Lead Pentester
Cybersecurity Technical Audit Manager | Permanent Contract | Lille | Work from home 2 days/week
Allistic is a pure-play cybersecurity consulting firm that has been working since 2018 alongside demanding organizations to sustainably strengthen their security levels.
We primarily support mid-sized companies and large enterprises on issues related to governance, compliance, operational security, and technical auditing. Our goal is clear: to help our clients build a cybersecurity framework that is more robust, more transparent, and truly tailored to their risks.
At Allistic, we believe that cybersecurity relies as much on technical excellence as on the quality of the people who drive it. It requires rigor, discernment, knowledge sharing, and a genuine ability to progress collectively.
As part of the expansion of our offensive security operations, we are recruiting a Lead Penetration Tester to take charge of the technical audit division.
This position is for someone who wants to remain closely involved with the technical side of the work while playing a key role in developing a team, our service offerings, and our standards of excellence.
As a Lead Pentester, you will lead and carry out technical audit assignments for our clients, while contributing to the structuring and development of the division.
Your role is not limited to conducting penetration tests. You are expected to excel in three areas: technical expertise, quality of delivery, and the growth of the team.
You’ll serve as a point of reference on complex projects, mentor less experienced penetration testers, contribute to the continuous improvement of our methods, and help drive business growth for our technical audit practice.
Conduct and manage technical audit projects
You will perform penetration tests on a variety of environments: web applications, APIs, internal and external infrastructures, Active Directory, the cloud, security configurations, internet exposure, and hybrid environments.
You manage projects from start to finish: scoping, technical execution, vulnerability analysis, risk prioritization, report writing, client debriefing, and remediation support.
You ensure the quality of deliverables: clarity of findings, technical accuracy, practicality of recommendations, and the ability to tailor the level of detail to the audience.
Structuring and managing the technical audit division
You will gradually assume operational responsibility for the unit: organizing the workload, monitoring quality, capitalizing on lessons learned, and standardizing practices.
You will support consultants in their professional development: reviewing reports, conducting peer reviews, preparing for certifications, and developing internal training materials.
You will help define the division’s standards: methodologies, report templates, checklists, levels of evidence, and quality indicators.
Develop the technical audit offering
You will help build and improve our proactive services: web penetration testing, API testing, infrastructure testing, Active Directory testing, cloud testing, configuration reviews, and remediation support.
You will actively monitor vulnerabilities, attack techniques, exploitation methods, and market expectations.
Contribute to pre-sales and client relationship management
You help assess customer needs, draft technical proposals, prepare project cost estimates, and present proposals.
You know how to identify the real challenges behind a client request and build a relationship of trust based on expertise and quality of execution.
You have at least 5 years of experience in penetration testing, technical auditing, or offensive security, with a variety of projects across multiple areas: web, APIs, infrastructure, Active Directory, networks, and the cloud.
You are proficient in common penetration testing methodologies and tools: Burp Suite, Nmap, Metasploit, BloodHound, CrackMapExec / NetExec, Impacket, Kali Linux, Python, Bash, and PowerShell. What matters most is your ability to think critically, investigate, and adapt your methods to the context.
You know how to write high-quality, well-structured, and useful reports for a variety of audiences, from technicians to CISOs.
You have high technical standards, but you don’t limit yourself to individual performance: you enjoy sharing knowledge, helping others grow, and establishing common standards.
Previous experience in management, as a technical lead, or in project management is highly valued.
OSCP, CRTO, CRTE, PNPT, CRTL, or Burp Suite Certified Practitioner certifications are a plus, but do not replace hands-on experience and sound reasoning.
We are looking for someone capable of serving as a key point of reference: technically strong, reliable in execution, clear in communication, and exacting in deliverables.
This also means being willing to build: structuring a proposal, helping a team grow, setting standards, documenting methods, making difficult decisions, and championing quality both with the client and internally.
This position is not suitable for someone who only wants to conduct penetration tests in isolation. It will suit someone who wants to take on responsibility, maintain a strong connection to the technical side, and contribute directly to the growth of a specialized firm.
Permanent position, based in Lille. Remote work is possible up to 2 days per week, depending on client requirements and team needs.
Syntec collective bargaining agreement. Compensation based on profile and experience, competitive with the regional market.
The process consists of four steps:
Because you’re not joining a large, rigid organization. You’re joining a specialized firm that aims to take technical auditing to the next level, with the ambition of building a robust, transparent, and well-recognized service offering.
You’ll play a concrete role in this journey: developing, structuring, communicating, improving, and upholding the division’s technical standards.
At Allistic, your role will not be peripheral. It will be central.