Senior Security Engineer - Pentester
New
J
JobgetherCybersecurity
CanadaFull-TimeSenior
SalaryCAD 158,000 to CAD 237,000
Apply NowOpens the employer's application page
Job Details
- Required Skills
- AWSPythonGCPKubernetesGoTerraform
Requirements
- Strong professional experience in security engineering, penetration testing, offensive security, application security, or a related cybersecurity discipline.
- Deep understanding of cloud security concepts with hands-on experience assessing AWS and GCP environments.
- Proven experience securing and testing containerized environments, including Kubernetes, GKE, EKS, or ECS.
- Expert knowledge of web application security principles, OWASP Top 10 vulnerabilities, API security, and modern exploitation techniques.
- Extensive hands-on experience with manual security testing tools such as Burp Suite Professional or OWASP ZAP.
- Strong understanding of browser security mechanisms, authentication flows (OAuth 2.0, OIDC, JWT), and security headers.
- Ability to identify complex vulnerabilities and create effective proof-of-concept demonstrations.
- Experience using AI-assisted security tools and large language models to improve penetration testing workflows.
- Strong scripting and automation skills using Python, Go, or Bash.
- Experience reviewing and auditing Infrastructure as Code, particularly Terraform.
Responsibilities
- Conduct comprehensive penetration tests across applications, APIs, cloud environments, and infrastructure components to identify security vulnerabilities before product releases.
- Assess security controls across multi-cloud environments, including AWS and GCP architectures, cloud configurations, IAM policies, and resource permissions.
- Review and test cloud-native systems, container environments, virtual machines, and hybrid infrastructure for security weaknesses.
- Perform dynamic security testing of web applications, APIs, and user interfaces using industry-standard offensive security methodologies.
- Analyze findings, develop reproducible proof-of-concepts, and provide clear remediation guidance to engineering and product teams.
- Monitor and triage vulnerability reports from bug bounty programs and external researchers.
- Use AI and large language models to accelerate reconnaissance, generate attack scenarios, and improve testing efficiency.
- Develop automation scripts and security tooling to streamline vulnerability discovery and validation processes.
- Review Infrastructure as Code configurations, including Terraform deployments, to identify security risks.
- Create high-quality technical documentation and security reports for technical and non-technical stakeholders.
View Full Description & ApplyYou'll be redirected to the employer's site