About Northwave Our mission is clear: to enable businesses to operate securely. With over 275 dedicated specialists, Northwave works daily on innovative cybersecurity solutions that truly help organizations move forward. We operate from our headquarters in Utrecht and offices in Germany, Sweden, and Belgium. Northwave brings together ethical hacking, behavioral psychology, and top-level security management. We respond to threats, and anticipate them - through 24/7 managed security services and tailored specialist solutions. Joining Northwave means stepping into an environment where innovation and results go hand in hand. Whether you excel in technical testing or strategic client communication, you’ll have the freedom to help shape the future of digital security and make a real impact. Our Red Team Northwave’s Red Team lives for hacking. Our team consists of 15+ hackers from all over the world, with diverse backgrounds and expertise. We focus solely on challenging pentests and realistic red teaming operations that enhance the digital resilience of organizations across Europe. We collaborate with our Blue Team, Threat Intelligence, Reverse Engineering, and CERT to create realistic, high-value attack scenarios. In addition to our mature services, we are a highly regarded TIBER and ART provider, making our work consistently exciting and cutting-edge. The Role As an Ethical Hacker, you help our clients identify and understand vulnerabilities before malicious attackers can exploit them. You will work on a variety of penetration-testing assignments, covering areas such as web applications and APIs, internal and external infrastructure, Active Directory, Microsoft cloud environments and other technologies. We match assignments to your experience while giving you opportunities to broaden your technical skills. You will be involved throughout the engagement. Together with colleagues and the client, you define the scope and testing approach, perform the technical assessment and document your findings. You determine how vulnerabilities can be exploited, assess their potential impact and translate the results into clear, practical recommendations. You will also contribute to reports, discuss findings with clients and, where applicable, verify whether vulnerabilities have been resolved. You do not need to know every technology or be an experienced red team operator when you join. You will work alongside experienced colleagues who review your approach, challenge your thinking and help you develop. As your knowledge and confidence grow, you will take more ownership of assignments and can specialise in the areas that interest you most. Depending on your experience, skills and ambitions, you may also contribute to red team and purple team engagements. This could include activities such as Active Directory attack-path testing, reconnaissance, social engineering or working towards a broader attack objective. Red teaming is a possible development path within the role, rather than a requirement from day one. What we offer Competitive salary, paid on the 25th, with annual review and 8% holiday allowance Pension via Nationale Nederlanden, Northwave pays 50%, including partner pension 25 vacation days plus all national holidays Generous special leave for marriage, birth, bereavement, care and pregnancy Lease car based on salary scale (electric options available), or choose €0.25/km plus 50% lease budget as a mobility allowance MacBook, phone and accessories fully provided €200 net annual allowance for flexible and remote working Alleo budget for sports, wellness and leisure activities of your choice Training budget Referral bonus for bringing in a new colleague Hybrid working from a modern office in Utrecht Personal growth through the Role Model and FeedForward cycle, with your ambitions and development at the center Initial hands-on experience performing penetration tests, gained through employment, an internship or comparable practical security work. A solid technical foundation in at least one relevant area, such as web applications and APIs, infrastructure, Active Directory or cloud environments. A good understanding of networking, operating systems, common protocols and frequently encountered vulnerability classes. Experience using penetration-testing tools, combined with the ability and willingness to investigate and manually validate their results. A structured and responsible approach to testing, including respecting scope restrictions, handling client data carefully and keeping clear evidence of your work. The ability to explain technical findings and their impact in clear written and spoken English. Curiosity and persistence when the obvious testing approach does not work. A collaborative mindset. You are comfortable asking for help, receiving feedback and sharing what you learn with others. A relevant technical education or equivalent knowledge demonstrated through practical experience, personal projects or training. Useful, but not required Experience with Active Directory, Entra ID, Microsoft 365 or other cloud environments. Basic scripting or programming skills, for example in Python, PowerShell or Bash. Experience with vulnerability research, bug bounty programmes, CTFs or building your own security lab. Exposure to red teaming, purple teaming, social engineering or adversary simulation. A practical security certification such as OSCP, CRTP or eWPT, or the ambition to obtain one. Another European language in addition to English. Interested? What is important to you in your next step? We are happy to start a conversation. Apply directly or contact our recruiter Youri Roelofs via [email protected]
Security Researcher / Ethical Hacker
Sqills
Taxateur bedrijfsmatig vastgoed
Instroom
Applicatiebeheerder
Instroom
Experienced Red Team Operator
Northwave Cyber Security
Manager klantintegriteit
Brandnewday
Open sollicitatie
Brandnewday