# Consultant - Penetration testing / Pentesting - Luxembourg

**Company:** [Adservio Luxembourg](null/companies/pXCnp24JhtGsk9yJzDGjbF.md)
**Location:** Luxembourg, Luxembourg
**Workplace:** hybrid
**Employment type:** Full-time
**Department:** Technologies

[Apply for this job](null/view/9de625d1-5cd6-45e2-8821-3c9629c08b49)

## Description

**Adservio Luxembourg**  
Adservio Luxembourg is the Luxembourg arm of Adservio Group — 300+ consultants across Paris, Brussels and Luxembourg, 15 years serving regulated industries. We opened in Luxembourg in 2022 and work across financial services, energy and utilities, transport and mobility, insurance and the public sector: wherever compliance is not optional and failure is not acceptable. You join our Technologies & Engineering team.

**The context**  
With our team, you work for a Luxembourg bank strengthening the security of its applications and exposed infrastructure. Under DORA, Penetration testing / Pentesting is no longer a one-off exercise: it is part of a resilience testing programme overseen by senior management and expected by the supervisor.

**Your mission**  
Find the weaknesses before an attacker does, and give the teams what they need to fix them.

_Prepare and run the tests_

-   You scope each campaign with the security teams: perimeter, rules of engagement, scenarios.
-   You run penetration tests on web applications, APIs, and internal and external infrastructure.

_Qualify and report_

-   You rate each vulnerability by exploitability and business impact, beyond the raw score.
-   You write reports that work for those who fix and for those who decide.

_Follow through on remediation_

-   You support the technical teams through remediation, then verify with retests.
-   You document results for risk tracking and for the evidence expected under DORA.

**Your profile**

_What you must bring_

-   At least two years of hands-on Penetration testing / Pentesting, with several campaigns delivered end to end.
-   Command of reference methodologies (OWASP Testing Guide, PTES) and of common application and network vulnerabilities.
-   Day-to-day use of Burp Suite, Nmap, Metasploit and Kali Linux, plus a scripting language (Python, Bash or PowerShell).
-   A Master's or engineering degree in computer science, with a focus on security or networks.

_What makes the difference_

-   OSCP, or an equivalent certification (eWPT, GPEN, CRTP).
-   Testing experience in banking or another regulated environment, or familiarity with TIBER-EU.

**Languages**  
Required: fluent English and French, spoken and written.

**What you find with us**

-   **A tribe of peers.** You join our cybersecurity tribe, \[X\] consultants strong: peer reviews, shared threat watch.
-   **Expertise as a status.** Subject Matter Expert is a recognised status: our experts are called on by fellow consultants and by clients across the group.
-   **Regulated environments, across sectors.** Your mission is anchored in banking; our work also spans energy, transport, insurance and the public sector. You will not stay a single-sector consultant.
-   **A practice still being built, with a clear path.** Our Luxembourg office opened in 2022 and is taking shape now, backed by a group of 300+ consultants. What you set up here becomes how we work. Our grade structure is explicit, with an expert track for those who choose depth over management.

**The process**  
Application → HR conversation → Technical interview with your future peers → Feedback and decision. Whatever the outcome, you will hear back from us.
