718,867open jobs
42,744companies
102,468added this week
Browse all
Salary
$75k – $117k per year
Location
Remote/Hybrid (Utrecht, Netherlands)
Seniority
Senior

Confirmed on the employer's own hiring board on Sep 23, 2026. First seen by Alion on Aug 4, 2026. Northwave scores B on the Alion truth index.

Overview
Company
Impact
Profile match
Northwave is a Dutch cybersecurity company founded in 2006 and headquartered in Utrecht. It combines strategy consulting, security operations and incident response through its own computer emergency response team. The company serves enterprises across the Netherlands, Belgium and Germany.

At Northwave, 275 cybersecurity specialists transform how organisations approach digital safety. From our HQ in Utrecht, along with offices in Germany, Sweden, and Belgium.

Northwave combines ethical hacking expertise with behavioral psychology insights and cutting-edge security management at the highest level. We respond to threats and anticipate them, providing 24/7 managed security services and tailored solutions for each client's journey.

By joining Northwave, you’ll become part of an organisation where innovation drives results, whether your talents lie in technical penetration testing or strategic client partnerships. Here, your expertise will grow and help shape the future of digital security across industries, leaving a lasting impact.

The team you will join

Our Red Team brings together 15 ethical hackers with expertise spanning adversary simulation, social engineering, Active Directory and Entra ID, malware and tooling development, cloud, application security, reverse engineering and exploitation. We challenge one another, share techniques openly and combine the right skills for each operation.

You will also work closely with our Threat Intelligence, Blue Team, Reverse Engineering and CERT specialists. Insights from real incidents and current threats help us build credible scenarios. Purple teaming turns each exercise into practical improvements for our clients.

What you will do

  • Design and execute realistic attack scenarios against critical business processes and systems.

  • Operate across the full attack chain: reconnaissance and initial access, command and control, privilege escalation, lateral movement and actions on objectives.

  • Deliver threat-intelligence-led ART and TIBER exercises, alongside other advanced red team and purple team engagements.

  • Build or adapt tooling, infrastructure and payloads when an operation requires it.

  • Make sound OPSEC and risk decisions while working in live client environments.

  • Translate technical activity into clear lessons for defenders, technical leaders and executives.

  • Improve our tradecraft by researching new techniques, developing TTPs and sharing what you learn with the team.

How an engagement works

We start by understanding the organisation, its critical functions and the threat actors it faces. Together with the client and control team, we turn that context into objectives, attack scenarios and clear Rules of Engagement.

During execution, you will have room to adapt. The aim is not to follow a checklist, but to emulate a credible adversary without losing sight of safety or learning value. We close with transparent reporting, executive and technical presentations, and often a purple teaming session in which attacks are replayed with the defenders.

What you can expect from us

Serious red team work requires trust, time to learn and colleagues who can challenge your thinking. We offer:

  • Complex, multi-week adversary simulation assignments with meaningful objectives.

  • A team of specialists who share knowledge and bring different perspectives to an operation.

  • Direct collaboration with offensive, defensive, threat intelligence, reverse engineering and incident-response experts.

  • Time and budget for training, certifications, conferences and longer development programmes.

  • Professional equipment and the tooling needed to do your work well.

  • Hybrid working with access to our offices in Belgium, Germany, the Netherlands and Sweden.

  • A competitive local compensation and benefits package. Salary, leave, pension, mobility and allowances differ by country. Our recruiter will explain the package that applies to your location.

  • Room to influence our methods, tooling and the future of our red team services as demand grows.

Requirements

Essential

  • Several years of hands-on penetration testing or red team experience, including responsibility for planning and executing operations.

  • Strong attack-path knowledge in Windows and Active Directory environments.

  • Experience with Entra ID or other cloud environments.

  • Practical command-and-control, OPSEC and infrastructure skills.

  • The judgement to balance operational objectives, client safety and learning value.

  • Clear written and spoken English, with the ability to explain decisions and findings to both technical and non-technical audiences.

  • A collaborative approach: you ask for a second pair of eyes, share what worked and help others improve.

  • Eligibility to work from Belgium, Germany, the Netherlands or Sweden, and willingness to travel for client work when an engagement requires it.

Useful, but not required

  • Experience delivering ART, TIBER or another structured threat-led red team framework.

  • Depth in one or more areas such as social engineering, malware development, cloud, application security, exploit development or reverse engineering.

  • Relevant certifications such as OSCP, OSEP or CRTO. We value demonstrated capability and sound judgement more than a checklist of certificates.

  • Another European language in addition to English.

Not sure you match every point?

If you have solid offensive-security experience and are ready to take ownership of realistic red team operations, we would still like to hear from you. Tell us what you are strongest at, what you want to deepen and how you approach an operation when the obvious route does not work.

Ready to operate with us?

Apply through the vacancy page or contact Youri Roelofs at [email protected]. Please include the country from which you would like to work so we can discuss the relevant local package and practical arrangements.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
718,867 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Utrecht
PAM CyberArk Engineer 2 hours ago
$62k – $134k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Panama
PowerShell
DevOps
Rest API
Azure
Windows Server
Incident Management
Linux
Windows
Unix
Cybersecurity
CyberArk
Microsoft Entra ID
Active Directory
LDAP
Management
ServiceNow
Apply
$63k – $135k per year (Estimated) • Remote • Full-Time • 5+ years exp • United States
PowerShell
AI/ML
Copilot
DevOps
Windows
Cybersecurity
Microsoft Sentinel
Microsoft Defender
PCI DSS
GDPR
HIPAA
Zero Trust
Least Privilege
Microsoft Entra ID
SIEM
DLP
Management
OneDrive
SharePoint
Apply
$14k – $34k per year (Estimated) • Remote • Moscow
DevOps
SLI/SLO/SLA
Linux
Windows
VPN
Cybersecurity
Active Directory
Apply
Systems Administrator 5 hours ago
$62k – $141k per year • In office • Secret • Full-Time • High School Diploma • Fort Meade
SQL
DevOps
Linux
Windows
Unix
Apply
$124k per year (gross) • In office • Part-Time • Grand Haven
DevOps
Windows
Apply
SOC Analyst 10 hours ago
$36k – $55k per year • In office • Utrecht
Cybersecurity
SIEM
Apply
$36k – $38k per year • In office • Part-Time • Leipzig
Cybersecurity
ISO 27001
Apply
$42k – $66k per year • In office • Associate's Degree • Utrecht
Apply
HR People Partner 28 days ago
$55k – $75k per year • In office • Utrecht
Apply
$42k – $68k per year • In office • Utrecht
AI/ML
Red Teaming
Cybersecurity
ISO 27001
Apply
$32k – $59k per year (Estimated) • In office • Utrecht
Apply
$66k – $134k per year • In office • Full-Time • Utrecht
Management
Microsoft Office
Marketing
Salesforce
Apply
$22k – $57k per year (Estimated) • Remote/Hybrid • 2+ years exp • PhD • Utrecht
AI/ML
Edge AI
DevOps
Windows
Cybersecurity
ESET
Active Directory
Management
Google Workspace
Apply
Finance Stagiair 1 day ago
$39k – $75k per year (Estimated) • In office • Internship • Utrecht
Rust
Apply
Operations Officer 1 day ago
$36k – $75k per year (Estimated) • In office • Full-Time • Utrecht
DevOps
SLI/SLO/SLA
Management
Outlook
Microsoft Teams
Apply
See all jobs
This is one of many
718,867 more open roles from verified company boards, updated every day.