DongIT logo

Pentester/Ethical Hacker

DongIT

Leiden
Full-time
2-5 years experience
Hybrid

Key Skills

Penetration testing
Ethical hacking
Web application security
API security
Mobile app security
Network security
IoT security
Cloud security
Burp Suite
Nmap
Metasploit
Python
Bash
Red teaming
Social engineering
Vulnerability assessment

Job Description

Please note: At this time, we are only considering candidates who already live in the Netherlands and do not require relocation. Dutch language skills are a strong plus. At DongIT, we believe good security starts with curiosity and creativity. We are looking for an Ethical Hacker who enjoys breaking things for the right reasons and helping organizations improve their security. If you thrive on finding vulnerabilities, sharing knowledge, and working together in a skilled and friendly team, this role may be the right fit for you. About the Role As an Ethical Hacker at DongIT, you will be directly involved in testing and improving the security of web applications, APIs, mobile apps, networks, and even IoT systems. Our projects vary: from black-box pentests to red team exercises, phishing simulations, and social engineering assessments. Your primary goal is to identify weaknesses, demonstrate their actual impact, and produce reports that clients can understand and use to improve their security. What You’ll Do Perform penetration tests on web applications, APIs, mobile apps, networks (internal and external), and IoT devices. Review cloud environments (AWS, Azure, GCP) to find misconfigurations and security risks. Examine source code to detect vulnerabilities. Detect and exploit vulnerabilities to show risk and impact. Write clear, actionable reports that help clients improve their security. Discuss findings with clients and support remediation. Research new vulnerabilities and attack techniques to stay sharp. Contribute to red team, phishing, or social engineering projects. Collaborate with the team to deliver high-quality results and share knowledge. Keep improving your skills through projects, training, and certifications. What We’re Looking For Required Someone with a hacker mindset: curious, creative, and persistent in finding security weaknesses. At least 3 years of experience in pentesting, security consulting, or related role. Knowledge of common vulnerabilities and tools such as Burp Suite, Nmap, Metasploit. Basic scripting skills (Python, Bash) and networking knowledge. Ability to explain technical issues clearly to clients and colleagues. Enjoys working in a friendly and supportive team. At least one relevant certification, such as OSCP, OSWE, eCPPT, eMAPT, eCPTX, or a comparable certification. Nice to have Mobile testing experience (iOS/Android). Knowledge of cloud platforms (AWS, Azure, GCP). Skills in reverse engineering or malware analysis. Experience with red team engagements or advanced exploitation techniques. Why Work at DongIT? Exciting Projects: Work on diverse pentests for leading organizations, from web apps to mobile and networks. Real Impact: Your findings directly help clients strengthen their security and protect critical systems. Small, Skilled Team: Collaborate with passionate developers and security specialists. Hybrid Work: Flexible remote work options or join us at our Leiden office (5 min from the station!). Personal Growth: Time and budget for training, courses, and certifications. Great Work Atmosphere: Informal, friendly environment with fun team events. Competitive Salary: Based on experience and certifications. Extras: Pension plan, Commuting reimbursement and high-end laptop. Acquisition in response to this vacancy is not appreciated. We do not accept candidates through third parties, including recruitment parties, employment agencies, headhunters, and outsourcing organizations.

Core Responsibilities

Perform penetration tests across web, mobile, network, and cloud environments to identify and exploit security vulnerabilities. Produce clear, actionable reports and collaborate with clients to support the remediation of identified security risks.

Requirements

Candidates must have at least 3 years of experience in pentesting and possess a relevant security certification such as OSCP or OSWE. A hacker mindset, proficiency with security tools like Burp Suite, and the ability to communicate technical findings effectively are required.

Benefits

  • Hybrid work
  • Training budget
  • Certification support
  • Pension plan
  • Commuting reimbursement
  • High-end laptop
  • Team events

About DongIT

Industry: Computer and Network Security

Company size: 11-50 employees

DongIT is an independent Dutch cybersecurity company, founded in 2012 and based in Leiden. We specialize in senior-led penetration testing and security assessments for web applications, APIs, cloud environments, networks, mobile apps and OT systems. Our pentests are performed exclusively by certified specialists (OffSec) working under a four-eyes principle, with methodologies aligned with OWASP, NCSC guidelines and emerging Dutch government standards. DongIT holds the CCV Keurmerk Pentesten and is ISO/IEC 27001:2022 certified, and we are a member of ECSO and Security Delta (HSD). More than 500 organizations rely on our work, from SMEs to banks, government bodies and international technology companies. What sets DongIT apart is the combination of offensive security expertise and deep software engineering knowledge. We understand how software is built, not just how it breaks. That makes our findings concrete, reproducible and directly actionable for the teams that need to fix them. That engineering DNA also produced Security Reporter: our self-hosted, all-in-one pentest assessment and reporting platform, in development since 2020 and used by security teams across Europe. It supports the full assessment workflow, from testing and collaboration to retesting and branded PDF and CSV exports. Learn more: • dongit.eu — company • websecurityscan.eu — pentesting services • securityreporter.app — Security Reporter platform

Added Today