.com/jobs <span>We are hiring yet again - pentester job</span> <div><p>We are looking for a penetration tester again. The business has been growing steadily and we need more people. </p> <p>We will prefer somebody from Belgium or EU, but will consider applications from other countries also. We are located in Brussels, Belgium. The job is full time, mostly on customer sites in Belgium.</p> <p>The job involves performing security testing, alone or in a team. We perform a wide variety of security tests, from web applications security to hardware hacking, from low-level network security testing to telephony and VoIP security. What kind of tests you will be involved in depends on your interests and skill set. Apart from testing, you will have to write project reports, and interact with the clients before, during and after the test execution. You might also have to develop tools or use and adapt tools developed by other team members. Some project management is also expected.</p> <p>You will constantly have the opportunity to work with new products and technologies, learn new tools and techniques and share the knowledge.</p> <p>You get a competitive salary, a company car, laptop, cell phone subscription, Internet connection at home paid, home office compensation, rail pass, etc. The conditions are negotiable (see <a href="http://www.gremwell.com/we_are_hiring">the previous job ad</a> with regards to cream toffees).</p> <p>We are looking for somebody with a solid background in IT security, ideally an experienced pentester. We would like to see:</p> <ul><li>In-depth knowledge of and interest in computer security. You are familiar with the concepts, tools and methods used in IT security and specifically in penetration testing. Most importantly, you love security, you enjoy hacking, when you figure out how to exploit some tricky bug you feel happy for the rest of the day. </li> <li>Prior experience in penetration testing is a huge plus </li> <li>Knowledge of web application technologies and web application security. Familiarity with web application testing tools, such as intercepting proxies, application vulnerability scanners, etc. You have used intercepting proxies, you can exploit an SQL injection manually or with a tool, you know why there is more to XSS than &lt;script&gt;alert(1);&lt;/script&gt; (and you can write the that script-alert-script thingy without having to look up the syntax. I wish I was joking) </li> <li>In-depth knowledge of TCP/IP and application-level protocols and their security concepts. I mean more than "what's the difference between TCP and UDP?" sort of questions. </li> <li>Understanding of networking on link level is a plus </li> <li>Knowledge of operating system security concepts (and if you understand the security architecture of iOS and Android and can explain the differences, we love you already) </li> <li>Knowledge of mobile application security is a plus </li> <li>Knowledge of voice technologies is a plus </li> <li>Working knowledge of electronics is a plus </li> <li>Ability to code and read other people's code. If you have done security source code reviews, that's great. </li> <li>Ability to speak and write clearly in English is a requirement, knowledge of French and Dutch is a plus <p>Send your CV to <a href="mailto:info@gremwell.com">info@gremwell.com</a> with [Job] in the subject.</p></li> </ul></div> <span><span lang="" about="/user/10" typeof="schema:Person" property="schema:name" datatype="">alla</span></span> <span>Wed, 05/22/2019 - 12:06</span> Wed, 22 May 2019 10:06:26 +0000 alla 925 at https://www.gremwell.com We are hiring again! https://www.gremwell.com/we_are_hiring_again <span>We are hiring again!</span> <div><p>Once again, we are looking for a penetration tester. See <a href="http://www.gremwell.com/we_are_hiring">this post</a> for a descriptiong of skills we are interested in. Prior penetration testing experience is a plus, but not a must, provided that you have the necessary knowledge, both practical and theoretical. The job is in Brussels, Belgium, working remotely may be possible for some projects, but most of the time you'll have to be on site.</p> <p>Contact us at <a href="mailto:info@gremwell.com?Subject=[Job]">info@gremwell.com</a> if you are interested.</p> </div> <span><span lang="" about="/user/10" typeof="schema:Person" property="schema:name" datatype="">alla</span></span> <span>Thu, 12/06/2012 - 11:07</span> Thu, 06 Dec 2012 10:07:15 +0000 alla 853 at https://www.gremwell.com We Are Hiring https://www.gremwell.com/we_are_hiring <span>We Are Hiring</span> <div><p>We are looking for a penetration tester. Most of the work is in or around Brussels. Some of the work will have to be done remotely. Employee or subcontractor.</p> <p>You'll get a lot of opportunities to hack stuff. Actually, you'll be trying to break stuff most of your working time. Except when you are writing reports. Or trying to make stuff work, before you can start breaking it. Most of the work are web application tests, but other stuff as well, from hardware hacking to custom client-server applications.</p> <p>Obviously, you get a salary, and other perks, such as a laptop, cell phone, a paid Internet connection at home, hospitalisation insurance, etc. Pay and benefits are discussable, so if, for example, you always dreamt of getting your bonuses in cream toffees, that can be arranged.</p> <p>We are looking for penetration testers with a broad knowledge in IT security domain, but if you happen to specialise in some area this is ok as well. For web application penetration testers we are looking for:</p> <ul><li>Web application knowledge. You understand HTTP, you can read/write HTML and JavaScript, you understand web application security. You can use intercepting proxies. You can read (and write at least a "hello world" with minimum Googling) in common web development languages (Java, ASP, .NET, PHP). Web development knowledge is a large plus. </li> <li>Security. Uhm, I don't know exactly how to describe it. You know and love security. If you are asked what XSS is, you can talk for half an hour. You can exploit an SQL injection where automated tools fail (okay, at least sometimes). You can explain why an invalid SSL certificate on a server is a bad thing. </li> <li>Human interface. You can write a report that people won't mind reading. You can talk to people and explain security to them. You can think about security in terms of business impact. You can speak and write in English (uhm, and read and listen too). Dutch and French in addition to English are also welcome. </li> <li>Certificates. Nice to have. </li> </ul><p>For more network-oriented penetration testers we are looking for: </p> <ul><li>Excellent knowledge of networking - link level, TCP/IP, application level. You know how to capture network traffic and you know what to do with it once you captured it. Experience in system/network administration is a plus. </li> <li>Familiarity with Windows and Unix/Linux. You can use them, you can install and configure them, you understand the security models. </li> <li>Programming. You can script. Perl, python, ruby, shell, whatever you like. The more the better. At least you should be able to read and fix Perl/shell scripts. </li> </ul><p>Also, if you are good in Java and willing to help with development of MagicTree, it is a plus. If you don't know what is MagicTree, it is a minus.</p> <p>Looks good? Send your CV to <a href="mailto:info@gremwell.com?Subject=[Job]">info@gremwell.com</a> with [Job] in the subject.</p> </div> <span><span lang="" about="/user/10" typeof="schema:Person" property="schema:name" datatype="">alla</span></span> <span>Thu, 03/08/2012 - 15:15</span> Thu, 08 Mar 2012 14:15:26 +0000 alla 414 at https://www.gremwell.com