
Spektrum · The Hague
Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent to our team and look forward to...
Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent
to our team and look forward to hearing from you.
Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a
wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales,
delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects.
Who we are supporting
The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and
information technology (IT) services to NATO's member countries and its partners. The agency was established in 2012 and is
headquartered in Brussels, Belgium.
systems against cyber threats.
operations.
between NATO forces.
to its communication networks.
and servers.
Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information
technology capabilities.
The program
Assistance and Advisory Service (AAS)
The NATO Communications and Information Agency (NCI Agency) is NATO’s principal C3 capability deliverer and CIS service provider.
It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult
together under Article IV, and, when required, stand together in the face of attack under Article V.
To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high
performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International
Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI
Agency workforce and make up approximately 15 percent of the total workforce.
Role ID – C004912
Role Duties and Responsibilities
accreditation processes.
and external stakeholders.
Essential Skills, Experience and Certifications
o Web application penetration testing.
o IT infrastructure penetration testing.
o Network security architecture design.
o Assessing security vulnerabilities within OS, software, protocols & networks.
o Researching and evaluating security products & technologies.
o Knowledge in system and network administration of UNIX and Windows systems.
o Use of penetration testing tools, techniques, and recognized testing methodologies.
o Scripting skills in at least one of the following: Perl, Python, Ruby, shell (bash, ksh, csh).
o Technical knowledge in system and network security, authentication and security protocols, cryptography, application
security, as well as malware infection techniques and protection technologies.
o Ability to evaluate risks and formulate mitigation plans.
o Proven ability to write clear and structured technical reports including executive summary, technical findings and
remediation.
Working Location
Working Policy: The Hague, Netherlands.
Travel: Some travel to other NATO sites may be required
Security Clearance: Valid National or NATO Secret personal security clearance
We never know what new opportunities might be just over the horizon. If this opportunity isn't for you, please feel free to send
us your resume anyway and be the first to know if something suitable for your skills and experience comes up.
TL;DR: We're looking for a world-class Penetration Tester with a name in the field. You'll push Lovable's platform to its limits, hunt vulnerabilities across our AI pipelines and user-generated code, and make sure attackers never get there before you do. Why Lovable? Lovable lets anyone and everyone build software with any language. From solopreneurs to Fortune 100 teams, millions of people use Lovable to transform raw ideas into real products - fast. We are at the forefront of a foundational shift in software creation, which means you have an unprecedented opportunity to change the way the digital world works. Over 2 million people in 200+ countries already use Lovable to launch businesses, automate work, and bring their ideas to life. And we’re just getting started. We’re a small, talent-dense team building a generation-defining company from Stockholm. We value extreme ownership, high velocity, and low-ego collaboration. We seek out people who care deeply, ship fast, and are eager to make a dent in the world. What we’re looking for * 12+ years of hands-on penetration testing experience across web, mobile, APIs, and cloud infrastructure. * A track record the field knows about: CVEs to your name, hall-of-fame credits in major bug bounty programs, or a reputation that precedes you. * Deep expertise in offensive security techniques: OWASP, MITRE ATT&CK, exploit development, privilege escalation, and lateral movement. * Hands-on experience using AI as part of your hacking workflow — not just testing AI systems, but actively leveraging it as an offensive tool. * Experience attacking AI-native products or LLM-integrated systems, including prompt injection, model abuse, and data exfiltration vectors. * Strong understanding of cloud environments (GCP, AWS, Cloudflare) and the attack surfaces they introduce. * Ability to translate complex findings into clear, prioritised reports that engineering teams can act on immediately. * Low ego, high output. You collaborate as naturally as you compete against systems. * Bonus: experience with red team operations, supply chain attacks, or mobile security (iOS/Android). Familiarity with SAST/DAST tooling. What you’ll do * Own offensive security end-to-end: plan and execute penetration tests across Lovable's web platform, mobile surface, APIs, cloud infrastructure, and AI pipelines. * Break our AI before others do: probe LLM integrations for prompt injection, jailbreaks, data leakage, and novel attack vectors unique to AI-generated code running in live products. * Stress-test user-generated code at scale: identify systemic vulnerabilities introduced when millions of users create and deploy real applications on Lovable. * Turn findings into action: work directly with engineering to prioritise, remediate, and verify fixes, closing the loop between discovery and resolution. * Raise the security bar org-wide: run internal red team exercises, contribute to threat modelling, and embed an attacker's mindset across the engineering culture. * Help make Lovable the most secure AI product in the market. Our Tech Stack * Frontend: React and TypeScript * Backend: Golang and Rust * Cloud: Cloudflare, GCP, AWS, multiple LLM providers * DevOps & Tooling: GitHub Actions, Grafana, OTEL, infra-as-code (Terraform) * Data: Clickhouse, Firestore, Spanner, BigQuery And we're always exploring what's next! About your application Please submit your application in English. It’s our company language, so you’ll be speaking lots of it if you join. We treat all candidates equally - if you’re interested, please apply through our careers portal.
TL;DR: We're looking for a Penetration Tester who lives to break things, ethically. You'll push Lovable's platform to its limits, hunt vulnerabilities across our AI pipelines and user-generated code, and make sure attackers never get there before you do. Why Lovable? Lovable lets anyone and everyone build software with any language. From solopreneurs to Fortune 100 teams, millions of people use Lovable to transform raw ideas into real products - fast. We are at the forefront of a foundational shift in software creation, which means you have an unprecedented opportunity to change the way the digital world works. Over 2 million people in 200+ countries already use Lovable to launch businesses, automate work, and bring their ideas to life. And we’re just getting started. We’re a small, talent-dense team building a generation-defining company from Stockholm. We value extreme ownership, high velocity, and low-ego collaboration. We seek out people who care deeply, ship fast, and are eager to make a dent in the world. What we’re looking for 5+ years of hands-on penetration testing experience across web, mobile, APIs, and cloud infrastructure. Deep expertise in offensive security techniques: OWASP, MITRE ATT&CK, exploit development, privilege escalation, and lateral movement. Experience attacking AI-native products or LLM-integrated systems, including prompt injection, model abuse, and data exfiltration vectors. Strong understanding of cloud environments (GCP, AWS, Cloudflare) and the attack surfaces they introduce. Ability to translate complex findings into clear, prioritised reports that engineering teams can act on immediately. Low ego, high output. You collaborate as naturally as you compete against systems. Bonus: experience with red team operations, supply chain attacks, or mobile security (iOS/Android). Familiarity with SAST/DAST tooling. Background in security research or CVE disclosure. What you’ll do Own offensive security end-to-end: plan and execute penetration tests across Lovable's web platform, mobile surface, APIs, cloud infrastructure, and AI pipelines. Break our AI before others do: probe LLM integrations for prompt injection, jailbreaks, data leakage, and novel attack vectors unique to AI-generated code running in live products. Stress-test user-generated code at scale: identify systemic vulnerabilities introduced when millions of users create and deploy real applications on Lovable. Turn findings into action: work directly with engineering to prioritise, remediate, and verify fixes, closing the loop between discovery and resolution. Raise the security bar org-wide: run internal red team exercises, contribute to threat modelling, and embed an attacker's mindset across the engineering culture. Help make Lovable the most secure AI product in the market. Our Tech Stack Frontend: React and TypeScript Backend: Golang and Rust Cloud: Cloudflare, GCP, AWS, Modal, multiple LLM providers DevOps & Tooling: GitHub Actions, Grafana, OTEL, infra-as-code (Terraform) Data: Clickhouse, Firestore, Spanner, BigQuery And we're always exploring what's next! About your application Please submit your application in English. It’s our company language, so you’ll be speaking lots of it if you join. We treat all candidates equally - if you’re interested, please apply through our careers portal.
Are you passionate about ethical hacking and eager to develop the skills that keep modern applications safe? Do you dream of finding the weaknesses others miss — and helping organisations fix them before attackers do? If so, we have the perfect opportunity for you! ABOUT THE INTERNSHIP Our Application Security & Penetration Testing Internship is designed for ambitious individuals who want to explore the exciting world of offensive security and gain hands-on experience. This program offers the chance to work on real client engagements, learn industry-standard testing methodologies, and collaborate with experienced security consultants. WHAT YOU'LL LEARN As an intern, you will: Test modern web applications, APIs and mobile apps for real security weaknesses. Learn how professional penetration tests are planned, executed and reported. Turn technical findings into clear, practical advice that clients can act on. Gain hands-on experience with the tools and methodologies used on live engagements. This internship is designed for individuals eager to dive deep into application security and apply their curiosity to problems that matter. Every vulnerability you help find and every report you help write makes a real system secure and safer for the people who depend on it. WHY JOIN US? Hands-on experience with state-of-the-art security tools and technologies. Guidance and mentorship from seasoned penetration testers. Opportunity to work on real-world client engagements that make an impact. A collaborative and supportive environment where questions are always welcome. WHO WE'RE LOOKING FOR We welcome interns who: Have a strong interest in cybersecurity and ethical hacking. Have a solid grasp of web technologies, networking, and Linux or Windows OS. You don't need to be an expert, but we expect you to be very comfortable working in these environments. Good knowledge of mobile app development (iOS/Android) and APIs. Good knowledge of any major cloud technologies/platforms (AWS/Azure/GCP). Have some awareness of common application vulnerabilities, such as the OWASP Top 10. Exposure to web application penetration testing, API security testing, or mobile application security through academic projects or self-learning. Have tried their hand at CTFs or practice labs such as Hack The Box, TryHackMe or PortSwigger Web Security Academy, or personal projects or home labs. Good programming/scripting experience, for example, Python or Bash, is a bonus. Strong analytical and problem-solving skills with the ability to think creatively, eager to learn and solve complex problems. Are ready to contribute ideas and collaborate with a dynamic team. Approach security work with care, discretion and a strong ethical mindset. HOW TO APPLY Send your resume and a cover letter explaining why you're excited about penetration testing and why you are an ideal candidate for the role. It is recommended to include any personal security projects, CTF write-ups or lab platform profiles you have worked on. Applications are open until 31st August 2026. Don't miss this chance to kickstart your career in offensive security! Join us, and let's build a safer digital world together! Please note: This is an unpaid, full-time, 6-month onsite internship starting September 2026 at our offices in Lindholmen, Gothenburg.