ON2IT - Zero Trust Innovators

Select your region

Talk to us →
Hack the X · Live Recruitment CTF

Breach the system.
Hack the Hospital.

SOC Recruitment Sep 24, 2026 · 12:40–19:00 ON2IT HQ, Zaltbommel Free · dinner included

One afternoon. Real vulnerability classes. A seat in our SOC if you're good enough.

SEP 24, 2026 · ON2IT HQ, ZALTBOMMEL 37 SPOTS LEFT · APPLY BY SEP 22 REAL VULNERABILITY CLASSES · NO TUTORIAL CTF EVALUATED BY ON2IT'S SECURITY SPECIAL SERVICE TEAM 300+ PARTICIPANTS SINCE 2024 SEP 24, 2026 · ON2IT HQ, ZALTBOMMEL 37 SPOTS LEFT · APPLY BY SEP 22 REAL VULNERABILITY CLASSES · NO TUTORIAL CTF EVALUATED BY ON2IT'S SECURITY SPECIAL SERVICE TEAM 300+ PARTICIPANTS SINCE 2024

This isn't a recruiter funnel

What you get out of it

01
A real technical challenge

Not a tutorial CTF. Real vulnerabilities, a genuinely hard flag.

02
Evaluated by the team itself

Scored by ON2IT's Security Special Service Team on how you think.

03
Direct access to leadership

Dinner and a direct line to ON2IT's leadership.

04
A fast track, not a queue

Perform well, skip the CV queue, go straight to hiring.

One live target. One afternoon.

The mission

Live target

Operation: Tainted Supply

A fictional hospital, built for this event. Breach the perimeter, escalate into OT, seize the water treatment system.

Difficulty

Objectives4
Time limit2.5 hours
Spots left37
Claim your spot

Runs inside an isolated range built for this event. No real hospital, patient data, or live infrastructure is touched.

root@meridian-general:~
> ~ init_sequence --target=meridian-general.local
[+] Analyzing perimeter…
[+] Bypassing OT segmentation… SUCCESS
[+] Enumerating control systems…
Target
meridian-general.local
Segment
OT / ICS
System
Water Treatment
function overrideDosing(controller) {
  if (controller.auth_level !== "operator") {
    // TODO: enforce mTLS before merge
    return false;
  }
  return true;
}
System access: %

We don't hire analysts who memorized a playbook. We hire people who understand how an attacker actually moves. The fastest way to prove that is to be the attacker for an afternoon.

Why we're hiring SOC analysts through an offensive CTF

Motivation over pedigree

Who should apply

Forget the diploma. Graduates and career changers alike: if security is already what you do in the evenings, you qualify.

What actually qualifies you

  • A CTF ranking, home lab, or a GitHub full of side projects
  • Evenings spent on this while working a day job in something else
  • Curiosity that turned into practice, on your own time
  • MBO, HBO, WO, self-taught, or anything in between

What we're not screening for

  • A dedicated cybersecurity degree
  • Years of professional experience
  • A polished CV
  • A specific university or starting point

One event, eight checkpoints

The schedule

12:40
Doors open
12:45
Check-in
13:00
Briefing
13:30
Operation Tainted Supply (CTF)
16:00
Walkthrough & award ceremony
16:30
SOC tour & CTO meet and greet
17:15
Dinner
18:00
Speed-date interviews

Frequently asked questions

Before you apply

Do I need a cybersecurity degree, or a degree at all?

No. MBO, HBO, WO, self-taught, career changers: all welcome. What matters is that you do this for fun.

I'm switching careers into security. Am I too far behind?

No. We evaluate motivation and hours already put in, not years of experience.

Are you actually attacking a real hospital?

No. Meridian General is fictional, built on an isolated training range. No real hospital or patient data is involved.

Does doing well guarantee a job offer?

No. It's a recruitment assessment. Strong performance fast-tracks you into hiring, it doesn't guarantee an offer.

What should I bring?

A laptop is mandatory. Curiosity and eagerness matter most. Prior CTF experience is a plus, definitely not a requirement.

Registration closes Sep 22

Claim your spot

Spots are limited. Open to graduates and career changers alike.

Fields marked are required.

Registration is always solo; teams/groups are not part of the sign-up flow.